Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Vulnerability Analysis

Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

NewestRelevanceMost popularRecently updated
25170 results
S2-072 preview

S2-072

GitHubcuteecat/s2-072

Proof-of-concept exploit for the Apache Struts JSON plugin denial-of-service vulnerability (CVE-2026-73633), demonstrating CPU and memory exhaustion…

vulnerability-analysisexploitationweb-application-exploitation
6 days ago
CVE-2026-64600-RefluXFS-PoC preview

CVE-2026-64600-RefluXFS-PoC

GitHub0xsec1/cve-2026-64600-refluxfs-poc

Proof-of-concept exploit for CVE-2026-64600 in RefluXFS, demonstrating the flaw and providing technical context for detection, patching, and further…

vulnerability-analysisexploitationbinary-exploitation
7 days ago
CVE-2023-22047---Oracle-PeopleSoft-LFI preview

CVE-2023-22047---Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047---oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
CVE-2026-72898 preview

CVE-2026-72898

GitHub4minx/cve-2026-72898

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

vulnerability-scannersvulnerability-analysisexploitation+3
16 days ago
CVE-2023-22047-Oracle-PeopleSoft-LFI preview

CVE-2023-22047-Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047-oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

vulnerability-analysisexploitationweb-application-exploitation+3
5 days ago
CVE-2026-46300_Fragnesia preview

CVE-2026-46300_Fragnesia

GitHubkentox493/cve-2026-46300_fragnesia

Linux kernel local privilege escalation exploit with automated prerequisite audit for CVE-2026-46300, validating patch status, XFRM ESP-in-TCP…

privilege-escalationvulnerability-analysisexploitation+3
6 days ago
CVE-2026-53587 preview

CVE-2026-53587

GitHubalixploit22/cve-2026-53587

Python proof-of-concept for CVE-2026-53587, providing a focused exploit path to reproduce the vulnerability and support validation and defensive…

vulnerability-analysisexploitationpenetration-testing
5 days ago
CVE-2026-6440 preview

CVE-2026-6440

GitHubalixploit22/cve-2026-6440

mencari sebuah kerentanan, wodpres dan mengungah shell di kerentanan wodpres tersebut

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
CVEX2SHEL preview

CVEX2SHEL

GitHubalixploit22/cvex2shel

Exploit for CVE-2026-64638, a pre-authentication reflected XSS in WordPress login, enabling injection of malicious JavaScript into /wp-login.php…

vulnerability-analysisexploitationweb-application-exploitation+2
5 days ago
CVE-2021-36934-DLL-Hijacking-DFIR-Investigation preview

CVE-2021-36934-DLL-Hijacking-DFIR-Investigation

GitHubduyduongduyduong/cve-2021-36934-dll-hijacking-dfir-investigation

DFIR investigation resources for CVE-2021-36934, covering DLL hijacking, privilege-escalation detection, and forensic analysis of affected Windows…

privilege-escalationvulnerability-analysisexploitation+2
6 days ago
CVE-2026-8793 preview

CVE-2026-8793

GitHubh4zaz/cve-2026-8793

Technical CVE write-up detailing missing brute-force protection in a web admin login form, with PoC reproduction, attack-chain context, and…

password-attacksvulnerability-analysisexploitation+4
6 days ago
CVE-2026-8794 preview

CVE-2026-8794

GitHubh4zaz/cve-2026-8794

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

reconnaissancevulnerability-analysisweb-application-exploitation+4
6 days ago
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
CVE-2026-9090-poc preview

CVE-2026-9090-poc

GitHubkimdir01/cve-2026-9090-poc

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

payload-generationvulnerability-analysisexploitation+4
5 days ago
CVE-2026-42533 preview

CVE-2026-42533

GitHubleeyoonjoo/cve-2026-42533

CVE-specific proof-of-concept written in Python for vulnerability validation and security testing.

vulnerability-analysisexploitationpenetration-testing
7 days ago
CVE-2025-32433-PoC-Analysis preview

CVE-2025-32433-PoC-Analysis

GitHubliam-worsley/cve-2025-32433-poc-analysis

This is an analysis for CVE-2025-32433 (Erlang OTP SSH Vulnerability). I did not write any of the code, I only wrote comments describing what the…

authentication-authorizationvulnerability-analysisexploitation+4
6 days ago
Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows preview

Perform-an-RDP-exploitation-using-the-BlueKeep-vulnerability-CVE-2019-0708-on-Windows

GitHubmohaimenul370/perform-an-rdp-exploitation-using-the-bluekeep-vulnerability-cve-2019-0708-on-windows

Step-by-step demonstration of BlueKeep CVE-2019-0708 exploitation against Windows Remote Desktop Services, including RCE via crafted RDP packets and…

vulnerability-analysisexploitationnetwork-security+2
7 days ago
CVE-2021-41773-Exploit-Lab preview

CVE-2021-41773-Exploit-Lab

GitHubsanr01/cve-2021-41773-exploit-lab

Reproduces CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with PoC code, root-cause analysis, impact assessment, and mitigation guidance…

vulnerability-analysisexploitationweb-application-exploitation+4
6 days ago
Previous1…8910…1399Next