Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
176 results
CVE-2018-16370 preview

CVE-2018-16370

GitHubsnappyjack/cve-2018-16370

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

code-analysisexploitationpenetration-testing+2
8 years ago
Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Code-Execution preview

Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Code-Execution

GitHubsanupl/vehicle-service-management-system-multiple-file-upload-leads-to-code-execution

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

code-analysisexploitationpayload-generation+3
4 months ago
CVE-2026-77262 preview

CVE-2026-77262

GitHubromain-deperne/cve-2026-77262

Proof-of-concept exploit for arbitrary file read in mcp-atlassian via path traversal in confluence_upload_attachment, with analysis and reproduction…

code-analysisexploitationpenetration-testing+2
19 days ago
CVE-2023-46694 preview

CVE-2023-46694

GitHubinvisiblebyte/cve-2023-46694

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

code-analysisexploitationpenetration-testing+2
42 years ago
CVE-2022-36532 preview

CVE-2022-36532

GitHublutrasecurity/cve-2022-36532

Proof-of-concept exploit script for CVE-2022-36532 enabling authenticated remote code execution via file upload in Bolt CMS 5.1.12 and below.

code-analysisexploitationpenetration-testing+2
34 years ago
CVE-2026-48939_PoC preview

CVE-2026-48939_PoC

GitHubchiefyoru/cve-2026-48939_poc

iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and…

code-analysisexploitationvulnerability-analysis+1
2 months ago
CVE-2024-46209 preview

CVE-2024-46209

GitHubh4ckr4v3n/cve-2024-46209

Security research repository detailing CVE-2024-46209 (authenticated RCE) and CVE-2024-46210 (stored XSS via file upload) in Redaxo CMS v5.17.1, with…

code-analysisexploitationpenetration-testing+2
1 year ago
CVE-2023-43360-CMSmadesimple-Stored-XSS---File-Picker-extension preview

CVE-2023-43360-CMSmadesimple-Stored-XSS---File-Picker-extension

GitHubsromanhu/cve-2023-43360-cmsmadesimple-stored-xss---file-picker-extension

Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top…

code-analysisexploitationpenetration-testing+3
3 years ago
CVE-2019-19634 preview

CVE-2019-19634

GitHubjra89/cve-2019-19634

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4

code-analysisexploitationpayload-generation+3
366 years ago
CVE-2019-19576 preview

CVE-2019-19576

GitHubjra89/cve-2019-19576

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3

code-analysisexploitationpayload-generation+3
126 years ago
CVE-2026-13157 preview

CVE-2026-13157

GitHubminhhk68/cve-2026-13157

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

code-analysisexploitationpayload-development+4
1 month ago
CVE-2026-11344-RCE preview

CVE-2026-11344-RCE

GitHubxmyronn/cve-2026-11344-rce

Unauthenticated remote code execution exploit for Vehicle Management System in PHP via unrestricted file upload in newdriver.php and newvehicle.php,…

code-analysisexploitationinformation-gathering+5
4 months ago
CVE-2026-7393-RCE preview

CVE-2026-7393-RCE

GitHubxmyronn/cve-2026-7393-rce

Proof-of-concept exploit for CVE-2026-7393: unrestricted file upload in Pizzafy Ecommerce System 1.0 allowing authenticated administrators to upload…

code-analysisexploitationpayload-generation+3
5 months ago
CVE-2026-1657 preview

CVE-2026-1657

GitHubd3kc4rt1/cve-2026-1657

Unauthenticated Arbitrary File Upload in EventPrime Plugin

code-analysiseducationexploitation+3
5 months ago
CVE-2024-52302 preview

CVE-2024-52302

GitHubd3sca/cve-2024-52302

PoC exploit for CVE-2024-52302: unrestricted file upload in common-user-management Spring Boot app leading to remote code execution via…

code-analysisexploitationpayload-generation+3
11 year ago
CVE-2023-26262 preview

CVE-2023-26262

GitHubistern/cve-2023-26262

Proof-of-concept for authenticated arbitrary file upload in Sitecore 10.3, enabling webshell deployment and remote code execution via the import…

code-analysisexploitationpayload-generation+3
3 years ago
CVE-2024-10410 preview

CVE-2024-10410

GitHubk1nakoo/cve-2024-10410

Proof-of-concept exploit for CVE-2024-10410: unrestricted file upload in Online Hotel Reservation System. Demonstrates bypass of image validation via…

code-analysisexploitationpayload-generation+3
1 year ago
prefect-cve-2026-5366 preview

prefect-cve-2026-5366

GitHubrenat0z3r0/prefect-cve-2026-5366

PoC for CVE-2026-5366: git argument injection in Prefect's GitRepository leading to RCE on the worker.

code-analysiseducationexploitation+3
3 months ago
Previous123…10Next