Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
115 results
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
5
2 days ago
cve-2026-75157-poc preview

cve-2026-75157-poc

GitHublicitrasimone/cve-2026-75157-poc

Standalone authorized universal HTTP PoC for CVE-2026-75157

api-security-testingexploitationpenetration-testing+3
6 days ago
CVE-2026-65013-BOLA-IDOR preview

CVE-2026-65013-BOLA-IDOR

GitHubisaca0315/cve-2026-65013-bola-idor

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

api-security-testingauthentication-authorizationeducation+7
11 days ago
your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack preview

your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

GitHubhunt-benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

Proof-of-concept exploit for CVE-2026-68929, demonstrating unauthenticated cross-tenant takeover of FastGPT WeChat channels via public shareId,…

api-security-testingexploitationpenetration-testing+3
27 days ago
wpprobe preview

wpprobe

GitHubchocapikk/wpprobe

A fast WordPress plugin enumeration tool

api-security-testingcrawlerexploitation+5
9531 month ago
CVE-2026-9198 preview

CVE-2026-9198

GitHubk3ystr0k3r/cve-2026-9198

PoC and detection guide for the critical unauthenticated RCE in IBM Langflow OSS, covering the auto_login token bypass and unsafe /validate/code…

api-security-testingexploitationpenetration-testing+2
11 month ago
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

api-security-testingeducationexploitation+4
1 month ago
CVE-2026-34910-PoC preview

CVE-2026-34910-PoC

GitHubboreas37/cve-2026-34910-poc

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

api-security-testingauthenticationexploitation+3
71 month ago
cve-2026-19478 preview

cve-2026-19478

GitHubn0xdaemon/cve-2026-19478

Provides PoC exploits and root-cause analysis for two GitLab GraphQL `@gl_introduced` directive vulnerabilities: unauthenticated method execution and…

api-security-testingexploitationvulnerability-analysis+2
1 month ago
CVE-2026-9830 preview

CVE-2026-9830

GitHubopaxial/cve-2026-9830

CVE-2026-9830 Proof of Concept

api-security-testingexploitationinformation-gathering+3
5211 month ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

api-security-testingcloud-securityexploitation+3
1 month ago
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

api-security-testingauthentication-authorizationcontainer-security+3
11 month ago
gitlab-cve-2026-19478-lab preview

gitlab-cve-2026-19478-lab

GitHubdinosn/gitlab-cve-2026-19478-lab

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

api-security-testingexploitationlabs-practice+4
101 month ago
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

api-security-testingexploitationmisconfiguration+4
1 month ago
CVE-2026-54356 preview

CVE-2026-54356

GitHubkovachvl/cve-2026-54356

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

api-security-testingcloud-securityexploitation+3
1 month ago
ragflow-audit preview

ragflow-audit

GitHubqianlijaingshan/ragflow-audit

RAGFlow 三洞审计工具 (CVE-2026-28797 / CVE-2026-24770 / CVE-2025-69286)

api-security-testingexploitationpenetration-testing+4
11 month ago
CVE-2026-9198 preview

CVE-2026-9198

GitHubcuteecat/cve-2026-9198

CVE-2026-9198利用代码

api-security-testingexploitationpenetration-testing+3
1 month ago
CVE-2025-59528-PoC preview

CVE-2025-59528-PoC

GitHubloaxert/cve-2025-59528-poc

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

api-security-testingeducationexploitation+3
1 month ago
Previous1234567Next