Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2447 results
CVE-2026-6433 preview

CVE-2026-6433

GitHubmurrez/cve-2026-6433

PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk…

educationexploitationpayload-development+4
2
2 months ago
CVE-2025-6440-Poc-Exploit preview

CVE-2025-6440-Poc-Exploit

GitHubm2hcz/cve-2025-6440-poc-exploit

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

exploitationpayload-generationpenetration-testing+3
11 month ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
22 months ago
Blind-Trust-CVE-2024-21413-Research preview

Blind-Trust-CVE-2024-21413-Research

GitHubh1ssbl1tz/blind-trust-cve-2024-21413-research

A security research tool for simulating targeted phishing campaigns using CVE-2024-21413 (Moniker Link).

educationemail-securityexploitation+7
2 months ago
incriminator preview

incriminator

GitHubkernelfl00d/incriminator

Incriminator is an OpenSource Project with educational purposes that allows you to incriminate other devices during a cybercrime.

educationimpersonation-toolslateral-movement+2
38 years ago
pocKeycloakCVE-2023-0264 preview

pocKeycloakCVE-2023-0264

GitHubeliangonzi00/pockeycloakcve-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

authenticationdefensive-toolsexploitation+7
1 month ago
cve-2024-3400-panos_rce_reproduction preview

cve-2024-3400-panos_rce_reproduction

GitHubrazureink/cve-2024-3400-panos_rce_reproduction

Reproduction of cve-2024-3400-panos_rce_reproduction

command-and-controleducationexploitation+5
1 month ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
1 month ago
cve-2024-1708-connectwise_rce_reproduction preview

cve-2024-1708-connectwise_rce_reproduction

GitHubrazureink/cve-2024-1708-connectwise_rce_reproduction

Reproduction of cve-2024-1708-connectwise_rce_reproduction

authenticationeducationexploitation+5
1 month ago
cve-2024-49113-ldap_nightmare_reproduction preview

cve-2024-49113-ldap_nightmare_reproduction

GitHubrazureink/cve-2024-49113-ldap_nightmare_reproduction

Reproduction of cve-2024-49113-ldap_nightmare_reproduction

binary-exploitationeducationexploitation+4
1 month ago
CVE-2026-15282 preview

CVE-2026-15282

GitHubshinthink/cve-2026-15282

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

educationexploitationpayload-generation+5
2 months ago
CVE-2024-41570-Havoc-C2-RCE preview

CVE-2024-41570-Havoc-C2-RCE

GitHubleo-mitch/cve-2024-41570-havoc-c2-rce

This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs

command-and-controlexploitationpenetration-testing+3
31 year ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
1 month ago
CVE-2025-32432-POC preview

CVE-2025-32432-POC

GitHubtheeomega/cve-2025-32432-poc

Single-target proof of concept for CVE-2025-32432, a pre-authentication remote code execution in Craft CMS. Performs vulnerability confirmation via…

educationexploitationpenetration-testing+3
1 month ago
CVE-2026-35585-poc preview

CVE-2026-35585-poc

GitHubsaku0512/cve-2026-35585-poc

Proof-of-concept exploit for CVE-2026-35585, an OS command injection vulnerability in File Browser (versions 2.0.0 to 2.33.1). Includes Python and…

educationexploitationpenetration-testing+3
2 months ago
Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230 preview

Cisco-Unified-Communications-Manager-Server-Side-Forgery-Request-Vulnerability-CVE-2026-20230

GitHubw5m1n9/cisco-unified-communications-manager-server-side-forgery-request-vulnerability-cve-2026-20230

Analyzes CVE-2026-20230 SSRF to arbitrary file write and RCE in Cisco Unified Communications Manager, providing PoC derivation, detection logic, and…

educationexploitationpapers-research+4
12 months ago
CVE-2022-25061 preview

CVE-2022-25061

GitHubexploitwritter/cve-2022-25061

This script exploits a remote command execution vulnerability under the oal_setIp6DefaultRoute component in the TPLink WR840N router.

exploitationpenetration-testingred-teaming+2
24 years ago
tor-ip-changer preview

tor-ip-changer

GitHubianxtianxt/tor-ip-changer

Simple shell script to automatically request new Tor identity at configurable intervals for IP rotation.

educationids-ips-evasionprivacy+1
26 years ago
Previous1…9899100Next