Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
CVE-2026-29053 preview

CVE-2026-29053

GitHubk3ystr0k3r/cve-2026-29053

Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

exploitationpayload-developmentpenetration-testing+5
1
6 days ago
CVE-2023-4762 preview

CVE-2023-4762

GitHubzined/cve-2023-4762

Proof-of-concept exploit for CVE-2023-4762, a Chromium V8 type confusion vulnerability enabling remote code execution via crafted JavaScript.

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2025-58434 preview

CVE-2025-58434

GitHubr3vpwnx/cve-2025-58434

Exploit chain for Flowise 3.0.5: unauthenticated account takeover via password-reset token disclosure (CVE-2025-58434) chained to CustomMCP…

authenticationexploitationpenetration-testing+3
24 days ago
CVE-2026-30251 preview

CVE-2026-30251

GitHubvenablee/cve-2026-30251

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
CVE-2026-27574-OneUptime-RCE preview

CVE-2026-27574-OneUptime-RCE

GitHubmbanyamer/cve-2026-27574-oneuptime-rce

Proof-of-concept exploit for CVE-2026-27574, a critical code injection in OneUptime enabling remote code execution and environment variable leakage.

exploitationpayload-developmentpenetration-testing+3
17 months ago
cve-2024-21683-rce preview

cve-2024-21683-rce

GitHubr3db34rdh4x/cve-2024-21683-rce

Exploit for CVE-2024-21683, a post-authentication remote code execution vulnerability in Atlassian Confluence Server and Data Center, allowing…

exploitationpenetration-testingred-teaming+2
1 year ago
CVE-2026-23830-SandBreak preview

CVE-2026-23830-SandBreak

GitHubgalaxy-sc/cve-2026-23830-sandbreak

Generates and delivers exploit payloads for CVE-2026-23830, a SandboxJS escape, with modes for blind OOB exfiltration and local calc PoC. Supports…

exploitationpayload-generationpenetration-testing+3
17 months ago
CVE-2026-22444 preview

CVE-2026-22444

GitHubbfdfhdsfdd-crypto/cve-2026-22444

Exploit for Apache Solr CVE-2026-22444, leveraging UNC path injection and SMB server to achieve remote code execution via malicious configset and…

exploitationpenetration-testingred-teaming+3
8 months ago
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

api-securityexploitationpayload-development+4
1 month ago
CVEX2SHEL preview

CVEX2SHEL

GitHubalixploit22/cvex2shel

CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC preview

Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC

GitHubdarknesschieftain/injection-vulnerability-in-paradox-security-systems-ipr512-cve-2023-24709-poc

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

exploitationiot-securitypenetration-testing+3
3 years ago
XSSFire preview

XSSFire

GitHubseifelsallamy/xssfire

A standalone Blind XSS Script.

data-exfiltrationexploitationinformation-gathering+3
471 year ago
Zapscape preview

Zapscape

GitHubaarif450/zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

binary-exploitationdefensive-toolsexploitation+2
15 days ago
CVE-2026-67340_exploit preview

CVE-2026-67340_exploit

GitHub0xdak/cve-2026-67340_exploit

Post-auth RCE exploit for ArcadeDB via JavaScript trigger GraalVM sandbox escape, executing OS commands over HTTP API with reverse shell or blind…

database-securityexploitationpenetration-testing+1
1 month ago
nodejsshell preview

nodejsshell

GitHubh3x0v3rl0rd/nodejsshell

Node.js reverse shell payload generator for penetration testing. Creates bind and reverse shells in JavaScript.

exploitationpayload-generationpenetration-testing+4
1 year ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

command-and-controlexploitationpayload-generation+5
52 months ago
wp2shell-poc-fulljs preview

wp2shell-poc-fulljs

GitHubraphy76/wp2shell-poc-fulljs

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

exploitationpayload-generationpenetration-testing+2
2 months ago
CVE-2025-44998 preview

CVE-2025-44998

GitHubl8bl/cve-2025-44998

Proof-of-concept exploit for a stored XSS vulnerability in TinyFileManager v2.4.7, enabling arbitrary JavaScript execution and session cookie…

exploitationinformation-gatheringpenetration-testing+3
1 year ago
Previous1234567Next