Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5736 results
CVE-2025-40778 preview

CVE-2025-40778

GitHubnehkark/cve-2025-40778

Proof-of-concept demonstrating DNS cache poisoning via additional record injection in BIND 9, with tools to validate and exploit CVE-2025-40778 for…

dns-analysiseducationexploitation+3
5
9 months ago
CVE-2026-22738-POC preview

CVE-2026-22738-POC

GitHubn0n4m3x41/cve-2026-22738-poc

Proof-of-concept exploit for CVE-2026-22738, a critical SpEL injection RCE in Spring AI SimpleVectorStore, demonstrating unauthenticated OS command…

educationexploitationpapers-research+2
134 months ago
CVE-2025-32463 preview

CVE-2025-32463

GitHubmuhammedkayag/cve-2025-32463

Proof-of-concept demonstrating a local privilege escalation in sudo (CVE-2025-32463) via chroot configuration manipulation, intended for defensive…

educationexploitationlabs-practice+2
10 months ago
Inside-CVE-2026-20805-How-a-Windows-DWM-Flaw-Exposed-Sensitive-Data preview

Inside-CVE-2026-20805-How-a-Windows-DWM-Flaw-Exposed-Sensitive-Data

GitHubmrk336/inside-cve-2026-20805-how-a-windows-dwm-flaw-exposed-sensitive-data

CVE‑2026‑20805: A Windows Desktop Window Manager flaw causing local information disclosure. Requires low privileges, no user interaction. Rated CVSS…

educationexploitationincident-response+2
7 months ago
Breaking-the-Update-Chain-Inside-CVE-2025-59287-and-the-WSUS-RCE-Threat preview

Breaking-the-Update-Chain-Inside-CVE-2025-59287-and-the-WSUS-RCE-Threat

GitHubmrk336/breaking-the-update-chain-inside-cve-2025-59287-and-the-wsus-rce-threat

Technical analysis and proof-of-concept exploit for CVE-2025-59287, a critical RCE in Windows Server Update Services via unsafe deserialization,…

educationexploitationpapers-research+2
310 months ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubmin8282/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

educationexploitationpenetration-testing+3
4 months ago
dissecting-pkexec-cve-2021-4034 preview

dissecting-pkexec-cve-2021-4034

GitHubmilot/dissecting-pkexec-cve-2021-4034

Educational analysis and proof-of-concept code for CVE-2021-4034 (pkexec local privilege escalation), with detailed comments explaining the…

binary-exploitationeducationexploitation+3
4 years ago
CVE-2026-37750 preview

CVE-2026-37750

GitHubmenevarad007/cve-2026-37750

Reflected XSS proof-of-concept for School Management System 1.0, demonstrating unauthenticated JavaScript execution via the type parameter in…

educationexploitationvulnerability-analysis+2
4 months ago
deephas-1.0.7-Prototype-Pollution-PoC-CVE-2026-25047- preview

deephas-1.0.7-Prototype-Pollution-PoC-CVE-2026-25047-

GitHubmbanyamer/deephas-1.0.7-prototype-pollution-poc-cve-2026-25047-

Proof-of-concept demonstrating prototype pollution in deephas <=1.0.7 (CVE-2026-25047) leading to arbitrary code execution and denial of service,…

code-analysiseducationexploitation+2
6 months ago
CVE-2026-3395-MaxSite-CMS-Unauthenticated-RCE preview

CVE-2026-3395-MaxSite-CMS-Unauthenticated-RCE

GitHubmbanyamer/cve-2026-3395-maxsite-cms-unauthenticated-rce

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

educationexploitationpenetration-testing+3
55 months ago
CVE-2026-26988-LibreNMS-SQLi preview

CVE-2026-26988-LibreNMS-SQLi

GitHubmbanyamer/cve-2026-26988-librenms-sqli

Proof-of-concept exploit for unauthenticated SQL injection in LibreNMS ajax_table.php, demonstrating time-based and boolean-based blind injection…

educationexploitationpenetration-testing+3
6 months ago
CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE preview

CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE

GitHubmbanyamer/cve-2026-26030-microsoft-semantic-kernel-1.39.4-rce

Proof-of-concept exploit for CVE-2026-26030, demonstrating remote code execution via unsafe filter expressions in Microsoft Semantic Kernel's…

code-analysiseducationexploitation+2
16 months ago
CVE-2026-24854-ChurchCRM-6.7.2-Authenticated-Numeric-SQL-Injection preview

CVE-2026-24854-ChurchCRM-6.7.2-Authenticated-Numeric-SQL-Injection

GitHubmbanyamer/cve-2026-24854-churchcrm-6.7.2-authenticated-numeric-sql-injection

Proof-of-concept demonstrating authenticated numeric SQL injection in ChurchCRM before 6.7.2, enabling logic manipulation to bypass WHERE clauses and…

educationexploitationpenetration-testing+3
6 months ago
PoC-CVE-2026-33017 preview

PoC-CVE-2026-33017

GitHubmasterwok/poc-cve-2026-33017

Proof-of-concept exploit for CVE-2026-33017 (Langflow <= 1.8.1).

educationexploitationpenetration-testing+3
4 months ago
PoC-CVE-2026-1357 preview

PoC-CVE-2026-1357

GitHubmasterwok/poc-cve-2026-1357

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration plugin for WordPress, enabling…

educationexploitationpenetration-testing+2
4 months ago
PoC-CVE-2026-21858 preview

PoC-CVE-2026-21858

GitHubmasterwok/poc-cve-2026-21858

Proof-of-concept exploit for CVE-2026-21858 (ni8mare) impacting n8n versions < 1.121.0

educationexploitationvulnerability-analysis+1
4 months ago
CVE-2026-31431---Copy-Fail-PoC preview

CVE-2026-31431---Copy-Fail-PoC

GitHubmaniakh/cve-2026-31431---copy-fail-poc

Bu depo, Linux cekirdeginde (kernel) bulunan CVE-2026-31431 (Copy Fail) zafiyetini icermektedir. Zafiyet, algif_aead modülündeki bir optimizasyon…

binary-exploitationeducationexploitation+3
13 months ago
exploit-CVE-2026-23744 preview

exploit-CVE-2026-23744

GitHubluiskrnr/exploit-cve-2026-23744

Exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam Inspector, allowing attackers to execute arbitrary commands via crafted…

exploitationpenetration-testingremote-access-tool+2
34 months ago
Previous12…100Next