Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
362 results
CVE-2026-48206 preview

CVE-2026-48206

GitHuboscerd/cve-2026-48206

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

api-security-testingeducationexploitation+3
2 months ago
CVE-2026-70481 preview

CVE-2026-70481

GitHubfoxer131/cve-2026-70481

Proof-of-concept exploit for an authorization flaw in Open WebUI that lets low-privileged users edit and delete other members' channel messages via…

api-security-testingauthentication-authorizationexploitation+4
1 month ago
CVE-2026-46453 preview

CVE-2026-46453

GitHuboscerd/cve-2026-46453

Reproducer for CVE-2026-46453 — Apache Camel camel-elasticsearch-rest-client unprefixed-header injection (operation/query override via inbound HTTP…

api-security-testingeducationexploitation+3
2 months ago
CVE-2026-46587 preview

CVE-2026-46587

GitHuboscerd/cve-2026-46587

Reproducer for CVE-2026-46587: Apache Camel camel-couchbase CCB_* header injection enabling document disclosure, tampering, and TTL-forced data…

api-security-testingeducationexploitation+3
2 months ago
CVE-2026-54356 preview

CVE-2026-54356

GitHubkovachvl/cve-2026-54356

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

api-security-testingcloud-securityexploitation+3
1 month ago
CVE-2026-49099 preview

CVE-2026-49099

GitHuboscerd/cve-2026-49099

PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and…

api-security-testingeducationexploitation+3
2 months ago
CVE-2026-55255-Lab preview

CVE-2026-55255-Lab

GitHubrootdirective-sec/cve-2026-55255-lab

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

api-security-testingeducationlabs-practice+3
2 months ago
CVE-2026-46588 preview

CVE-2026-46588

GitHuboscerd/cve-2026-46588

Reproducer for CVE-2026-46588: Apache Camel camel-couchdb CouchDb* header injection (operation confusion) subverting a write-only endpoint into read…

api-security-testingeducationexploitation+3
2 months ago
CVE-2026-48204 preview

CVE-2026-48204

GitHuboscerd/cve-2026-48204

Reproducer for CVE-2026-48204: Apache Camel camel-mongodb-gridfs gridfs.* header injection overriding the GridFS operation (enumerate/read/delete…

api-security-testingexploitationpenetration-testing+2
2 months ago
milvus-auth-audit preview

milvus-auth-audit

GitHubqianlijaingshan/milvus-auth-audit

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

api-security-testingauthentication-authorizationdatabase-security+4
1 month ago
CVE-2026-9198 preview

CVE-2026-9198

GitHubk3ystr0k3r/cve-2026-9198

PoC and detection guide for the critical unauthenticated RCE in IBM Langflow OSS, covering the auto_login token bypass and unsafe /validate/code…

api-security-testingexploitationpenetration-testing+2
11 month ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubsaboor-hakimi/cve-2023-23752

CVE-2023-23752 nuclei template

api-security-testingexploitationinformation-gathering+3
43 years ago
HTB-TwoMillion-machine preview

HTB-TwoMillion-machine

GitHubabedallarawashdeh/htb-twomillion-machine

Hack The Box TwoMillion machine writeup — JWT/invite-code bypass, IDOR, command injection, and CVE-2023-0386 privilege escalation.

api-security-testingctfeducation+4
1 month ago
langflow-cors-scanner preview

langflow-cors-scanner

GitHubridhinva/langflow-cors-scanner

Scanner: CVE-2025-34291 Langflow Origin Validation Error / CORS Misconfiguration — Python checker (CISA KEV)

api-security-testingmisconfigurationpenetration-testing+2
1 month ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
1 month ago
CVE-2024-11423 preview

CVE-2024-11423

GitHubrandomrobbiebf/cve-2024-11423

Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

api-security-testingauthentication-authorizationpenetration-testing+2
31 year ago
CVE-2026-35616-check preview

CVE-2026-35616-check

GitHubbishopfox/cve-2026-35616-check

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

api-security-testingauthenticationexploitation+3
25 months ago
CVE-2016-4014 preview

CVE-2016-4014

GitHubmurataydemir/cve-2016-4014

[CVE-2016-4014] SAP Netweaver AS JAVA UDDI Component XML External Entity (XXE)

api-security-testingexploitationpenetration-testing+3
26 years ago
Previous1…151617…21Next