Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
etaHEN preview

etaHEN

GitHubetahen/etahen

PS5 homebrew enabler payload offering post-exploitation features: custom plugin/payload loading, unsigned fself/fpkg support, debug settings, FTP…

binary-exploitationexploitationpayload-development+3
650
3 months ago
CVE-2026-64824-PoC preview

CVE-2026-64824-PoC

GitHubboreas37/cve-2026-64824-poc

CVE-2026-64824 — Home Assistant backup-restore symlink path traversal → root RCE. First working PoC, verified on real HA 2026.5.4 (sitecustomize.py…

exploitationiot-securitypayload-development+2
14 days ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubdungsocool/cve-2026-64638

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

code-analysisexploitationpayload-development+4
16 days ago
weaponised-XSS-payloads preview

weaponised-XSS-payloads

GitHubhakluke/weaponised-xss-payloads

JavaScript payloads that weaponize XSS bugs into critical impact, enabling account takeover and admin creation on popular CMS platforms for pentest…

exploitationpayload-developmentpayload-generation+3
1.4k2 years ago
PE-Obfuscator preview

PE-Obfuscator

GitHubsaadahla/pe-obfuscator

Obfuscates PE binaries into fileless loaders that add PE sections, unhook ntdll, and exploit signed drivers to remove kernel callbacks for EDR…

adversarial-attackexploitationpayload-development+2
2113 years ago
ZeroHVCI preview

ZeroHVCI

GitHubzer0condition/zerohvci

Achieve arbitrary kernel read/writes/function calling in Hypervisor-Protected Code Integrity (HVCI) protected environments calling without admin…

binary-exploitationexploitationpayload-development+2
2925 months ago
CVE-2025-57819-RCE preview

CVE-2025-57819-RCE

GitHubteteren/cve-2025-57819-rce

PoC exploit for FreePBX 16 chaining CVE-2025-57819 (unauthenticated stacked SQL injection) and CVE-2025-61678 (arbitrary file upload/path traversal)…

exploitationpayload-developmentpenetration-testing+2
24 days ago
CVE-2026-67206 preview

CVE-2026-67206

GitHubanirbala98/cve-2026-67206

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

educationexploitationpayload-development+3
15 days ago
CVE-2026-13158 preview

CVE-2026-13158

GitHubminhhk68/cve-2026-13158

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

exploitationpayload-developmentpenetration-testing+4
24 days ago
WPTimeCapsulePOC preview

WPTimeCapsulePOC

GitHubsecforce/wptimecapsulepoc

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

authenticationexploitationpayload-development+3
56 years ago
CVE-2026-3584 preview

CVE-2026-3584

GitHubyucaerin/cve-2026-3584

Automated mass scanner for CVE-2026-3584, an unauthenticated RCE in WordPress Kali Forms. Executes a 4-phase pipeline: REST API enumeration, form…

exploitationinformation-gatheringpayload-development+5
5 months ago
CVE-2024-1813-POC preview

CVE-2024-1813-POC

GitHubmobetasec/cve-2024-1813-poc

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

ctfeducationlabs-practice+4
2 months ago
EXPLOIT-CVE-2026-40901 preview

EXPLOIT-CVE-2026-40901

GitHubjoaovicdev/exploit-cve-2026-40901

Automated exploit for DataEase: 4-vulnerability chain (auth bypass, JDBC blocklist bypass, SQL injection, Java deserialization) achieving…

educationexploitationlabs-practice+4
11 month ago
CVE-2026-63030-CVE-2026-60137-wp2shell-poc preview

CVE-2026-63030-CVE-2026-60137-wp2shell-poc

GitHubgagaltotal/cve-2026-63030-cve-2026-60137-wp2shell-poc

Proof-of-concept exploit for WordPress REST API time-based blind SQL injection (CVE-2026-63030, CVE-2026-60137) with full chain escalation to remote…

exploitationpayload-developmentpenetration-testing+3
1 month ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubmhtsec/cve-2026-63030

Pre-auth SQL injection to remote code execution exploit for WordPress REST API batch endpoint. Creates admin account and executes system commands via…

exploitationpayload-developmentpenetration-testing+2
121 month ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubadministrator-01001/cve-2026-63030

Proof-of-concept exploit for CVE-2026-63030 chaining REST API route confusion, SQL injection, oEmbed cache poisoning, and Customizer privilege…

exploitationpayload-developmentpenetration-testing+4
11 month ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
12 years ago
CVE-2021-1675 preview

CVE-2021-1675

GitHubthomasgeens/cve-2021-1675

PowerShell exploit for CVE-2021-1675 (PrintNightmare) performing local privilege escalation via Print Spooler, with custom DLL payload injection to…

binary-exploitationexploitationpayload-development+2
35 years ago
Previous123Next