Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Vulnerability Analysis

Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

NewestRelevanceMost popularRecently updated
25170 results
zyxel-social-login-bypass-cve-2026-8508 preview

zyxel-social-login-bypass-cve-2026-8508

GitHubminanagehsalalma/zyxel-social-login-bypass-cve-2026-8508

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

vulnerability-analysisexploitationweb-application-exploitation+4
4 days ago
CVE-2026-9830 preview

CVE-2026-9830

GitHubopaxial/cve-2026-9830

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

vulnerability-analysisexploitationweb-application-exploitation+3
1425 days ago
CVE-2026-73678-PoC preview

CVE-2026-73678-PoC

GitHubboreas37/cve-2026-73678-poc

CVE-2026-73678 — MindsDB Minds Platform unauthenticated RCE via scratchpad exec (CVSS 10.0). Verified end-to-end with real LLM

vulnerability-analysisexploitationweb-application-exploitation+1
14 days ago
CVE-2026-17544 preview

CVE-2026-17544

GitHubr2qa/cve-2026-17544

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

vulnerability-analysisexploitationweb-application-exploitation+4
5 days ago
CVE-2026-73633 preview

CVE-2026-73633

GitHubcuteecat/cve-2026-73633

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

vulnerability-analysisexploitationweb-application-exploitation+2
4 days ago
CVE-2026-72898-safe-detection preview

CVE-2026-72898-safe-detection

GitHubfranc-zar/cve-2026-72898-safe-detection

Simple script to achieve safe and non-desruptive active detection of CVE-2026-72898 (SQLi in Metabase)

vulnerability-scannersvulnerability-analysisweb-application-exploitation+2
4 days ago
CVE-2025-11740 preview

CVE-2025-11740

GitHubalixploit22/cve-2025-11740

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

vulnerability-analysisexploitationpenetration-testing
5 days ago
CVE-2026-47103-python-statemachine-rce preview

CVE-2026-47103-python-statemachine-rce

GitHubsaiteja-erukude/cve-2026-47103-python-statemachine-rce

Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.

payload-generationvulnerability-analysisexploitation+1
5 days ago
CVE-2026-47117-openmed-rce preview

CVE-2026-47117-openmed-rce

GitHubsaiteja-erukude/cve-2026-47117-openmed-rce

OpenMed < 1.5.2 unauthenticated RCE via PII privacy-filter model loading and trust_remote_code=True

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
CVE-2026-9147-uproot-rce preview

CVE-2026-9147-uproot-rce

GitHubsaiteja-erukude/cve-2026-9147-uproot-rce

uproot <= 5.7.4 code injection via unsafe Python source generation from ROOT TStreamerInfo metadata.

payload-generationvulnerability-analysisexploitation
5 days ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsvulnerability-scannersweb-vulnerability-scanners+4
4 days ago
CVE-2017-7921-EXP preview

CVE-2017-7921-EXP

GitHubblacksheepstudio/cve-2017-7921-exp

Python exploit for CVE-2017-7921 in Hikvision IP cameras, performing unauthenticated user enumeration, snapshot capture, and configuration file…

iot-securityvulnerability-analysisexploitation+3
3 years ago
Windows-Defender-Security-Auditor-CVE-2026-50656- preview

Windows-Defender-Security-Auditor-CVE-2026-50656-

GitHubeh-amish/windows-defender-security-auditor-cve-2026-50656-

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

defensive-toolsioc-managementpersistence-mechanisms+8
5 days ago
flar3ad preview

flar3ad

GitHubdaemoncibsec/flar3ad

POC of CVE-2026-51031 for arbitrary local file read

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
CVE-2023-48795 preview

CVE-2023-48795

GitHubhav0cx0/cve-2023-48795

Scans SSH servers for Terrapin-affected OpenSSH versions by grabbing banners over port 22, enabling quick internal audits, penetration testing, and…

vulnerability-scannersvulnerability-analysisinformation-gathering+2
1 year ago
cve-2025-5781_FreePBX preview

cve-2025-5781_FreePBX

GitHubiamrajkumar1995/cve-2025-5781_freepbx

Proof-of-concept exploit for FreePBX Endpoint module CVE-2025-5781: chains unauthenticated SQL injection with database manipulation and scheduled…

vulnerability-analysisexploitationweb-application-exploitation+1
5 days ago
CVE-2026-42945_NginxRift preview

CVE-2026-42945_NginxRift

GitHubkentox493/cve-2026-42945_nginxrift

Automates CVE-2026-42945 exploitation in NGINX containers: verifies vulnerable targets, brute-forces heap offsets, executes commands, and opens an…

container-securityvulnerability-analysisexploitation+5
6 days ago
POC-GeoLeak-CVE-2026-52715 preview

POC-GeoLeak-CVE-2026-52715

GitHub686f6c61/poc-geoleak-cve-2026-52715

PoC funcional de CVE-2026-52715 (GeoLeak): SQLi no autenticada en GEO my WordPress <= 4.5.5 via swlatlng/nelatlng. Laboratorio Docker + exploit…

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
Previous1…789…1399Next