Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
CVE_POC_test preview

CVE_POC_test

GitHublingchul/cve_poc_test

PoC exploit for CVE-2019-13086 targeting SQL injection and file upload vulnerabilities in CSZ CMS. Includes experimental setup and reproduction code…

educationexploitationlabs-practice+3
6 years ago
CVE-2025-2304-exploit preview

CVE-2025-2304-exploit

GitHubjeanback1/cve-2025-2304-exploit

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

educationexploitationlabs-practice+5
4 months ago
grav-cve-2024-28116 preview

grav-cve-2024-28116

GitHubbebarossi/grav-cve-2024-28116

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

educationexploitationlabs-practice+3
9 days ago
CVE-2023-41892_PoC preview

CVE-2023-41892_PoC

GitHublyccyc/cve-2023-41892_poc

Proof-of-concept scripts and Docker lab for reproducing CVE-2023-41892, a pre-authenticated remote code execution vulnerability in Craft CMS.…

educationexploitationlabs-practice+3
1 month ago
CVE_2018_16763_Proof_of_Concept preview

CVE_2018_16763_Proof_of_Concept

GitHubsaccles/cve_2018_16763_proof_of_concept

A Proof-of-Concept (PoC) exploit for CVE-2018-16763 (Fuel CMS - Preauthenticated Remote Code Execution).

educationexploitationlabs-practice+3
1 year ago
CVE-2026-3395-Lab preview

CVE-2026-3395-Lab

GitHubrootdirective-sec/cve-2026-3395-lab

Educational Docker lab demonstrating CVE-2026-3395, an unauthenticated RCE in MaxSite CMS via the run_php plugin, with vulnerable and patched…

educationexploitationlabs-practice+2
15 months ago
cve-2026-16219-croogo-lab preview

cve-2026-16219-croogo-lab

GitHubhellboy3110/cve-2026-16219-croogo-lab

Safely demonstrates CVE-2026-16219 path traversal in Croogo CMS with a loopback-only PoC, technical analysis, remediation guidance, and standalone…

educationexploitationlabs-practice+3
1 month ago
CVE-2023-27372 preview

CVE-2023-27372

GitHubkiroloskhairy/cve-2023-27372

Safe PoC scanner and Docker lab for CVE-2023-27372, an RCE in SPIP CMS before 4.2.1. Verifies vulnerability via password recovery endpoint without…

educationexploitationlabs-practice+3
7 months ago
CVE-2020-25790 preview

CVE-2020-25790

GitHub7mitu/cve-2020-25790

Dockerized Typesetter CMS environment reproducing CVE-2020-25790 file upload vulnerability, with default admin credentials and a walkthrough for…

educationexploitationlabs-practice+2
53 years ago
Exfiltrated-Machine-Walkthrough---Subrion-CMS-CVE-2021-2220- preview

Exfiltrated-Machine-Walkthrough---Subrion-CMS-CVE-2021-2220-

GitHubnyambiblaise/exfiltrated-machine-walkthrough---subrion-cms-cve-2021-2220-

Step-by-step walkthrough for exploiting Subrion CMS via CVE-2021-2220 on an OffSec lab machine, covering web application exploitation and flag…

ctfeducationlabs-practice+3
8 months ago
CVE-2026-26980-PoC preview

CVE-2026-26980-PoC

GitHubn0bitaemon/cve-2026-26980-poc

Ghost CMS Content API Blind SQL Injection

database-securityexploitationinformation-gathering+4
12 months ago
poc-CVE-2019-9053 preview

poc-CVE-2019-9053

GitHubrideckszz/poc-cve-2019-9053

PoC didático em Python 3 para a CVE-2019-9053, uma SQL Injection time-based blind no CMS Made Simple <= 2.2.9. Esta versão foi adaptada para uso em…

ctfeducationlabs-practice+3
12 months ago
CVE-2019-6249_Hucart-cms preview

CVE-2019-6249_Hucart-cms

GitHubalphabugx/cve-2019-6249_hucart-cms

CVE-2019-6249 Hucart cms 复现环境

educationexploitationlabs-practice+3
14 years ago
ghost-cve-2026-26980 preview

ghost-cve-2026-26980

GitHubdinosn/ghost-cve-2026-26980

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

database-securityeducationexploitation+5
164 months ago
Awesome-RCE-techniques preview

Awesome-RCE-techniques

GitHubp0dalirius/awesome-rce-techniques

Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

curated-resourceseducationexploitation+3
1.9k2 years ago
CVE-2026-26980 preview

CVE-2026-26980

GitHubeqstlab/cve-2026-26980

Ghost Content API SQL Injection

educationexploitationlabs-practice+3
33 months ago
Joomla-CMS-Full-Lifecycle-Pentest preview

Joomla-CMS-Full-Lifecycle-Pentest

GitHubmarwan651/joomla-cms-full-lifecycle-pentest

A comprehensive full-lifecycle penetration testing project on Joomla 4.2.5 exploiting CVE-2023-23752 inside a Dockerized lab environment

educationexploitationinformation-gathering+7
3 months ago
Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954- preview

Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-

GitHubshivanshkuntal/exploitation-of-a-remote-code-execution-vulnerability--cve-2024-7954-

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

educationexploitationinformation-gathering+8
18 months ago