Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
182 results
CVE-2021-24145 preview

CVE-2021-24145

GitHubdnr6419/cve-2021-24145

WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5

educationexploitationpayload-generation+3
3
4 years ago
Web-App-PenTesting preview

Web-App-PenTesting

GitHubsarthak4126/web-app-pentesting

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

educationlabs-practicepenetration-testing+4
2 days ago
CVE-2026-0740 preview

CVE-2026-0740

GitHub0xgh057r3c0n/cve-2026-0740

Ninja Forms File Uploads <= 3.3.26 - Unauthenticated Arbitrary File Upload

educationexploitationpenetration-testing+2
242 months ago
JQShell preview

JQShell

GitHubstahlz/jqshell

Automated exploit tool for CVE-2018-9206 (jQuery File Upload) with single/multi-target scanning, Tor proxy support, and output logging for…

educationexploitationpenetration-testing+2
627 years ago
CVE-2026-22241 preview

CVE-2026-22241

GitHubcves-labs/cve-2026-22241

Lab Environment for CVE-2026-22241

educationexploitationlabs-practice+3
2 months ago
CVE-2022-30887 preview

CVE-2022-30887

GitHubsonerctnkya/cve-2022-30887

Proof-of-concept exploit for CVE-2022-30887, demonstrating remote code execution via file upload in Pharmacy Management System 1.0, with mitigation…

educationexploitationpayload-development+3
24 years ago
CVE-2025-4403 preview

CVE-2025-4403

GitHubyucaerin/cve-2025-4403

Drag and Drop Multiple File Upload for WooCommerce <= 1.1.6 - Unauthenticated Arbitrary File Upload via upload Function

educationexploitationpenetration-testing+2
31 year ago
CVE-2026-36669-FengOffice preview

CVE-2026-36669-FengOffice

GitHubfirstlax6t/cve-2026-36669-fengoffice

Detailed security advisory for CVE-2026-36669: unauthenticated arbitrary file upload in Feng Office, enabling stored XSS and session hijacking.…

educationexploitationpapers-research+3
2 months ago
CVE-2024-1247-PoC preview

CVE-2024-1247-PoC

GitHubnxploited/cve-2024-1247-poc

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

code-analysiseducationexploitation+3
1 year ago
CVE-2026-5718-Lab preview

CVE-2026-5718-Lab

GitHubrootdirective-sec/cve-2026-5718-lab

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

ctfeducationexploitation+3
14 months ago
CVE-2020-29607 preview

CVE-2020-29607

GitHubalienfader/cve-2020-29607

Python exploit for CVE-2020-29607 that bypasses file upload restrictions in Pluck CMS to upload a PHP webshell, enabling remote command execution on…

educationexploitationpenetration-testing+2
1 year ago
Inject-PHP-to-JPG-Using-Jhead preview

Inject-PHP-to-JPG-Using-Jhead

GitHubjenderal92/inject-php-to-jpg-using-jhead

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

educationpayload-developmentsteganography+1
13 months ago
0l4bs preview

0l4bs

GitHubtegal1337/0l4bs

Cross-site scripting labs for web application security enthusiasts

ctfeducationlabs-practice+1
3485 years ago
CVE-2026-88533 preview

CVE-2026-88533

GitHubhemlock-lyk/cve-2026-88533

PoC and lab reproduction for CVE-2026-88533, an unauthenticated arbitrary file write leading to root RCE in QAnything via path traversal in the…

educationexploitationlabs-practice+4
7 days ago
CVE-2024-11635 preview

CVE-2024-11635

GitHubvigilante-1337/cve-2024-11635

The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the…

educationexploitationlabs-practice+3
8 months ago
CVE-2023-24249-Exploit preview

CVE-2023-24249-Exploit

GitHubiduzzel/cve-2023-24249-exploit

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

educationexploitationpayload-generation+4
92 years ago
CVE-2023-29386 preview

CVE-2023-29386

GitHubvigilante-1337/cve-2023-29386

PoC CVE-2023-29386 — Manager for Icomoon < 2.1 - Unauthenticated Arbitrary File Upload

educationexploitationlabs-practice+3
11 months ago
Ghost-5.58-Arbitrary-File-Read-CVE-2023-40028 preview

Ghost-5.58-Arbitrary-File-Read-CVE-2023-40028

GitHub0xdtc/ghost-5.58-arbitrary-file-read-cve-2023-40028

CVE-2023-40028 affects Ghost, an open source content management system, where versions prior to 5.59.1 allow authenticated users to upload files that…

educationexploitationpenetration-testing+3
131 year ago
Previous12…11Next