Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
96 results
CVE-2026-87902 preview

CVE-2026-87902

GitHubhassham1/cve-2026-87902

WordPress Core <= 7.1.1 unauthenticated LFI to RCE - validation lab, PoC, nuclei template (GHSA-7hp8-65ch-5whp)

educationexploitationlabs-practice+7
1
3 days ago
CVE-2026-14856-TastyIgniter preview

CVE-2026-14856-TastyIgniter

GitHubjonastrikex/cve-2026-14856-tastyigniter

Technical analysis and PoC for CVE-2026-14856, a stored XSS in TastyIgniter v4.3.0 Media Manager that chains with CSRF to achieve admin account…

exploitationpapers-researchpenetration-testing+3
2 months ago
CVE-2026-19952 preview

CVE-2026-19952

GitHubabraxas/cve-2026-19952

Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab…

exploitationlabs-practicepapers-research+5
7 days ago
CVE-2026-87796 preview

CVE-2026-87796

GitHubabraxas/cve-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

educationexploitationlabs-practice+6
18 days ago
CVE-2026-38526-KrayinCRM preview

CVE-2026-38526-KrayinCRM

GitHubish3ng0m4/cve-2026-38526-krayincrm

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

educationexploitationpapers-research+5
9 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubsolivaquaant/cve-2026-85706

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

data-exfiltrationexploitationinformation-gathering+7
14 days ago
CVE-2026-25645 preview

CVE-2026-25645

GitHubjaycelation/cve-2026-25645

Insecure Temp File Reuse in extract_zipped_paths()

exploitationpapers-researchstatic-analysis+2
6 months ago
CVE-2020-13671 preview

CVE-2020-13671

GitHubivanesk315/cve-2020-13671

Proof-of-concept exploit for CVE-2020-13671, a Drupal file upload vulnerability enabling remote code execution via crafted filenames.

exploitationpapers-researchvulnerability-analysis+2
16 days ago
code-graph-rag-PoC preview

code-graph-rag-PoC

GitHubsqueeze440/code-graph-rag-poc

PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1).

educationexploitationpapers-research+3
15 days ago
CVE-2026-9335-keras-hdf5-externallink preview

CVE-2026-9335-keras-hdf5-externallink

GitHubpaparojonathan/cve-2026-9335-keras-hdf5-externallink

CVE-2026-9335: KerasFileEditor and load_weights follow h5py ExternalLinks, disclosing arbitrary local HDF5 file contents in keras ≤ 3.14.0. Advisory…

curated-resourceseducationexploitation+2
23 days ago
CVE-2026-27280 preview

CVE-2026-27280

GitHubr3n3r0/cve-2026-27280

In-depth analysis and proof-of-concept for CVE-2026-27280, an out-of-bounds write in Adobe DNG SDK's dng_render_task::ProcessArea, reachable via…

android-securitybinary-exploitationexploitation+5
129 days ago
CVE-2026-30480 preview

CVE-2026-30480

GitHubparlakbarann/cve-2026-30480

Proof-of-concept for CVE-2026-30480, a Local File Inclusion vulnerability in LibreNMS NFSen module, demonstrating path traversal to include arbitrary…

educationexploitationpapers-research+2
5 months ago
CVE-2026-29041 preview

CVE-2026-29041

GitHubkx00007/cve-2026-29041

Hi, I’m K, This is my first CVE, which is a Remote Code Execution (RCE) vulnerability. It is the beginning of my journey as a security researcher.

educationexploitationpapers-research+2
26 months ago
cve-2026-21440-writeup-poc preview

cve-2026-21440-writeup-poc

GitHubk0nnect/cve-2026-21440-writeup-poc

poc and writeup for cve-2026-21440: a critical path traversal vulnerability in @adonisjs/bodyparser allowing arbitrary file writing

curated-resourceseducationexploitation+4
48 months ago
CVE-2026-39973-PoC preview

CVE-2026-39973-PoC

GitHubfrawlaboy/cve-2026-39973-poc

Proof of concept (builder) for CVE-2026-39973 (apktool)

educationexploitationpapers-research+2
14 months ago
CVE-disclosures preview

CVE-disclosures

GitHubarchana1122m/cve-disclosures

CVE-2026-3171 and CVE-2026-3170 vulnerability disclosure by Archana M

curated-resourceseducationpapers-research+2
7 months ago
CVE-2026-34070 preview

CVE-2026-34070

GitHubrickidevs/cve-2026-34070

I Found a Zero-Day Vulnerability in langchain — Here’s How It Went

educationexploitationpapers-research+2
6 months ago
CVE-2026-6227 preview

CVE-2026-6227

GitHubpixel-defaultbr/cve-2026-6227

Educational proof-of-concept for CVE-2026-6227, an authenticated Local File Inclusion in BackWPup WordPress plugin, including root cause analysis,…

educationexploitationpapers-research+2
5 months ago
Previous123456Next