Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
306 results
WPTimeCapsulePOC preview

WPTimeCapsulePOC

GitHubsecforce/wptimecapsulepoc

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

authenticationexploitationpayload-development+3
5
6 years ago
cve-2026-6471-postgres-logical-decoding-dlopen preview

cve-2026-6471-postgres-logical-decoding-dlopen

GitHubgoldendivider/cve-2026-6471-postgres-logical-decoding-dlopen

Proof-of-concept exploit for CVE-2026-6471, demonstrating privilege escalation in PostgreSQL via logical decoding dlopen to achieve arbitrary code…

database-securityexploitationpayload-development+4
24 days ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubyasouxken/cve-2026-41940-poc

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

authenticationcommand-and-controlexploitation+7
8 days ago
bypass_disablefunc_via_LD_PRELOAD preview

bypass_disablefunc_via_LD_PRELOAD

GitHubianxtianxt/bypass_disablefunc_via_ld_preload

解决php提权的时候因系统禁用函数导致无法执行命令的情况

exploitationpayload-developmentpenetration-testing+4
67 years ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubgbuyssens/cve-2026-39987

Marimo exploit prior to 0.23.0. Pre-Auth RCE vulnerability via websocket endpoint : /terminal/ws.

exploitationpayload-generationpenetration-testing+3
1 month ago
CVE-2025-8088 preview

CVE-2025-8088

GitHublennertdefauw/cve-2025-8088

WinRAR < 7.13 path traversal for persistency

exploitationpayload-generationpenetration-testing+3
56 months ago
CVE-2026-24291 preview

CVE-2026-24291

GitHublennertdefauw/cve-2026-24291

Obfuscated Windows privilege escalation exploit for CVE-2026-24291 that automatically creates a local administrator with generated credentials.

exploitationpayload-developmentpost-exploitation+1
46 months ago
MSC-EvilTwin-Local-Privilege-Escalation preview

MSC-EvilTwin-Local-Privilege-Escalation

GitHubmbanyamer/msc-eviltwin-local-privilege-escalation

CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on…

binary-exploitationexploitationpayload-generation+4
410 months ago
CVE-2025-55182-golang-PoC preview

CVE-2025-55182-golang-PoC

GitHubkeklick1337/cve-2025-55182-golang-poc

Go-based proof-of-concept for CVE-2025-55182, a critical RCE in React Server Components. Features vulnerability checking, command execution, memory…

command-and-controlexploitationpayload-development+6
69 months ago
CVE-2025-54123-Poc preview

CVE-2025-54123-Poc

GitHubkasem545/cve-2025-54123-poc

CVE-2025-54123 Hoverfly Authenticated Middleware Command Injection RCE

command-and-controlexploitationpayload-development+5
76 months ago
Pwnkit-go preview

Pwnkit-go

GitHubfdlucifer/pwnkit-go

A golang based exp for CVE-2021-4034 dubbed pwnkit (more features added......)

binary-exploitationexploitationpayload-development+3
34 years ago
revshell preview

revshell

GitHubprodigiousmind/revshell

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

exploitationpayload-generationpenetration-testing+3
43 years ago
Project-CVE-2026-33017 preview

Project-CVE-2026-33017

GitHube4zyy/project-cve-2026-33017

CVE-2026-33017 - Langflow Unauthenticated RCE Exploit

command-and-controlexploitationpayload-development+6
11 month ago
CVE-2024-2044 preview

CVE-2024-2044

GitHubhanzzly/cve-2024-2044

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…

exploitationpayload-developmentpenetration-testing+5
117 days ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubnoname-elv/cve-2026-48907

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

exploitationpayload-developmentpenetration-testing+6
114 days ago
SenselessViolence preview

SenselessViolence

GitHubevergreencartoons/senselessviolence

CVE-2022-31814 Exploitation Toolkit.

command-and-controlexploitationlog-analysis+7
44 years ago
CVE-2019-9702_Symantec_Encryption_Desktop_LPE_PoC preview

CVE-2019-9702_Symantec_Encryption_Desktop_LPE_PoC

GitHubdavidcarliez/cve-2019-9702_symantec_encryption_desktop_lpe_poc

Local Privilege Escalation PoC to pop a SYSTEM shell for CVE-2019-9702 in Symantec Encryption Desktop.

binary-exploitationexploitationpayload-development+4
22 months ago
CVE-2026-17566 preview

CVE-2026-17566

GitHubhackspeak/cve-2026-17566

pgAdmin 4 Import/Export RCE (CVE-2026-17566) PoC - TO PROGRAM injection via backslash-escape mismatch

exploitationpayload-generationpenetration-testing+3
21 month ago
Previous1…121314…17Next