Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1868 results
CVE-2026-1357 preview

CVE-2026-1357

GitHubsahmsec/cve-2026-1357

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

educationexploitationpenetration-testing+3
16h 53m ago
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write preview

CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

GitHubbiitts/cve-2026-82286-gpt-crawler-arbitrary-file-write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

educationexploitationlabs-practice+3
1 day ago
CVE-2025-10952-ml-logger-AFR preview

CVE-2025-10952-ml-logger-AFR

GitHubkhashayarnzk/cve-2025-10952-ml-logger-afr

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

exploitationinformation-gatheringpenetration-testing+2
2 days ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubmachiavelliii/cve-2024-23897

Unauthenticated arbitrary file read exploit for Jenkins CVE-2024-23897, with HTTPS and CSRF-crumb support to bypass hardened instances.

exploitationinformation-gatheringpenetration-testing+2
2 days ago
CVE-2026-23751-poc preview

CVE-2026-23751-poc

GitHubsiebrum/cve-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP…

exploitationpenetration-testingred-teaming+2
2 days ago
htb-labs-connected preview

htb-labs-connected

GitHubdiegorivas1/htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

ctfeducationexploitation+7
2 days ago
WSOB preview

WSOB

GitHubdsssssssm/wsob

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

exploitationpenetration-testingred-teaming+2
263 years ago
CVE-2026-32475 preview

CVE-2026-32475

GitHubsahmsec/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

educationexploitationpenetration-testing+3
2 days ago
DNSRPC-BOF preview

DNSRPC-BOF

GitHubparadoxis/dnsrpc-bof

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

exploitationpayload-developmentpenetration-testing+2
501 month ago
llm-agent-testbed preview

llm-agent-testbed

GitHubpie-script/llm-agent-testbed

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

ai-securityapi-securityeducation+4
93 days ago
By-Poloss..-..CVE-2026-18080 preview

By-Poloss..-..CVE-2026-18080

GitHubpolosss/by-poloss..-..cve-2026-18080

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

exploitationpayload-developmentpenetration-testing+3
3 days ago
CVE-2023-4861-PoC preview

CVE-2023-4861-PoC

GitHubnoambouillet/cve-2023-4861-poc

Automated proof-of-concept for authenticated remote code execution in WordPress File Manager Pro (Filester) via arbitrary file upload, including…

exploitationpayload-developmentpenetration-testing+2
21 month ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
3 months ago
cPanelSniper preview

cPanelSniper

GitHubynsmroztas/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4944 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubsahmsec/cve-2026-3844

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

exploitationpayload-developmentpenetration-testing+3
3 months ago
POC_CVE-2026-41940 preview

POC_CVE-2026-41940

GitHubimbas007/poc_cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

command-and-controlexploitationpenetration-testing+3
3 months ago
CVE-2026-42167-Exploit preview

CVE-2026-42167-Exploit

GitHubefeanilarslan/cve-2026-42167-exploit

Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.

data-exfiltrationexploitationpenetration-testing+2
4 months ago
CVE-2026-10170-RCE preview

CVE-2026-10170-RCE

GitHubxmyronn/cve-2026-10170-rce

Proof-of-concept demonstrating SQL injection and unrestricted file upload chained to achieve remote code execution in Visitor Management System 1.0,…

exploitationpayload-developmentpenetration-testing+2
3 months ago
Previous12…100Next