Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
4228 results
VulnForge preview

VulnForge

GitHubrootless-ghost/vulnforge

Vulnerability & exploit intelligence — ExploitDB, NVD, Metasploit search with CVE→ATT&CK mapping and LogNorm/HuntForge integration | Part of Nebula…

exploitationinformation-gatheringred-teaming+5
1
2 months ago
CVE-2026-52782 preview

CVE-2026-52782

GitHubabraxas/cve-2026-52782

Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive…

exploitationinformation-gatheringlabs-practice+5
3 days ago
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
422 days ago
CVE-2026-90817 preview

CVE-2026-90817

GitHubfarih123/cve-2026-90817

Python checker and configurable exploit hook for CVE-2026-90817, fingerprinting REDCap instances, validating survey hashes, and probing __passthru…

exploitationinformation-gatheringpenetration-testing+5
3 days ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubhitechcloud-vietnam/cve-2026-41940-poc

Exploits CVE-2026-41940, a cPanel & WHM authentication bypass, to gain root WHM access and run post-exploitation commands, file reads, and account…

authenticationcommand-and-controlexploitation+8
2 days ago
XXERipper preview

XXERipper

GitHubkamalx06/xxeripper

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

api-security-testingdata-exfiltrationexploitation+9
3 days ago
file-notification-attacks preview

file-notification-attacks

GitHubisec-tugraz/file-notification-attacks

Research artifacts for file-notification side-channel attacks on Linux, Windows, and macOS, demonstrating inotify/FSEvents leakage, keystroke timing,…

android-securityeducationexploitation+6
17 days ago
Ch4120N-CVE-Pulse preview

Ch4120N-CVE-Pulse

GitHubch4120n/ch4120n-cve-pulse

Live CVE PoC (Proof-of-Concepts) Aggregator with Smart Search & Threat Intelligence

curated-resourcesexploitationinformation-gathering+8
33 days ago
CVE-2026-14281 preview

CVE-2026-14281

GitHubmurrez/cve-2026-14281

Unauthenticated privilege escalation in WordPress WAWP (Automation Web Platform) ≤ 4.8.6 via public REST signup and unsanitized wawp_custom_fields →…

exploitationpenetration-testingprivilege-escalation+5
13 days ago
CVE-2026-48842 preview

CVE-2026-48842

GitHubmurrez/cve-2026-48842

Python checker for CVE-2026-48842, a pre-auth SQL injection in Roundcube Webmail's virtuser_query plugin. Detects version, plugin path, and verifies…

exploitationinformation-gatheringpenetration-testing+4
3 days ago
CVE-2026-89055 preview

CVE-2026-89055

GitHubmurrez/cve-2026-89055

Python check/exploit PoC for CVE-2026-89055, an unauthenticated authorization bypass in Customer Reviews for WooCommerce that lets attackers link…

exploitationpenetration-testingreconnaissance+4
3 days ago
CVE-2026-93399 preview

CVE-2026-93399

GitHubmurrez/cve-2026-93399

Python PoC for CVE-2026-93399, an unauthenticated IDOR in Bookly <= 28.2 that leaks order tokens, exposes appointments, and rolls back bookings.

exploitationinformation-gatheringpenetration-testing+4
3 days ago
VectorFreed preview

VectorFreed

GitHubrafabd1/vectorfreed

Documents the VectorFreed librsvg use-after-free RCE chain (CVE-2026-96889) with an SVG generator PoC and remediation guidance for librsvg, Next.js,…

binary-exploitationexploitationinformation-gathering+4
84 days ago
NotCVE-2026-0014 preview

NotCVE-2026-0014

GitHubcduram/notcve-2026-0014

Proof-of-concept and advisory for a CWE-22 path traversal in InputLeap's drag-and-drop handler, with reproduction steps, exploit script, and…

exploitationinformation-gatheringpenetration-testing+2
4 days ago
CVE-2026-72001-Pangolin-Cross-Org-Auth-Bypass preview

CVE-2026-72001-Pangolin-Cross-Org-Auth-Bypass

GitHubbiitts/cve-2026-72001-pangolin-cross-org-auth-bypass

PoC for CVE-2026-72001 — Pangolin < 1.22.0 cross-organization resource authentication bypass via the share-link access-token endpoint (CWE-639, CVSS…

authenticationexploitationinformation-gathering+4
4 days ago
CVE-2026-12227 preview

CVE-2026-12227

GitHubmurrez/cve-2026-12227

Python 3 PoC and scanner for CVE-2026-12227, an unauthenticated local file inclusion in WordPress Visual Composer Website Builder via the…

exploitationinformation-gatheringpenetration-testing+5
4 days ago
cve-2026-87902 preview

cve-2026-87902

GitHubzyphorixofficialmain-lab/cve-2026-87902

Python exploit for CVE-2026-87902, a WordPress Core LFI-to-RCE chain. Fingerprints versions, writes a PHP shell via pearcmd, and provides command…

exploitationinformation-gatheringpayload-development+6
4 days ago
Enigm-Writeup preview

Enigm-Writeup

GitHubabdelhakimgafernetworksec/enigm-writeup

Comprehensive penetration testing write-up and exploit details for Hack The Box - Enigma machine, covering local enumeration, OliveTin CVE-2026-27626…

ctfeducationexploitation+7
15 days ago
Previous12…100Next