Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
471 results
CVE-2026-15667 preview

CVE-2026-15667

GitHubcflowsec/cve-2026-15667

Python proof-of-concept for CVE-2026-15667, an authenticated local file inclusion in the WordPress Eventin plugin via the event_layout REST field.

exploitationpenetration-testingvulnerability-analysis+3
3 days ago
CVE-2026-14962 preview

CVE-2026-14962

GitHubcflowsec/cve-2026-14962

Wordpress Plugin ELEX WooCommerce Request a Quote unauthenticated SQL injection

exploitationpenetration-testingvulnerability-analysis+3
3 days ago
CVE-2018-20062 preview

CVE-2018-20062

GitHubjasper2018/cve-2018-20062

Verification script and PoC for CVE-2018-20062, the ThinkPHP 5.0.x invokefunction deserialization RCE, confirming route reachability and capturing…

exploitationpenetration-testingvulnerability-analysis+2
5 days ago
Mikrotrick_POC preview

Mikrotrick_POC

GitHub4rt-net/mikrotrick_poc

Testing tool for the Mikrotrick exploit (CVE-2026-67276)

authenticationexploitationnetwork-security+3
5 days ago
CVE_2023_44487-Rapid_Reset preview

CVE_2023_44487-Rapid_Reset

GitHubgmh5225/cve_2023_44487-rapid_reset

Python-based testing tool for CVE-2023-44487 (HTTP/2 Rapid Reset) with multiple attack patterns, granular configuration, and monitoring for…

exploitationnetwork-securitypenetration-testing+2
1 year ago
CVE-2026-57811 preview

CVE-2026-57811

GitHub0xcyp1337/cve-2026-57811

Exploits CVE-2026-57811, an unauthenticated RCE in Realtyna Organic IDX + WPL Real Estate WordPress plugin, enabling shell upload and command…

exploitationpayload-developmentpenetration-testing+2
16 days ago
CVE-2023-42793-TeamCity-Unauthenticated-RCE preview

CVE-2023-42793-TeamCity-Unauthenticated-RCE

GitHubburakacar6/cve-2023-42793-teamcity-unauthenticated-rce

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

authenticationexploitationpenetration-testing+3
10 days ago
CVE-2026-63077 preview

CVE-2026-63077

GitHub0xcyp1337/cve-2026-63077

Exploit for CVE-2026-63077, an unauthenticated RCE in JetBrains TeamCity via deserialization. Supports mass scanning, multi-threading, and…

exploitationpenetration-testingremote-access-tool+2
110 days ago
ActiveMQ-CVE-2023-46604 preview

ActiveMQ-CVE-2023-46604

GitHubbhanunamikaze/activemq-cve-2023-46604

Non-destructive validator for Apache ActiveMQ CVE-2023-46604. Sends crafted OpenWire packets, uses HTTP callback server to confirm RCE or XML…

exploitationpenetration-testingvulnerability-analysis+2
13 days ago
phpBB-CVE-2026-48611 preview

phpBB-CVE-2026-48611

GitHubethicalgrey/phpbb-cve-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

authentication-authorizationexploitationinformation-gathering+5
15 days ago
WSOB preview

WSOB

GitHubdsssssssm/wsob

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

exploitationpenetration-testingred-teaming+2
263 years ago
By-Poloss..-..CVE-2026-18080 preview

By-Poloss..-..CVE-2026-18080

GitHubpolosss/by-poloss..-..cve-2026-18080

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

exploitationpayload-developmentpenetration-testing+3
19 days ago
CVE-2026-72898-metabase-sqli preview

CVE-2026-72898-metabase-sqli

GitHubd-maggipinto/cve-2026-72898-metabase-sqli

Detector + root-cause analysis for CVE-2026-72898 (Metabase unauthenticated SQLi via reset_password)

exploitationpenetration-testingvulnerability-analysis+2
19 days ago
CVE-2023-4861-PoC preview

CVE-2023-4861-PoC

GitHubnoambouillet/cve-2023-4861-poc

Automated proof-of-concept for authenticated remote code execution in WordPress File Manager Pro (Filester) via arbitrary file upload, including…

exploitationpayload-developmentpenetration-testing+2
22 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubthekawix/cve-2026-41940

Generates detection artifacts to verify cPanel/WHM authentication bypass vulnerability (CVE-2026-41940) and tests targets for exposure.

authenticationexploitationpenetration-testing+2
14 months ago
CVE-2026-42228 preview

CVE-2026-42228

GitHubrudsarkar/cve-2026-42228

Proof-of-concept exploit for CVE-2026-42228, an unauthenticated chat execution hijacking vulnerability in n8n, with automated scanning and attack…

exploitationpenetration-testingreconnaissance+3
4 months ago
CVE-2026-68820_Mass_Exploit preview

CVE-2026-68820_Mass_Exploit

GitHubmaxprog-svg/cve-2026-68820_mass_exploit

Automated local privilege escalation exploit for Windows 10/11 targeting AFD.sys use-after-free to gain SYSTEM, with PPL bypass and EDR evasion for…

exploitationexploit-frameworkslateral-movement+5
20 days ago
CVE-2026-42167-Exploit preview

CVE-2026-42167-Exploit

GitHubefeanilarslan/cve-2026-42167-exploit

Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.

data-exfiltrationexploitationpenetration-testing+2
4 months ago
Previous12…27Next