Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write preview

CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

GitHubbiitts/cve-2026-82286-gpt-crawler-arbitrary-file-write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

educationexploitationlabs-practice+3
1 day ago
llm-agent-testbed preview

llm-agent-testbed

GitHubpie-script/llm-agent-testbed

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

ai-securityapi-securityeducation+4
93 days ago
CVE-2026-56705 preview

CVE-2026-56705

GitHubboreas37/cve-2026-56705

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

educationexploitationlabs-practice+4
24 days ago
cve-2026-21440-writeup-poc preview

cve-2026-21440-writeup-poc

GitHubk0nnect/cve-2026-21440-writeup-poc

poc and writeup for cve-2026-21440: a critical path traversal vulnerability in @adonisjs/bodyparser allowing arbitrary file writing

curated-resourceseducationexploitation+4
47 months ago
jinjava-cve-2026-25526-poc preview

jinjava-cve-2026-25526-poc

GitHubav4nth1ka/jinjava-cve-2026-25526-poc

Step-by-step exploit harness and proof-of-concept for CVE-2026-25526 in Jinjava, demonstrating file read, file creation, and info disclosure with…

educationexploitationlabs-practice+2
26 months ago
CVE-2026-44656 preview

CVE-2026-44656

GitHubcryingn/cve-2026-44656

Reproduction environment for CVE-2026-44656, a Vim modeline command injection vulnerability. Includes Docker setup, PoC file, and exploit script to…

binary-exploitationeducationexploitation+2
13 months ago
WordPress-Path-Traversal-CVE-2019-11447 preview

WordPress-Path-Traversal-CVE-2019-11447

GitHubcapivara-research/wordpress-path-traversal-cve-2019-11447

Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including…

educationexploitationlabs-practice+3
7 days ago
CVE-2026-10053-lab preview

CVE-2026-10053-lab

GitHubdinosn/cve-2026-10053-lab

Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). Vulnerable 19.2.1 vs patched 19.2.2,…

educationexploitationlabs-practice+3
46 days ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

educationexploitationlabs-practice+4
11 days ago
CVE-2021-41773-Apache-Lab preview

CVE-2021-41773-Apache-Lab

GitHubs-amnajafri/cve-2021-41773-apache-lab

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

educationexploitationlabs-practice+4
16 days ago
CVE-2026-14282 preview

CVE-2026-14282

GitHubnullwhisper/cve-2026-14282

GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)

exploitationlabs-practicepenetration-testing+3
117 days ago
Damn_Vulnerable_C_Program preview

Damn_Vulnerable_C_Program

GitHubhardik05/damn_vulnerable_c_program

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

educationfuzzinglabs-practice+1
7271 year ago
OSCE3-Complete-Guide preview

OSCE3-Complete-Guide

GitHubjoasasantos/osce3-complete-guide

OSWE, OSEP, OSED, OSEE

binary-exploitationcurated-resourceseducation+9
3.9k7 months ago
CVE-2026-63223-POC preview

CVE-2026-63223-POC

GitHubimbas007/cve-2026-63223-poc

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

educationexploitationlabs-practice+5
227 days ago
flowise-arbitrary-file-read-getFileFromStorage preview

flowise-arbitrary-file-read-getFileFromStorage

GitHubmajpuv/flowise-arbitrary-file-read-getfilefromstorage

Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path…

data-exfiltrationexploitationinformation-gathering+4
27 days ago
CVE-2021-21972 preview

CVE-2021-21972

GitHubhurrrraaaa/cve-2021-21972

Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection,…

educationexploitationlabs-practice+4
27 days ago
CVE-2026-21858-and-CVE-2025-68613 preview

CVE-2026-21858-and-CVE-2025-68613

GitHubgiangdurian/cve-2026-21858-and-cve-2025-68613

Pre-auth n8n exploit chain: arbitrary file read (CVE-2026-21858) to expression-injection RCE (CVE-2025-68613), with Docker lab, PoC scripts, analysis.

educationexploitationlabs-practice+3
28 days ago
KindaRails2Shell preview

KindaRails2Shell

GitHub0xsha/kindarails2shell

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

exploitationlabs-practicepayload-development+4
229 days ago
Previous12…8Next