Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
150 results
CVE-2025-68613-POC preview

CVE-2025-68613-POC

GitHubthestingr/cve-2025-68613-poc

Public PoC + Scanner and research for CVE-2025-68613: Critical RCE in n8n Workflow Automation via Expression Injection (CVSS 10.0). Includes…

educationexploitationinformation-gathering+8
29
9 months ago
CVE-2025-55182-Scanner preview

CVE-2025-55182-Scanner

GitHubstealthmoud/cve-2025-55182-scanner

Scanner and exploit toolkit for CVE-2025-55182, a critical pre-auth RCE in React Server Components. Includes detection, interactive shell, Docker…

educationexploitationpayload-development+3
810 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

educationexploitationpayload-development+3
21 month ago
CVE-2026-56158-.NET-Framework-RCE-PoC-Exploit preview

CVE-2026-56158-.NET-Framework-RCE-PoC-Exploit

GitHubsam00/cve-2026-56158-.net-framework-rce-poc-exploit

Generates five .NET deserialization payload formats for CVE-2026-56158, delivers them over HTTP/SOAP/JSON endpoints, includes mock server, scanner,…

exploitationpayload-developmentpayload-generation+4
11 month ago
CVE-2026-48907- preview

CVE-2026-48907-

GitHubxitexploiter96-dot/cve-2026-48907-

Python-based scanner and exploit for CVE-2026-48907, a critical unauthenticated RCE in Joomla JCE Editor. Features safe fingerprinting, CSRF token…

exploitationpayload-developmentpenetration-testing+3
3 months ago
cpanel2shell-scanner preview

cpanel2shell-scanner

GitHubassetnote/cpanel2shell-scanner

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

authenticationexploitationpayload-development+3
924 months ago
CVE-2020-14882-WebLogic-Analysis preview

CVE-2020-14882-WebLogic-Analysis

GitHubvelessecurity/cve-2020-14882-weblogic-analysis

Technical analysis and clean Java Thread Echo PoC for Oracle WebLogic Server vulnerability chain.

exploitationpayload-developmentvulnerability-analysis+1
1 month ago
CVE-2025-55182-checker preview

CVE-2025-55182-checker

GitHubharness-security-labs/cve-2025-55182-checker

Multi-technique vulnerability detector for CVE-2025-55182 in React/Next.js applications. Tests gadget chains, RCE payloads, and WAF bypass variants…

exploitationpayload-developmentpenetration-testing+3
19 months ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9974 months ago
CVE-2026-3228 preview

CVE-2026-3228

GitHubnull200ok/cve-2026-3228

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

exploitationpayload-developmentpenetration-testing+3
26 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubcc3305/cve-2025-55182

Pre-authentication RCE exploit for React Server Components (CVE-2025-55182). Targets unsafe deserialization in react-server-dom packages across…

exploitationpayload-developmentpenetration-testing+2
3 months ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
13 years ago
CVE-2026-28134 preview

CVE-2026-28134

GitHubrandomrobbiebf/cve-2026-28134

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

exploitationpayload-developmentvulnerability-analysis+1
6 months ago
WeblogicScan preview

WeblogicScan

GitHubdr0op/weblogicscan

增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持

exploitationpayload-developmentpenetration-testing+3
9627 years ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub4minx/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

exploitationpayload-developmentpenetration-testing+3
127 days ago
CVE-2026-57811 preview

CVE-2026-57811

GitHub0xcyp1337/cve-2026-57811

Exploits CVE-2026-57811, an unauthenticated RCE in Realtyna Organic IDX + WPL Real Estate WordPress plugin, enabling shell upload and command…

exploitationpayload-developmentpenetration-testing+2
224 days ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubmaximofernandezriera/cve-2021-44228

Proof-of-concept exploit for Log4Shell (CVE-2021-44228) demonstrating remote code execution via JNDI injection, including payload compilation, LDAP…

exploitationpayload-developmentpenetration-testing+2
54 years ago
CVE-2018-15133 preview

CVE-2018-15133

GitHubazharikun/cve-2018-15133

Exploit tool for CVE-2018-15133, a Laravel unserialize RCE, with multiprocessing support for scanning and exploiting vulnerable endpoints.

exploitationpayload-developmentpenetration-testing+2
35 years ago
Previous123…9Next