Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
246 results
Joomla-webshell-plugin preview

Joomla-webshell-plugin

GitHubp0dalirius/joomla-webshell-plugin

A webshell plugin and interactive shell for pentesting a Joomla website.

command-and-controlexploitationpayload-development+6
62
4 years ago
blackbox-pentesting-infsecos preview

blackbox-pentesting-infsecos

GitHubsaqibnet/blackbox-pentesting-infsecos

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

ctfeducationexploitation+9
5 months ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubsi13nttt/cve-2025-24813

Python PoC exploiting Apache Tomcat CVE-2025-24813 partial PUT deserialization RCE, with auto variant detection, ysoserial gadget chains, and reverse…

educationexploitationpayload-development+6
24 days ago
CVE-2026-102489 preview

CVE-2026-102489

GitHubhorizon3ai/cve-2026-102489

Proof-of-concept exploit for CVE-2026-102489 in Zammad: chains a WebSocket session leak into authenticated session hijacking and unauthenticated…

exploitationpayload-developmentpost-exploitation+4
12 days ago
veneficus preview

veneficus

GitHubabraxas/veneficus

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

command-and-controldata-exfiltrationids-ips-evasion+8
21 month ago
CVE-2022-0543 preview

CVE-2022-0543

GitHubfulxey/cve-2022-0543

Redis RCE through Lua Sandbox Escape vulnerability

exploitationpayload-developmentpenetration-testing+5
14 years ago
FreePBX-SQLi-RCE preview

FreePBX-SQLi-RCE

GitHubthescriptkiddoz/freepbx-sqli-rce

Proof-of-concept exploit for CVE-2025-57819, an unauthenticated SQL injection in FreePBX that chains admin account creation, webshell deployment, and…

exploitationpapers-researchpayload-development+7
3 months ago
CVE-2026-102425 preview

CVE-2026-102425

GitHubtonydelouvre/cve-2026-102425

GUI scanner and exploit for CVE-2026-102425, an unauthenticated RCE in Balbooa Forms (com_baforms) via PHP shortcode injection, with mass scanning…

exploitationpayload-developmentpenetration-testing+7
8 days ago
CVE-2026-15989 preview

CVE-2026-15989

GitHubfl0ydsec/cve-2026-15989

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts…

exploitationpayload-generationpenetration-testing+6
7 days ago
CVE-2026-87930 preview

CVE-2026-87930

GitHubwinrarzipsexploit/cve-2026-87930

Joomla multi-CVE RCE suite with seven exploit modules for Balbooa Forms, Page Builder CK, SP Page Builder, JCE, iCagenda, Helix3, and SP LMS, plus…

exploitationpayload-generationpenetration-testing+7
122 days ago
CVE-2026-28695-craft-rce-bypass preview

CVE-2026-28695-craft-rce-bypass

GitHubgbuyssens/cve-2026-28695-craft-rce-bypass

Authenticated, **blind** remote code execution in Craft CMS. Fix for CVE-2026-28695

exploitationpayload-developmentpenetration-testing+5
112 days ago
CVE-2026-28695 preview

CVE-2026-28695

GitHubpredyy/cve-2026-28695

Python PoC exploit for CVE-2026-28695, an authenticated blind RCE in Craft CMS that bypasses the create() BaseObject patch and spawns a reverse shell.

exploitationpenetration-testingpost-exploitation+5
1312 days ago
CVE-2026-24516-DigitalOcean-RCE. preview

CVE-2026-24516-DigitalOcean-RCE.

GitHubpoxsky/cve-2026-24516-digitalocean-rce.

Technical analysis and PoC for CVE-2026-24516: Unauthenticated Root Remote Code Execution in DigitalOcean Droplet Agent (CVSS 10.0).

cloud-securityexploitationinformation-gathering+7
6 months ago
CVE-2026-31857 preview

CVE-2026-31857

GitHub0xtatsuki/cve-2026-31857

Craft CMS RCE via relational conditionals in the control panel

exploitationpayload-developmentpenetration-testing+6
10 days ago
cups-2.4.16-lpe preview

cups-2.4.16-lpe

GitHubmrdebora/cups-2.4.16-lpe

CUPS 2.4.16 Local Privilege Escalation via Local Admin Token Leak and file:// Arbitrary File Write (CVE-2026-34990)

exploitationpayload-generationpenetration-testing+4
10 days ago
CVE-2026-44011-craftcms-auth-rce preview

CVE-2026-44011-craftcms-auth-rce

GitHub4xura/cve-2026-44011-craftcms-auth-rce

The PoC of CVE-2026-44011: Craft CMS RCE with an authenticated user.

command-and-controlexploitationpenetration-testing+5
512 days ago
CVE-2026-44011-poc preview

CVE-2026-44011-poc

GitHubdennisdgr/cve-2026-44011-poc

Authenticated Craft CMS RCE PoC for CVE-2026-44011

command-and-controlexploitationpenetration-testing+5
12 days ago
CVE-2026-65660-Poc preview

CVE-2026-65660-Poc

GitHubshadowforge-cyber/cve-2026-65660-poc

Malicious Register Directive Code Injection Exploit

command-and-controldata-exfiltrationexploitation+8
114 days ago
Previous12…14Next