Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
CVE-2026-84434 preview

CVE-2026-84434

GitHubmurrez/cve-2026-84434

Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields.…

exploitationpenetration-testingreconnaissance+5
5 days ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubiicaicai/cve-2026-5524-poc

Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and…

exploitationinformation-gatheringpayload-development+8
2 months ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
CVE-2026-57827 preview

CVE-2026-57827

GitHubcandisexterior171/cve-2026-57827

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

exploitationpenetration-testingreconnaissance+2
3 days ago
CVE-2026-58480 preview

CVE-2026-58480

GitHubshinthink/cve-2026-58480

CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

exploitationpayload-generationpenetration-testing+3
32 months ago
smartermail-cve-scanner preview

smartermail-cve-scanner

GitHubnxgn-kd01/smartermail-cve-scanner

CVE-2025-52691 Scanner - Detects vulnerable SmarterMail installations (CVSS 10.0 RCE)

exploitationinformation-gatheringpenetration-testing+3
18 months ago
PutScanner preview

PutScanner

GitHubx00byte/putscanner

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

exploitationinformation-gatheringpenetration-testing+3
91 year ago
CVE-2019-7216 preview

CVE-2019-7216

GitHubekultek/cve-2019-7216

Filechucker filter bypass Proof Of Concept

exploitationpenetration-testingreconnaissance+2
107 years ago
Penetration-Test preview

Penetration-Test

GitHubjeevananand1202/penetration-test

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

educationexploitationpassword-cracking+6
5 months ago
pbck-exploit preview

pbck-exploit

GitHubshinthink/pbck-exploit

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

exploit-frameworkspayload-developmentpenetration-testing+4
32 months ago
CVE-2026-4883 preview

CVE-2026-4883

GitHubxshadow-here/cve-2026-4883

Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE

exploitationpayload-generationpenetration-testing+3
3 months ago
CVE-2026-14894 preview

CVE-2026-14894

GitHubshinthink/cve-2026-14894

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

educationexploitationinformation-gathering+6
12 months ago
WG-CVE-2026-1555-Linux preview

WG-CVE-2026-1555-Linux

GitHubwillygailo/wg-cve-2026-1555-linux

Automated exploit toolkit for CVE-2026-1555, a critical unauthenticated file upload RCE in the WebStack WordPress theme. Features PyQt5 GUI,…

command-and-controleducationexploitation+6
3 months ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

command-and-controlexploitationinformation-gathering+8
12 months ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubayiezola/cve-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

exploitationinformation-gatheringpayload-development+4
3 months ago
CVE-2026-56291 preview

CVE-2026-56291

GitHub0xdenis77/cve-2026-56291

Mendeteksi versi (passive detection) & Exploitation CVE POC

exploitationinformation-gatheringpenetration-testing+3
12 months ago
CVE-2024-0352 preview

CVE-2024-0352

GitHubcappricio-securities/cve-2024-0352

Likeshop < 2.5.7.20210311 - Arbitrary File Upload

exploitationinformation-gatheringpenetration-testing+3
2 years ago
Popcorn-TJNULL-OSCP- preview

Popcorn-TJNULL-OSCP-

GitHubr3fr4kt/popcorn-tjnull-oscp-

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

ctfeducationexploitation+7
3 months ago