Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
74 results
CVE-2026-70376 preview

CVE-2026-70376

GitHubilhomjonr/cve-2026-70376

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

educationexploitationpenetration-testing+3
14 days ago
CVE-2026-17544 preview

CVE-2026-17544

GitHubr2qa/cve-2026-17544

Exploit for CVE-2026-17544: PHP bcmath OOB write converted into memory-only RCE, bypassing disable_functions and open_basedir with a runtime…

binary-exploitationexploitationpayload-development+4
10 days ago
chyrp-lite-rce-poc preview

chyrp-lite-rce-poc

GitHubiltosec/chyrp-lite-rce-poc

CVE-2026-53767 + CVE-2026-53768 - Authenticated RCE in Chyrp Lite ≤ 2026.01 via uploads_path blocklist bypass and missing extension validation

educationexploitationpayload-development+4
2 months ago
CVE-2026-65891 preview

CVE-2026-65891

GitHubmurrez/cve-2026-65891

CVE-2026-65891 PoC — Joomla Content Editor file rename vulnerability (auth required, fixed in JCE 2.20.2)

exploitationinformation-gatheringpenetration-testing+4
16 days ago
amasty-chekout-POC-rce preview

amasty-chekout-POC-rce

GitHubchrissec2014/amasty-chekout-poc-rce

my poc for CVE-2026-53787

exploitationpenetration-testingweb-application-exploitation+1
4 days ago
CVE-2026-66492 preview

CVE-2026-66492

GitHubtoanln-cov/cve-2026-66492

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the file upload action - CVSS 6.1

exploitationpenetration-testingvulnerability-analysis+2
17 days ago
CVE-2026-66493 preview

CVE-2026-66493

GitHubtoanln-cov/cve-2026-66493

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

data-exfiltrationexploitationpenetration-testing+3
17 days ago
CVE-2026-66491 preview

CVE-2026-66491

GitHubtoanln-cov/cve-2026-66491

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

exploitationinformation-gatheringpenetration-testing+3
17 days ago
crlf-powered-desync-scanner preview

crlf-powered-desync-scanner

GitHubt0xodile/crlf-powered-desync-scanner

Burp extension scanner for CRLF injection and HTTP desync attacks, using mutated probes, WAF false-positive checks, and optional…

exploitationpenetration-testingweb-application-exploitation+2
171 month ago
e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout preview

e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

GitHubhunt-benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

database-securityeducationexploitation+4
219 days ago
CVE-2026-4040-Race-Condition-in-File-Upload-Leading-to-RCE preview

CVE-2026-4040-Race-Condition-in-File-Upload-Leading-to-RCE

GitHubgeorge0papasotiriou/cve-2026-4040-race-condition-in-file-upload-leading-to-rce

Reproduces CVE-2026-4040: Flask upload server with TOCTOU race condition and exploit script demonstrating arbitrary remote code execution.

educationexploitationpenetration-testing+2
23 days ago
extloader preview

extloader

GitHubsynacktiv/extloader

A chromium extension exploitation toolkit

exploitationinformation-gatheringpenetration-testing+4
2710 months ago
CVE-2025-61304 preview

CVE-2025-61304

GitHubpentastic-be/cve-2025-61304

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

exploitationpayload-generationpost-exploitation+3
210 months ago
PIL-CVE-2017-8291-study preview

PIL-CVE-2017-8291-study

GitHubshun1403/pil-cve-2017-8291-study

Educational lab demonstrating CVE-2017-8291 (PIL/GhostScript RCE) via crafted EPS file upload with PNG extension, including Docker setup and PoC…

code-analysiseducationexploitation+3
1 year ago
CVE-2026-46275 preview

CVE-2026-46275

GitHubxxconi/cve-2026-46275

Python exploit for CVE-2026-46725, achieving unauthenticated remote code execution in TYPO3 ceselector extension via PHP object injection and Monolog…

code-analysiseducationexploitation+4
3 months ago
CVE-2026-13001 preview

CVE-2026-13001

GitHubghostpels/cve-2026-13001

Exploit for CVE-2026-13001: Unauthenticated RCE in Podlove Podcast Publisher via extension confusion. Includes mass scanning, interactive shell, and…

educationexploitationpayload-development+3
1 month ago
CVE-2024-47051 preview

CVE-2024-47051

GitHubmallo-m/cve-2024-47051

Mautic < 5.2.3 Authenticated RCE

code-analysisexploitationpayload-development+3
51 year ago
cve-2020-29007 preview

cve-2020-29007

GitHubseqred-s-a/cve-2020-29007

Remote code execution in Mediawiki Score

code-analysisexploitationpenetration-testing+3
5 years ago
Previous12345Next