Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
CVE_2025_24257----NOT-MINE preview

CVE_2025_24257----NOT-MINE

GitHublearningdisordercapital35/cve_2025_24257----not-mine

Demonstrate CVE-2025-24257 with a public PoC for IOGPUFamily kernel heap OOB read/write and panic analysis

binary-exploitationexploitationmemory-forensics+2
2 days ago
Zapscape preview

Zapscape

GitHubaarif450/zapscape

Guest-to-host KVM/x86 escape exploiting CVE-2026-64561, delivering a full PoC chain and analysis for security researchers.

binary-exploitationdefensive-toolsexploitation+2
15 days ago
CVE-2026-29053 preview

CVE-2026-29053

GitHubk3ystr0k3r/cve-2026-29053

Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

exploitationpayload-developmentpenetration-testing+5
16 days ago
CVE-2025-58434 preview

CVE-2025-58434

GitHubr3vpwnx/cve-2025-58434

Exploit chain for Flowise 3.0.5: unauthenticated account takeover via password-reset token disclosure (CVE-2025-58434) chained to CustomMCP…

authenticationexploitationpenetration-testing+3
24 days ago
CVE-2025-29471 preview

CVE-2025-29471

GitHubskraft9/cve-2025-29471

Stored XSS in Nagios Log Server 2024R1.3.1

exploitationpenetration-testingprivilege-escalation+3
128 days ago
CVE-2026-30251 preview

CVE-2026-30251

GitHubvenablee/cve-2026-30251

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

api-securityexploitationpayload-development+4
1 month ago
CVEX2SHEL preview

CVEX2SHEL

GitHubalixploit22/cvex2shel

CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
CVE-2026-67340_exploit preview

CVE-2026-67340_exploit

GitHub0xdak/cve-2026-67340_exploit

Post-auth RCE exploit for ArcadeDB via JavaScript trigger GraalVM sandbox escape, executing OS commands over HTTP API with reverse shell or blind…

database-securityexploitationpenetration-testing+1
1 month ago
wp2shell-poc-fulljs preview

wp2shell-poc-fulljs

GitHubraphy76/wp2shell-poc-fulljs

full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

exploitationpayload-generationpenetration-testing+2
2 months ago
singularity preview

singularity

GitHubnccgroup/singularity

A DNS rebinding attack framework.

dns-analysisexploitationinformation-gathering+6
1.3k2 months ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

command-and-controlexploitationpayload-generation+5
52 months ago
CVE-2026-26719 preview

CVE-2026-26719

GitHubibrahim-sartawi/cve-2026-26719

A stored Cross‑Site Scripting vulnerability exists in xxl-job-admin JobInfoController.java where the addressList parameter accepts unsanitized…

exploitationpenetration-testingvulnerability-analysis+2
12 months ago
CVE-2025-68147-OSPOS-Stored-XSS preview

CVE-2025-68147-OSPOS-Stored-XSS

GitHubnixon-h/cve-2025-68147-ospos-stored-xss

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

code-analysiseducationexploitation+3
23 months ago
CVE-2026-47423-dompurify-xss-detector preview

CVE-2026-47423-dompurify-xss-detector

GitHubgalaxy-sc/cve-2026-47423-dompurify-xss-detector

Go-based scanner that detects DOMPurify sanitizer bypass (CVE-2026-47423) via logic fingerprinting on minified production JavaScript bundles,…

exploitationpenetration-testingstatic-analysis+2
4 months ago
Bludit-3.13.1-TAGS-Field-Stored-Cross-Site-Scripting-XSS preview

Bludit-3.13.1-TAGS-Field-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/bludit-3.13.1-tags-field-stored-cross-site-scripting-xss

CVE-2021-45744 - A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. Application stores…

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
CVE-2021-45744 preview

CVE-2021-45744

GitHubsanupl/cve-2021-45744

CVE-2021-45744 - A Stored Cross Site Scripting (XSS) vulnerability exists in bludit 3.13.1 via the TAGS section in login panel. Application stores…

exploitationpenetration-testingvulnerability-analysis+2
14 months ago
Bludit-3.13.1-About-Plugin-Stored-Cross-Site-Scripting-XSS preview

Bludit-3.13.1-About-Plugin-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/bludit-3.13.1-about-plugin-stored-cross-site-scripting-xss

CVE-2021-45745 - A Stored Cross Site Scripting (XSS) vulnerability exists in Bludit 3.13.1 via the About Plugin in login panel. Application stores…

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
Previous1234567Next