Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
233 results
CVE-2026-39808 preview

CVE-2026-39808

GitHub0xblackash/cve-2026-39808

CVE-2026-39808

command-and-controleducationexploitation+5
25 months ago
CVE-2026-40897 preview

CVE-2026-40897

GitHubeqstlab/cve-2026-40897

Math.js Expression Parser RCE

educationexploitationpayload-development+3
21 month ago
cve-2026-0770-langflow_rce_reproduction preview

cve-2026-0770-langflow_rce_reproduction

GitHubrazureink/cve-2026-0770-langflow_rce_reproduction

CVE Reproduction: cve-2026-0770-langflow_rce_reproduction

educationexploitationlabs-practice+4
2 months ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubcd-ratel/cve-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

ctfeducationexploitation+4
24 months ago
CVE-2025-67435-PoC preview

CVE-2025-67435-PoC

GitHubrajchowdhury240/cve-2025-67435-poc

PluckCMS 4.7.20 Zip Slip vulnerability Led to RCE

educationexploitationpayload-development+3
2 months ago
CVE-2019-9978 preview

CVE-2019-9978

GitHubyup-ivan/cve-2019-9978

POC (RCE) -> CVE-2019-9978

educationexploitationpayload-development+3
48 months ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubbayu06802/cve-2026-48908

Proof-of-concept exploit for CVE-2026-48908, an unauthenticated RCE in Joomla SP Page Builder via arbitrary file upload, with adaptive payload…

ctfeducationexploitation+4
2 months ago
CVE-2018-7600-Drupalgeddon2-RCE preview

CVE-2018-7600-Drupalgeddon2-RCE

GitHubshams-ul-mehmood/cve-2018-7600-drupalgeddon2-rce

Educational CVE-2018-7600 exploit project combining a Python RCE PoC, isolated Docker Drupal lab, payload research, and mitigation documentation for…

educationexploitationlabs-practice+5
1 month ago
CVE-2026-33017-Langflow-RCE preview

CVE-2026-33017-Langflow-RCE

GitHubindustri4l-h3ll-xpl0it3rs/cve-2026-33017-langflow-rce

CVE-2026-33017 Exploit | by infrar3d

educationexploitationpayload-development+3
12 months ago
cve-2025-43564-tomcat_put_rce_reproduction preview

cve-2025-43564-tomcat_put_rce_reproduction

GitHubrazureink/cve-2025-43564-tomcat_put_rce_reproduction

Reproduction of cve-2025-43564-tomcat_put_rce_reproduction

educationexploitationpayload-development+3
12 months ago
CVE-2026-68771_exploit preview

CVE-2026-68771_exploit

GitHub0xdak/cve-2026-68771_exploit

Unauthenticated exploit for CVE-2026-68771, a pickle deserialization RCE in ComfyUI. Plants a crafted shard via /upload/image, triggers it through…

educationexploitationpayload-development+3
11 month ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubeqstlab/cve-2026-16723

PoC exploit for Fastjson RCE (CVE-2026-16723) featuring automated JAR payload generation and delivery via crafted JSON, bypassing AutoType…

educationexploitationpayload-development+3
11 month ago
CVE-2026-56121_exploit preview

CVE-2026-56121_exploit

GitHub0xdak/cve-2026-56121_exploit

Unauthenticated RCE exploit for Feast registry gRPC server (CVE-2026-56121) using dill deserialization. Includes payload generation, reverse shell…

educationexploitationpayload-development+3
12 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubpssec-io/cve-2026-48907

POC for CVE-2026-48907

educationexploitationlabs-practice+5
12 months ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubthemursalin/cve-2025-32432

Exploit for Craft CMS pre-authentication RCE (CVE-2025-32432) chaining session poisoning with insecure deserialization to execute arbitrary commands…

educationexploitationpayload-development+3
5 months ago
CVE-2025-50286 preview

CVE-2025-50286

GitHubbinneko/cve-2025-50286

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

educationexploitationpayload-development+3
21 year ago
react2shell-scanner-CVE-2025-55182 preview

react2shell-scanner-CVE-2025-55182

GitHubsecurity-phoenix-demo/react2shell-scanner-cve-2025-55182

React2shell-web-scanner

educationexploitationioc-management+6
29 months ago
Cve-2024-38063 preview

Cve-2024-38063

GitHubbrownpanda29/cve-2024-38063

Exploit code and technical analysis for CVE-2024-38063, a critical Windows TCP/IP RCE vulnerability, including CVSS metrics and exploitation details…

educationexploitationpayload-development+3
12 years ago
Previous1…10111213Next