Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
464 results
CVE-2026-1357 preview

CVE-2026-1357

GitHubsahmsec/cve-2026-1357

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

educationexploitationpenetration-testing+3
16h 55m ago
CVE-2026-23751-poc preview

CVE-2026-23751-poc

GitHubsiebrum/cve-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP…

exploitationpenetration-testingred-teaming+2
2 days ago
WSOB preview

WSOB

GitHubdsssssssm/wsob

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

exploitationpenetration-testingred-teaming+2
263 years ago
CVE-2026-32475 preview

CVE-2026-32475

GitHubsahmsec/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

educationexploitationpenetration-testing+3
2 days ago
DNSRPC-BOF preview

DNSRPC-BOF

GitHubparadoxis/dnsrpc-bof

Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the…

exploitationpayload-developmentpenetration-testing+2
501 month ago
llm-agent-testbed preview

llm-agent-testbed

GitHubpie-script/llm-agent-testbed

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

ai-securityapi-securityeducation+4
93 days ago
By-Poloss..-..CVE-2026-18080 preview

By-Poloss..-..CVE-2026-18080

GitHubpolosss/by-poloss..-..cve-2026-18080

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

exploitationpayload-developmentpenetration-testing+3
3 days ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
3 months ago
cPanelSniper preview

cPanelSniper

GitHubynsmroztas/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4944 months ago
CVE-2026-56705 preview

CVE-2026-56705

GitHubboreas37/cve-2026-56705

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

educationexploitationlabs-practice+4
24 days ago
CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla preview

CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla

GitHubyallasec/cve-2026-21627---tassos-novarain-framework-plg_system_nrframework-exploit---joomla

Python exploit for CVE-2026-21627, an unauthenticated arbitrary PHP file inclusion in Joomla's Novarain Framework, enabling file upload, delete, and…

exploitationpayload-developmentpenetration-testing+3
6 months ago
CVE-2026-25099 preview

CVE-2026-25099

GitHubyahiahamza/cve-2026-25099

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

exploitationpayload-developmentpenetration-testing+3
5 months ago
cve-2026-64638-banner-poc preview

cve-2026-64638-banner-poc

GitHubxal6/cve-2026-64638-banner-poc

Generates a self-submitting HTML trigger page that exploits a reflected HTML injection in WordPress login (CVE-2026-64638) to display a custom…

exploitationpenetration-testingred-teaming+3
5 days ago
cve-2021-3864 preview

cve-2021-3864

GitHubwalac/cve-2021-3864

Proof-of-concept exploit for CVE-2021-3864, a privilege escalation vulnerability in logrotate, demonstrating core file generation to achieve root…

exploitationpenetration-testingprivilege-escalation+2
4 years ago
SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit preview

SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit

GitHubsastraadiwiguna-purpleeliteteaming/sastra-adi-wiguna-cve-2026-21858-holistic-audit

Technical audit and reproduction of CVE-2026-21858, an n8n RCE chain exploiting Content-Type confusion for arbitrary file read, session forgery, and…

curated-resourceseducationexploitation+4
7 months ago
copy-fail-CVE-2026-31431 preview

copy-fail-CVE-2026-31431

GitHubrio128128/copy-fail-cve-2026-31431

Copy Fail: 732 Bytes to Root on Every Major Linux Distribution.

binary-exploitationcloud-securitycontainer-security+6
4 months ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubmin8282/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

educationexploitationpenetration-testing+3
4 months ago
CVE-2026-25548 preview

CVE-2026-25548

GitHublagathos/cve-2026-25548

Detailed technical write-up and proof-of-concept for CVE-2026-25548, a critical RCE in InvoicePlane 1.7.0 via LFI and log poisoning, including attack…

educationexploitationpenetration-testing+3
15 months ago
Previous12…26Next