Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2248 results
CVE-2026-95675 preview

CVE-2026-95675

GitHubd6fault/cve-2026-95675

Python PoC exploiting CVE-2026-95675, an unauthenticated root command injection in D-Link DAP-1360 RevB firmware via a hardcoded auth-bypass and the…

embedded-systems-securityexploitationfirmware-analysis+6
1
1 day ago
watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127 preview

watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127

GitHubwatchtowrlabs/watchtowr-vs-f5-bigip-preauth-rce-cve-2026-94127

Python detection artifact generator and PoC for CVE-2026-94127, a pre-auth RCE in F5 BIG-IP reachable via OAuth-configured virtual servers, with…

exploitationpapers-researchpenetration-testing+4
222h 50m ago
cve-2026-87902 preview

cve-2026-87902

GitHubzyphorixofficialmain-lab/cve-2026-87902

Python exploit for CVE-2026-87902, a WordPress Core LFI-to-RCE chain. Fingerprints versions, writes a PHP shell via pearcmd, and provides command…

exploitationinformation-gatheringpayload-development+6
1 day ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubbhideki/cve-2026-87902

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

exploitationpayload-developmentpenetration-testing+6
1 day ago
GateKeeper preview

GateKeeper

GitHubgmh5225/gatekeeper

Self-hosted SSH access gateway in Go with OIDC/LDAP auth, RBAC, MFA, session recording, audit export, encryption at rest, IP rules, and policy…

authentication-authorizationconfiguration-auditingdefensive-tools+6
7 months ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
1 day ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubfl0ydsec/cve-2026-63030

Python mass exploit and detector for the WordPress Core pre-auth RCE chain CVE-2026-63030 and CVE-2026-60137, chaining SQL injection into remote code…

exploitationpassword-attackspayload-development+7
1 day ago
Weblogic_CVE-2020-14645 preview

Weblogic_CVE-2020-14645

GitHubjlvsjp/weblogic_cve-2020-14645

Java PoC for WebLogic CVE-2020-14645 Coherence deserialization RCE. Hosts a malicious class via LDAP and triggers remote code execution on vulnerable…

exploitationpayload-developmentpenetration-testing+4
6 years ago
CVE-2026-86218 preview

CVE-2026-86218

GitHubsuper-meuw/cve-2026-86218

Python 3 proof-of-concept exploit for CVE-2026-86218, a pre-auth RCE in N-able N-central via a Struts multipart race condition, with command…

exploitationpayload-developmentpenetration-testing+5
2 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubvulpecuna/cve-2026-87902

Python PoC for CVE-2026-87902, an unauthenticated WordPress path traversal RCE via get_page_template(), with version fingerprinting, theme checks,…

exploitationlabs-practicepenetration-testing+5
32 days ago
gopacket preview

gopacket

GitHubmandiant/gopacket

A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free…

command-and-controlexploit-frameworkslateral-movement+7
7071 month ago
CVE-Exploit-Research-Development preview

CVE-Exploit-Research-Development

GitHubfaizanali8232/cve-exploit-research-development

A professional Python tool designed for educational penetration testing, demonstrating SSH vulnerabilities (CVE-2008-0166 / CVE-2008-1657) with…

command-and-controleducationexploitation+6
6 months ago
IBM-Langflow-CVE-2026-48519-poc preview

IBM-Langflow-CVE-2026-48519-poc

GitHublukehebe/ibm-langflow-cve-2026-48519-poc

Proof-of-concept exploit for CVE-2026-48519, a pre-auth RCE in IBM Langflow <= 1.9.1 via the Shareable Playground /api/v1/build_public_tmp endpoint.

exploitationpenetration-testingremote-access-tool+3
3 days ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubyasouxken/cve-2026-41940-poc

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

authenticationcommand-and-controlexploitation+7
3 days ago
CVE-2026-14894 preview

CVE-2026-14894

GitHubnxploited/cve-2026-14894

Multi-threaded mass exploiter chaining unauthenticated WordPress file-upload flaws in Super Forms and Elementor Pro to deploy and verify a PHP web…

exploitationpayload-developmentpenetration-testing+7
4 days ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
11 month ago
CVE-2026-33439-Poc preview

CVE-2026-33439-Poc

GitHubrh33t/cve-2026-33439-poc

PoC for CVE-2026-33439, a pre-auth RCE in OpenAM via unsafe Java deserialization.

exploitationpenetration-testingremote-access-tool+2
4 days ago
CVE-2026-90817 preview

CVE-2026-90817

GitHubexdev994/cve-2026-90817

Python PoC for CVE-2026-90817, an unauthenticated REDCap RCE via survey passthrough routing and file-path injection, with a Docker lab and…

exploitationlabs-practicepayload-development+5
4 days ago
Previous12…100Next