Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
PrintSpoofer-ReflectiveDLL preview

PrintSpoofer-ReflectiveDLL

GitHubjonyfilc/printspoofer-reflectivedll

The Windows Print Spooler privilege escalation vulnerability (CVE-2019-1040/CVE-2019-1019) has been implemented as a Reflective DLL for penetration…

exploitationlateral-movementpayload-development+4
2
24 days ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
411 month ago
POC-CVE-2026-0300-exploit preview

POC-CVE-2026-0300-exploit

GitHubsam00/poc-cve-2026-0300-exploit

Palo Alto - CVE-2026-0300 exploit

binary-exploitationexploitationnetwork-security+6
1 month ago
CVE-2026-60004-POC preview

CVE-2026-60004-POC

GitHubimbas007/cve-2026-60004-poc

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

exploitationpayload-developmentpenetration-testing+4
171 month ago
CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field preview

CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field

GitHubtheopaid/cve-2026-66748-camaleon-cms---authenticated-rce-via-select_eval-custom-field

Security Advisory: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field

code-analysisexploitationpapers-research+4
1 month ago
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
1 month ago
tgt-monitor-bof preview

tgt-monitor-bof

GitHubjakobfriedl/tgt-monitor-bof

Async BOF to automatically extract or renew Kerberos TGTs on a target system.

authenticationlateral-movementpayload-development+3
1351 month ago
CVE-2026-50979 preview

CVE-2026-50979

GitHubbugresearch/cve-2026-50979

oPanel Authanticated Remote Code Execution via 'advenced/curl' Component

command-and-controlexploitationpayload-development+3
2 months ago
khaos-c2 preview

khaos-c2

GitHub28zaaky/khaos-c2

KHAOS is a modern C2 framework that routes agent traffic through cloud services already trusted by enterprise networks.

command-and-controllateral-movementpayload-development+5
2272 months ago
CVE-2025-69212-PoC preview

CVE-2025-69212-PoC

GitHubbridgeralderson/cve-2025-69212-poc

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

command-and-controlexploitationpayload-development+5
42 months ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubayiezola/cve-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

exploitationinformation-gatheringpayload-development+4
2 months ago
DCOMIllusionist preview

DCOMIllusionist

GitHubsynacktiv/dcomillusionist

DCOM in memory and fileless lateral movement techniques through .Net deserilization

authenticationcommand-and-controlexploitation+7
2912 months ago
By-Poloss..-..CVE-2017-20251 preview

By-Poloss..-..CVE-2017-20251

GitHubpolosss/by-poloss..-..cve-2017-20251

Insert PHP Plugin PHP Code Injection

code-analysiseducationexploitation+4
13 months ago
Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit preview

Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit

GitHub0x00phantom-hat/hoverfly-1.11.3-rce-cve-2025-54123-exploit

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

command-and-controleducationexploitation+6
13 months ago
CVE-2026-46275 preview

CVE-2026-46275

GitHubxxconi/cve-2026-46275

Python exploit for CVE-2026-46725, achieving unauthenticated remote code execution in TYPO3 ceselector extension via PHP object injection and Monolog…

code-analysiseducationexploitation+4
3 months ago
CVE-2026-3296 preview

CVE-2026-3296

GitHubxxconi/cve-2026-3296

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

code-analysisexploitationpayload-development+3
3 months ago
CVE-2026-5718 preview

CVE-2026-5718

GitHubxxconi/cve-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

code-analysisexploitationpayload-development+5
3 months ago
CVE-2026-33017-langflow-rce preview

CVE-2026-33017-langflow-rce

GitHubr3nsi15/cve-2026-33017-langflow-rce

Proof-of-concept exploit for CVE-2026-33017 demonstrating unauthenticated remote code execution in Langflow via malicious CustomComponent injection…

educationexploitationpayload-development+4
3 months ago
Previous12345Next