Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
CVE-2024-46986 preview

CVE-2024-46986

GitHubvidura2/cve-2024-46986

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

educationexploitationpayload-development+3
3
1 year ago
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationpayload-developmentpenetration-testing+3
19 days ago
CVE-2026-67206 preview

CVE-2026-67206

GitHubanirbala98/cve-2026-67206

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

educationexploitationpayload-development+3
18 days ago
CVE-2026-48909 preview

CVE-2026-48909

GitHubis4yev/cve-2026-48909

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

code-analysiseducationexploitation+4
231 month ago
CVE-2020-23839 preview

CVE-2020-23839

GitHubboku7/cve-2020-23839

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

exploitationpayload-developmentpenetration-testing+3
115 years ago
CVE-2025-50754-PoC preview

CVE-2025-50754-PoC

GitHubfurk4nyildiz/cve-2025-50754-poc

Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)

exploitationpayload-developmentpenetration-testing+3
41 year ago
CVE-2025-50286 preview

CVE-2025-50286

GitHubbinneko/cve-2025-50286

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

educationexploitationpayload-development+3
21 year ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubcd-ratel/cve-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

ctfeducationexploitation+4
23 months ago
CVE-2019-10068-PoC preview

CVE-2019-10068-PoC

GitHubcianananan/cve-2019-10068-poc

Proof of concept exploit for CVE-2019-10068.

exploitationpayload-developmentpenetration-testing+2
5 months ago
CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field preview

CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field

GitHubtheopaid/cve-2026-66748-camaleon-cms---authenticated-rce-via-select_eval-custom-field

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

code-analysisexploitationpapers-research+4
1 month ago
CVE-2025-15467 preview

CVE-2025-15467

GitHubguiimoraes/cve-2025-15467

Command Execution PoC for OpenSSL Stack buffer overflow CVE-2025-15467

binary-exploitationcryptographyeducation+5
156 months ago
CVE-2021-38817-Remote-OS-Command-Injection preview

CVE-2021-38817-Remote-OS-Command-Injection

GitHubhuskyhacks/cve-2021-38817-remote-os-command-injection

Remote OS Command Injection in TastyIgniter v3.0.7 Sendmail Path field

command-and-controlexploitationpayload-development+3
93 years ago
Dolibarr-17.0.0-Exploit-CVE-2023-30253 preview

Dolibarr-17.0.0-Exploit-CVE-2023-30253

GitHubdollarboysushil/dolibarr-17.0.0-exploit-cve-2023-30253

In Dolibarr 17.0.0 with the CMS Website plugin (core) enabled, an authenticated attacker can obtain remote command execution via php code injection…

code-analysisexploitationpayload-development+3
92 years ago
CVE-2020-25042-PoC preview

CVE-2020-25042-PoC

GitHubgroppoxx/cve-2020-25042-poc

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

exploitationpayload-developmentpenetration-testing+3
53 months ago
CVE-2023-41892 preview

CVE-2023-41892

GitHubzaenhaxor/cve-2023-41892

CVE-2023-41892 - Craft CMS Remote Code Execution (RCE)

exploitationpayload-developmentpenetration-testing+2
32 years ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubc0gnit00/cve-2025-32432

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

exploitationpayload-developmentpenetration-testing+3
31 month ago
Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954- preview

Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-

GitHubshivanshkuntal/exploitation-of-a-remote-code-execution-vulnerability--cve-2024-7954-

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

educationexploitationinformation-gathering+8
18 months ago
CVE-2025-67435 preview

CVE-2025-67435

GitHubrajchowdhury240/cve-2025-67435

A critical Remote Code Execution (RCE) vulnerability has been identified in PluXML CMS version 5.8.22. This vulnerability allows authenticated…

code-analysisexploitationpayload-development+3
18 months ago
Previous12Next