Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
CVE-2021-3030 preview

CVE-2021-3030

GitHubathosgonzaga/cve-2021-3030

Advisory: Cute Editor 6.4 reflected XSS via 'Theme' parameter in colorpicker_more.aspx

exploitationpapers-researchvulnerability-analysis+2
2 days ago
CVE-2026-2035703-x300 preview

CVE-2026-2035703-x300

GitHubdanish1162/cve-2026-2035703-x300

Tozed ZLT X300 5G CPE — Remote Root Code Execution via SDR Rogue Base Station (CVE-2026-2035703, CWE-78, CVSS 9.8) — Coordinated Disclosure

binary-analysiseducationexploitation+4
9 days ago
CVE-2026-20841-PoC preview

CVE-2026-20841-PoC

GitHubdogukankurnaz/cve-2026-20841-poc

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

educationexploitationpapers-research+2
26 months ago
CVE-2025-61319 preview

CVE-2025-61319

GitHubamaljafarzade/cve-2025-61319

Stored XSS in ReNgine <= 2.2.0 — public disclosure

exploitationpapers-researchvulnerability-analysis+2
11 months ago
CVE-2026-22849 preview

CVE-2026-22849

GitHublukasz-rybak/cve-2026-22849

CVE-2026-22849 - Saleor lacks proper HTML sanitization in rich text fields

curated-resourceseducationpapers-research+2
4 months ago
CVE-2026-66729-Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash preview

CVE-2026-66729-Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash

GitHubtheopaid/cve-2026-66729-out-of-bounds-read-in-facil.io-mime-parser-leads-to-server-crash

Security Advisory: Out-of-Bounds Read in facil.io MIME Parser leads to Server crash

binary-exploitationeducationpapers-research+2
1 month ago
CVE-2026-66730-Infinite-Loop-DoS-in-facil.io-MIME-Parser preview

CVE-2026-66730-Infinite-Loop-DoS-in-facil.io-MIME-Parser

GitHubtheopaid/cve-2026-66730-infinite-loop-dos-in-facil.io-mime-parser

Security Advisory: Infinite Loop DoS in facil.io MIME Parser (Partial Boundary)

code-analysiseducationpapers-research+2
1 month ago
CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field preview

CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field

GitHubtheopaid/cve-2026-66748-camaleon-cms---authenticated-rce-via-select_eval-custom-field

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

code-analysisexploitationpapers-research+4
1 month ago
CVE-2026-53921 preview

CVE-2026-53921

GitHub0xblackash/cve-2026-53921

CVE-2026-53921

educationiot-securitypapers-research+1
21 month ago
ritecms preview

ritecms

GitHubgurjotexpert/ritecms

CROSS SITE SCRIPTING

curated-resourceseducationpapers-research+3
11 year ago
CVE-2026-0847 preview

CVE-2026-0847

GitHubhyperps/cve-2026-0847

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including…

educationexploitationpapers-research+3
5 months ago
CVE-2026-0897 preview

CVE-2026-0897

GitHubhyperps/cve-2026-0897

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms…

educationexploitationmalware-analysis+2
5 months ago
CVE-2026-0848 preview

CVE-2026-0848

GitHubhyperps/cve-2026-0848

nltk.tokenize.StanfordSegmenter dynamically loads external Java .jar files without verification or sandboxing. If an attacker can supply or replace…

code-analysiseducationexploitation+3
5 months ago
CVE-2026-22692 preview

CVE-2026-22692

GitHublukasz-rybak/cve-2026-22692

CVE-2026-22692 - Critical Twig Sandbox Bypass via collect()->mapInto() allowing RCE/LFI/XXE in October CMS

code-analysiseducationexploitation+3
4 months ago
CVE-2026-23498 preview

CVE-2026-23498

GitHublukasz-rybak/cve-2026-23498

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

code-analysiseducationpapers-research+2
4 months ago
CVE-2026-23499 preview

CVE-2026-23499

GitHublukasz-rybak/cve-2026-23499

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

educationpapers-researchvulnerability-analysis+2
4 months ago
CVE-2026-23500 preview

CVE-2026-23500

GitHublukasz-rybak/cve-2026-23500

CVE-2026-23500 - OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration in Dolibarr

command-and-controleducationexploitation+3
4 months ago
CVE-2026-24419 preview

CVE-2026-24419

GitHublukasz-rybak/cve-2026-24419

CVE-2026-24419 - OpenSTAManager has a SQL Injection in the Prima Nota module

educationpapers-researchpenetration-testing+2
4 months ago
Previous1234Next