Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
CVE-2025-32432 preview

CVE-2025-32432

GitHubc0gnit00/cve-2025-32432

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

exploitationpayload-developmentpenetration-testing+3
3
1 month ago
CVE-2017-9822 preview

CVE-2017-9822

GitHubtranphuc2005/cve-2017-9822

Detailed analysis and proof-of-concept exploit for CVE-2017-9822, an XXE/insecure deserialization vulnerability in DotNetNuke CMS leading to remote…

binary-exploitationexploitationpayload-development+3
11 months ago
CVE-2026-67206 preview

CVE-2026-67206

GitHubanirbala98/cve-2026-67206

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

educationexploitationpayload-development+3
18 days ago
CVE-2024-46986 preview

CVE-2024-46986

GitHubvidura2/cve-2024-46986

Automated Python exploit for Camaleon CMS arbitrary file upload vulnerability (CVE-2024-46986). Supports reverse shell and command execution payloads…

educationexploitationpayload-development+3
31 year ago
CVE-2025-50286 preview

CVE-2025-50286

GitHubbinneko/cve-2025-50286

Authenticated RCE exploit for Grav CMS via plugin upload, demonstrating arbitrary PHP code execution and reverse shell.

educationexploitationpayload-development+3
21 year ago
CVE-2020-29607-Pluck-CMS-4.7.13-Authenticated-File-Upload-RCE-PoC preview

CVE-2020-29607-Pluck-CMS-4.7.13-Authenticated-File-Upload-RCE-PoC

GitHubestebanzarate/cve-2020-29607-pluck-cms-4.7.13-authenticated-file-upload-rce-poc

Authenticated RCE exploit for Pluck CMS <= 4.7.13 via unvalidated file upload. Uploads a PHP webshell and provides an interactive command shell.

exploitationpayload-developmentpenetration-testing+2
16 months ago
CVE-2026-25099 preview

CVE-2026-25099

GitHubyahiahamza/cve-2026-25099

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

exploitationpayload-developmentpenetration-testing+3
5 months ago
CVE-2026-29053 preview

CVE-2026-29053

GitHubrootxran/cve-2026-29053

Proof-of-concept exploit for Ghost CMS remote code execution via prototype pollution in jsonpath and static-eval, with a vulnerable environment setup…

exploitationpayload-developmentpenetration-testing+2
5 months ago
CVE-2022-41840-PoC preview

CVE-2022-41840-PoC

GitHubprinceaikinsbaidoo/cve-2022-41840-poc

This is the PoC exploit for CVE-2022-41840, running Zenario

educationexploitationpayload-development+3
6 months ago
cve-2018-16763-rust preview

cve-2018-16763-rust

GitHubbrunopincho/cve-2018-16763-rust

Rust implementation of an exploit for CVE-2018-16763, targeting a remote code execution vulnerability in Fuel CMS for penetration testing and…

binary-exploitationexploitationpayload-development+2
4 years ago
halo-cve-2026-67919 preview

halo-cve-2026-67919

GitHubk0nnect/halo-cve-2026-67919

halo cms plugin 1-request rce from a url, PoC + exploit chain

exploitationpayload-developmentpenetration-testing+3
19 days ago
CVE-2018-11736 preview

CVE-2018-11736

GitHubpurgemebaby/cve-2018-11736

PoC exploit for CVE-2018-11736 affecting Pluck CMS versions prior to 4.7.7-dev2 with a File Upload Vulnerability

exploitationpayload-developmentpenetration-testing+3
15 months ago
MAGNOLIA-8281 preview

MAGNOLIA-8281

GitHubmbadanoiu/magnolia-8281

MAGNOLIA-8281: FreeMarker Restriction Bypass 2 in Magnolia CMS

code-analysisexploitationpayload-development+2
2 years ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubthemursalin/cve-2025-32432

Exploit for Craft CMS pre-authentication RCE (CVE-2025-32432) chaining session poisoning with insecure deserialization to execute arbitrary commands…

educationexploitationpayload-development+3
4 months ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubcd-ratel/cve-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

ctfeducationexploitation+4
23 months ago
CVE-2026-48909 preview

CVE-2026-48909

GitHubis4yev/cve-2026-48909

Proof-of-concept exploit for CVE-2026-48909: unauthenticated remote code execution via PHP object injection in JoomShaper SP LMS. Includes detection,…

code-analysiseducationexploitation+4
231 month ago
CVE-2020-25042-PoC preview

CVE-2020-25042-PoC

GitHubgroppoxx/cve-2020-25042-poc

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

exploitationpayload-developmentpenetration-testing+3
53 months ago
SPIP-BigUp-Unauthenticated-RCE-Exploit-CVE-2024-8517 preview

SPIP-BigUp-Unauthenticated-RCE-Exploit-CVE-2024-8517

GitHubsaadhassan77/spip-bigup-unauthenticated-rce-exploit-cve-2024-8517

This Python exploit targets a critical unauthenticated Remote Code Execution (RCE) vulnerability in the BigUp plugin of SPIP CMS (≤ 4.3.1, 4.2.15,…

exploitationpayload-developmentpenetration-testing+3
11 year ago
Previous12Next