Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
457 results
CVE-2026-71204-PoC preview

CVE-2026-71204-PoC

GitHubnel-droid/cve-2026-71204-poc

PoC: changedetection.io settings blind-merge mass assignment (CVE-2026-71204, Medium 6.3)

api-securityauthentication-authorizationexploitation+2
1 month ago
CVE-2026-64849 preview

CVE-2026-64849

GitHubbiutrap/cve-2026-64849

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

api-securitycloud-securityexploitation+4
29 days ago
CVE-2026-72585-PoC preview

CVE-2026-72585-PoC

GitHubnel-droid/cve-2026-72585-poc

PoC: Grafana Editor role deletes protected contact points (CVE-2026-72585, Medium 6.5)

api-securityauthentication-authorizationexploitation+2
1 month ago
CVE-2026-40179-PoC preview

CVE-2026-40179-PoC

GitHubbsdrip/cve-2026-40179-poc

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

api-securityexploitationvulnerability-analysis+1
17 days ago
EITS-Portal-Exploit-CVE-2026-31367-PoC preview

EITS-Portal-Exploit-CVE-2026-31367-PoC

GitHubhereticl1nk/eits-portal-exploit-cve-2026-31367-poc

PoC exploit for unauthenticated RCE in EITS Admin Dashboard v2.4.0 via command injection in /api/v1/debug, allowing arbitrary OS command execution on…

api-securityexploitationpenetration-testing+2
1 month ago
CVE-2026-73519-WolfStack-PoC preview

CVE-2026-73519-WolfStack-PoC

GitHubsqueeze440/cve-2026-73519-wolfstack-poc

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

api-securityauthenticationcontainer-security+3
1 month ago
CVE-2026-51954 preview

CVE-2026-51954

GitHubenvincion1991-cmyk/cve-2026-51954

Vulnerability Research

api-securityauthenticationexploitation+2
1 month ago
CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field preview

CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field

GitHubtheopaid/cve-2026-66421-openclaw-dashboard-stored-xss-via-lastmessage-session-field

Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

ai-securityapi-securityexploitation+3
1 month ago
inference-gateway-PoC preview

inference-gateway-PoC

GitHubsqueeze440/inference-gateway-poc

PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).

api-securityauthenticationexploitation+3
7 days ago
CVE-2026-71203-PoC preview

CVE-2026-71203-PoC

GitHubnel-droid/cve-2026-71203-poc

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

api-securityapi-security-testingexploitation+4
1 month ago
CVE-2026-18953 preview

CVE-2026-18953

GitHubronamosa/cve-2026-18953

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

api-securityexploitationpenetration-testing+1
1 month ago
pasteguard-PoC preview

pasteguard-PoC

GitHubsqueeze440/pasteguard-poc

PoC — cross-origin proxy abuse of configured provider API keys in PasteGuard (GHSA-q94x-p9rc-q89f, CVE-2026-86998, CVSS 7.6).

api-securityexploitationpapers-research+3
14 days ago
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

api-securityexploitationpayload-development+4
23 days ago
sentrymcp preview

sentrymcp

GitHubzaydmulani09/sentrymcp

A static + runtime security scanner for MCP (Model Context Protocol) servers

ai-securityapi-securitymisconfiguration+3
29 days ago
super-secret-finder preview

super-secret-finder

GitHubrandomrobbiebf/super-secret-finder

Burp Plugin for Secret Matching

api-securityinformation-gatheringpenetration-testing+3
63 years ago
CVE-2025-6514 preview

CVE-2025-6514

GitHubcyberency/cve-2025-6514

mcp-remote exposed to OS command injection

api-securityauthenticationcommand-and-control+3
710 months ago
CVE-2026-31816 preview

CVE-2026-31816

GitHubk3ystr0k3r/cve-2026-31816

CVE-2026-31816 - Budibase Authentication Bypass to RCE

api-securityauthentication-authorizationexploitation+3
21 month ago
CVE-2026-33032 preview

CVE-2026-33032

GitHubkeraattin/cve-2026-33032

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

api-securityexploitationnetwork-security+4
55 months ago
Previous1…202122…26Next