Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
137 results
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
3 days ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubiicaicai/cve-2026-5524-poc

Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and…

exploitationinformation-gatheringpayload-development+8
2 months ago
CVE-2025-31324 preview

CVE-2025-31324

GitHubhkenzokimura/cve-2025-31324

Proof-of-concept exploit for CVE-2025-31324, an unauthenticated file upload in SAP NetWeaver Visual Composer, with detection guidance, MITRE mapping,…

educationexploitationincident-response+4
18 days ago
CVE-2026-75865 preview

CVE-2026-75865

GitHubghostpels/cve-2026-75865

Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC

educationexploitationpenetration-testing+3
19 days ago
CVE-2026-78839 preview

CVE-2026-78839

GitHubnabeelmkhan/cve-2026-78839

Proof-of-concept for CVE-2026-78839, an arbitrary file upload vulnerability in AppNitro MachForm v30 allowing remote code execution via crafted .phar…

exploitationpenetration-testingred-teaming+2
22 days ago
CVE-2026-1357 preview

CVE-2026-1357

GitHubsahmsec/cve-2026-1357

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

educationexploitationpenetration-testing+3
26 days ago
WSOB preview

WSOB

GitHubdsssssssm/wsob

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

exploitationpenetration-testingred-teaming+2
263 years ago
CVE-2026-32475 preview

CVE-2026-32475

GitHubsahmsec/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

educationexploitationpenetration-testing+3
128 days ago
By-Poloss..-..CVE-2026-18080 preview

By-Poloss..-..CVE-2026-18080

GitHubpolosss/by-poloss..-..cve-2026-18080

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

exploitationpayload-developmentpenetration-testing+3
29 days ago
CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla preview

CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla

GitHubyallasec/cve-2026-21627---tassos-novarain-framework-plg_system_nrframework-exploit---joomla

Python exploit for CVE-2026-21627, an unauthenticated arbitrary PHP file inclusion in Joomla's Novarain Framework, enabling file upload, delete, and…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2026-25099 preview

CVE-2026-25099

GitHubyahiahamza/cve-2026-25099

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

exploitationpayload-developmentpenetration-testing+3
6 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubim-hanzou/cve-2026-3844

Breeze Cache WordPress <=2.4.4 allows unauthenticated file upload via fetch_gravatar_from_remote when local gravatar hosting is enabled.

exploitationpenetration-testingred-teaming+2
5 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubhalilkirazkaya/cve-2026-3844

Exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to RCE in Breeze Cache WordPress plugin. Includes lab setup, usage, and…

educationexploitationpenetration-testing+3
44 months ago
CVE-2026-42879 preview

CVE-2026-42879

GitHubguzrex/cve-2026-42879

FacturaScripts RCE Exploit - Proof of Concept

exploitationpayload-developmentpenetration-testing+3
4 months ago
CVE-2026-22241 preview

CVE-2026-22241

GitHubashifcoder/cve-2026-22241

Automated exploit for CVE-2026-22241, an unrestricted file upload vulnerability in Open eClass, enabling remote code execution via a webshell with…

exploitationpayload-developmentpenetration-testing+3
18 months ago
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

exploitationpenetration-testingred-teaming+3
1 month ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
21 month ago
CVE-2026-14483_exploit preview

CVE-2026-14483_exploit

GitHub0xdak/cve-2026-14483_exploit

Unauthenticated arbitrary file upload exploit for Realtyna WPL/Organic IDX WordPress plugin, chains PHP webshell upload to RCE, with command…

exploitationpenetration-testingred-teaming+3
1 month ago
Previous12…8Next