Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3108 results
CVE-2026-48017 preview

CVE-2026-48017

GitHubromain-deperne/cve-2026-48017

Remote Code Execution in DbGate via functionName injection in the loadReader endpoint — CVSS 8.8

code-analysiseducationexploitation+4
2 months ago
CVE-2026-49009 preview

CVE-2026-49009

GitHubinteleon404/cve-2026-49009

Mender Server - Authenticated Path Traversal to RCE

exploitationpayload-developmentpenetration-testing+3
2 months ago
honda preview

honda

GitLabnu11secur1ty/0

Exploit for a Windows Defender race condition that escalates to SYSTEM via use-after-free, crashes MsMpEng.exe, spawns a hidden shell, and persists…

binary-exploitationexploitationpayload-development+3
2 months ago
CVE-2018-9276 preview

CVE-2018-9276

GitHubbardlaudian/cve-2018-9276

CVE-2018-9276 — PRTG Network Monitor < 18.2.39 Authenticated RCE. For educational purposes and authorized penetration testing only.

command-and-controleducationexploitation+5
2 months ago
CVE-2021-34427 preview

CVE-2021-34427

GitHubrt1252/cve-2021-34427

Windows POC for CVE-2021-34427 affecting Birt Viewer

exploitationpayload-developmentpenetration-testing+2
2 months ago
CVE-2012-1823 preview

CVE-2012-1823

GitHubk3ystr0k3r/cve-2012-1823

CVE-2012-1823 - PHP CGI Argument Injection Remote Code Execution (RCE)

educationexploitationpayload-development+3
2 months ago
CVE-2026-54350-Budibase-NoSQL-Injection preview

CVE-2026-54350-Budibase-NoSQL-Injection

GitHubbiitts/cve-2026-54350-budibase-nosql-injection

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

database-securityexploitationpayload-development+4
1 month ago
metabase-cve-2023-38646 preview

metabase-cve-2023-38646

GitHubkushiro45/metabase-cve-2023-38646

Repo contains the PoC and steps to reproduce cve 2023-38646

exploitationpayload-developmentpenetration-testing+3
1 month ago
aapanel-ws-bypass preview

aapanel-ws-bypass

GitHubeonsecurity/aapanel-ws-bypass

aaPanel WebSocket CSRF Bypass leading to RCE (Incomplete fix for CVE-2021-37840)

exploitationpayload-developmentpenetration-testing+3
2 months ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubs4dbrd/cve-2020-9496

Exploit script for Apache OFBiz CVE-2020-9496 unsafe deserialization vulnerability, enabling remote code execution via crafted XML-RPC requests with…

exploitationpayload-developmentremote-access-tool+2
45 years ago
CVE-2025-39866 preview

CVE-2025-39866

GitHubbytereaper77/cve-2025-39866

Proof of concept for CVE-2025-39866 (UAF and race condition)

binary-exploitationeducationexploitation+2
411 months ago
sendmail-clamav-exploit-CVE-2007-4560 preview

sendmail-clamav-exploit-CVE-2007-4560

GitHubstrikoder-premium/sendmail-clamav-exploit-cve-2007-4560

Python RCE exploit for Sendmail with ClamAV-Milter <0.91.2 (CVE-2007-4560). Remote root command injection via SMTP RCPT TO headers.

command-and-controlexploitationpayload-development+3
48 months ago
CVE-2025-59528 preview

CVE-2025-59528

GitHubmoon-harvest/cve-2025-59528

Go Proof of Concept (PoC) exploit for Flowise CustomMCP Remote Code Execution (RCE) CVE-2025-59528

exploitationpayload-developmentpenetration-testing+3
2 months ago
CVE-2026-5027-Langflow preview

CVE-2026-5027-Langflow

GitHublayer-6/cve-2026-5027-langflow

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

command-and-controlexploitationpayload-development+8
2 months ago
EXPLOIT-CVE-2026-26216 preview

EXPLOIT-CVE-2026-26216

GitHubjoaovicdev/exploit-cve-2026-26216

Proof-of-concept exploit for CVE-2026-26216, demonstrating unauthenticated remote code execution via hook injection in Crawl4AI's Docker deployment.…

educationexploitationlabs-practice+4
1 month ago
cve-2025-57819-exploit preview

cve-2025-57819-exploit

GitHubits1zero/cve-2025-57819-exploit

Python exploit for CVE-2025-57819 targeting FreePBX via unauthenticated SQL injection to achieve remote code execution with automatic reverse shell…

exploitationpayload-developmentpenetration-testing+4
2 months ago
F5-BIG-IP preview

F5-BIG-IP

GitHubdevrafaelprogrammer/f5-big-ip

O F5 BIG-IP é uma plataforma de entrega e segurança de aplicações amplamente utilizada em ambientes corporativos. A CVE-2020-5902 é uma…

command-and-controleducationexploitation+5
2 months ago
CVE-2026-33453 preview

CVE-2026-33453

GitHuboscerd/cve-2026-33453

Reproducer for CVE-2026-33453: Apache Camel camel-coap header injection to RCE via camel-exec

educationexploitationpayload-development+3
1 month ago
Previous1…929394…100Next