Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
203 results
CVE-2025-49844 preview

CVE-2025-49844

GitHubzain3311/cve-2025-49844

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

command-and-controlexploitationpayload-development+3
2
6 days ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubmr-destroyer/cve-2025-55182

Exploit for CVE-2025-55182 enabling remote code execution via prototype pollution in Next.js React Server Components, with command execution and…

exploitationlabs-practicepayload-development+4
6 days ago
CVE-2026-31816 preview

CVE-2026-31816

GitHubk3ystr0k3r/cve-2026-31816

CVE-2026-31816 - Budibase Authentication Bypass to RCE

api-securityauthentication-authorizationexploitation+3
216 days ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

educationexploitationpayload-development+3
322 days ago
CVE-2026-60004-POC preview

CVE-2026-60004-POC

GitHubimbas007/cve-2026-60004-poc

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

exploitationpayload-developmentpenetration-testing+4
1627 days ago
CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation- preview

CVE-2026-6666-XPC-Service-NSKeyedUnarchiver-Deserialization-Attack-macOS-iOS-simulation-

GitHubgeorge0papasotiriou/cve-2026-6666-xpc-service-nskeyedunarchiver-deserialization-attack-macos-ios-simulation-

Simulated macOS/iOS XPC service vulnerable to NSKeyedUnarchiver deserialization, plus exploit demonstration and crafted plist payload for RCE via…

educationexploitationios-security+3
27 days ago
CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle preview

CVE-2026-9998-Insecure-Deserialization-in-Blockchain-Oracle

GitHubgeorge0papasotiriou/cve-2026-9998-insecure-deserialization-in-blockchain-oracle

PoC for CVE-2026-9998: RCE via insecure Python pickle deserialization in a blockchain oracle, with vulnerable node simulation and exploit script.

exploitationpayload-developmentvulnerability-analysis
27 days ago
CVE-2026-13158 preview

CVE-2026-13158

GitHubminhhk68/cve-2026-13158

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

exploitationpayload-developmentpenetration-testing+4
29 days ago
KindaRails2Shell preview

KindaRails2Shell

GitHub0xsha/kindarails2shell

Single-file PoC for Rails CVE-2026-66066: arbitrary file read, secret recovery, threaded scanning, and conditional RCE via signed image variations.

exploitationlabs-practicepayload-development+4
21 month ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
1 month ago
wp2shell preview

wp2shell

GitHubmcipekci/wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

command-and-controlexploitationpayload-development+7
151 month ago
wp2shell-scanner preview

wp2shell-scanner

GitHubbahartanir/wp2shell-scanner

CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner

exploitationlabs-practicepayload-development+5
81 month ago
CVE-2026-31431-simple-test preview

CVE-2026-31431-simple-test

GitHubtematemaru/cve-2026-31431-simple-test

Educational proof-of-concept demonstrating CVE-2026-31431 with a vulnerable target application, demonstration payload, and shellcode extraction…

binary-exploitationeducationexploitation+3
1 month ago
CVE-2026-50979 preview

CVE-2026-50979

GitHubbugresearch/cve-2026-50979

oPanel Authanticated Remote Code Execution via 'advenced/curl' Component

command-and-controlexploitationpayload-development+3
1 month ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub0x00jeff/cve-2025-27591

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

binary-exploitationexploitationpayload-development+5
152 months ago
CVE-2026-48732-poc preview

CVE-2026-48732-poc

GitHubsaku0512/cve-2026-48732-poc

Proof-of-concept demonstrating OS command injection in Warp's legacy SSH background command handling (CVE-2026-48732). Includes local simulation of…

command-and-controleducationexploitation+3
2 months ago
CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE- preview

CVE-2026-20253-Splunk-Enterprise-Pre-Auth-RCE-

GitHubfevar54/cve-2026-20253-splunk-enterprise-pre-auth-rce-

Proof-of-concept exploit for CVE-2026-20253, enabling unauthenticated remote code execution on vulnerable Splunk Enterprise instances via file write…

command-and-controlexploitationpayload-development+5
2 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubliaoziqi-gzfls/cve-2026-42945

CVE-2026-42945 Nginx Rift

binary-exploitationexploitationfuzzing+6
12 months ago
Previous12…12Next