Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
210 results
CVE-2024-28397-command-execution-poc preview

CVE-2024-28397-command-execution-poc

GitHubghostoverflow/cve-2024-28397-command-execution-poc

This vulnerability arises from incomplete sandboxing in js2py, where crafted JavaScript can traverse Python’s internal object model and access…

code-analysisexploitationpayload-development+2
5
1 year ago
ReactOOPS-WriteUp preview

ReactOOPS-WriteUp

GitHubthestingr/reactoops-writeup

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

code-analysisctfeducation+8
78 months ago
CVE-2025-70830 preview

CVE-2025-70830

GitHubxiaoxiaoranxxx/cve-2025-70830

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

code-analysisexploitationpayload-development+3
56 months ago
CVE-2025-68664-LangGrinch-PoC preview

CVE-2025-68664-LangGrinch-PoC

GitHubak-cybe/cve-2025-68664-langgrinch-poc

A testing framework to identify and demonstrate deserialization vulnerabilities in LangChain Core (<0.3.81). Educational use only

ai-securitycode-analysiseducation+6
37 months ago
CVE-2026-5718 preview

CVE-2026-5718

GitHubxxconi/cve-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

code-analysisexploitationpayload-development+5
2 months ago
CVE-2026-44789-n8n-PrototypePollution-RCE preview

CVE-2026-44789-n8n-PrototypePollution-RCE

GitHubbiitts/cve-2026-44789-n8n-prototypepollution-rce

CVE-2026-44789 — n8n <1.123.43 HTTP Request pagination prototype pollution to RCE (NODE_OPTIONS runner-spawn gadget). Lab + automated PoC, verified…

code-analysiseducationexploitation+5
1 month ago
CVE-2026-12277 preview

CVE-2026-12277

GitHubmoritakaaz/cve-2026-12277

Frontend File Manager Plugin (WordPress) <= 23.6 - Unauthenticated Arbitrary File Deletion to RCE

code-analysisexploitationpayload-development+4
1 month ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
21 month ago
CVE-2022-22965_Spring4Shell preview

CVE-2022-22965_Spring4Shell

GitHubludovicpatho/cve-2022-22965_spring4shell

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit…

code-analysisexploitationpayload-development+3
24 years ago
CVE-2026-33454 preview

CVE-2026-33454

GitHuboscerd/cve-2026-33454

Reproducer for CVE-2026-33454: Apache Camel camel-mail header injection to RCE via camel-exec

code-analysisexploitationpayload-development+3
11 month ago
0-click-RCE-Exploit-for-CVE-2024-9932 preview

0-click-RCE-Exploit-for-CVE-2024-9932

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-9932

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

code-analysisexploitationpayload-development+5
27 months ago
CVE-2025-67435 preview

CVE-2025-67435

GitHubrajchowdhury240/cve-2025-67435

A critical Remote Code Execution (RCE) vulnerability has been identified in PluXML CMS version 5.8.22. This vulnerability allows authenticated…

code-analysisexploitationpayload-development+3
17 months ago
analysis-and-poc-n8n-CVE-2025-68613 preview

analysis-and-poc-n8n-CVE-2025-68613

GitHubreleaseown/analysis-and-poc-n8n-cve-2025-68613

Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive…

code-analysiseducationexploitation+5
17 months ago
roundcube-cve-2025-49113-lab preview

roundcube-cve-2025-49113-lab

GitHubankitpandey383/roundcube-cve-2025-49113-lab

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

code-analysisctfeducation+7
9 months ago
CVE-2022-1329 preview

CVE-2022-1329

GitHubdexit/cve-2022-1329

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check…

code-analysisexploitationpayload-development+3
3 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubseoqqq/cve-2018-6574

Remote command execution in Golang go get command allows an attacker to gain code execution on a system by installing a malicious library.

binary-exploitationcode-analysisexploitation+2
3 years ago
CVE-2024-6330 preview

CVE-2024-6330

GitHubrandomrobbiebf/cve-2024-6330

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

code-analysisexploitationpayload-development+3
1 year ago
SC3010-Computer-Security preview
Archived

SC3010-Computer-Security

GitHubaipeacs/sc3010-computer-security

Using Struts2 and PowerShell to recreate CVE-2017-5638 OGNL Injection vulnerability.

code-analysiseducationexploitation+6
3 months ago
Previous123…12Next