Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
931 results
CVE-2026-104826 preview

CVE-2026-104826

GitHubkiwknr/cve-2026-104826

Proof-of-concept exploit chain for CVE-2026-104826, a path traversal in DropzoneFileExplorer's chunked upload handler that writes a PHP webshell for…

exploitationpenetration-testingremote-access-tool+3
1
1 day ago
seetong-ts81xxd3x-rce preview

seetong-ts81xxd3x-rce

GitHubheapframe/seetong-ts81xxd3x-rce

CVE-2026-100886 | Unauthenticated Remote Code Execution toolkit.

binary-analysisembedded-systems-securityexploitation+6
6 days ago
CVE-2026-100520-laranode-path-traversal preview

CVE-2026-100520-laranode-path-traversal

GitHubwvllxe/cve-2026-100520-laranode-path-traversal

Path Traversal -> RCE in Laranode < 1.2.1 (CWE-22). PoC + advisory writeup.

exploitationpenetration-testingremote-access-tool+3
22 days ago
CVE-2026-13249 preview

CVE-2026-13249

GitHubmurrez/cve-2026-13249

Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit…

embedded-systems-securityexploitationhardware-iot-security+6
8 days ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubyym8538/cve-2026-21858

Docker-based PoC environment and exploit script for CVE-2026-21858, an n8n 1.120.4 arbitrary file read and RCE flaw, providing secret extraction and…

container-securityexploitationpenetration-testing+5
11 month ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubyym8538/cve-2026-33017

Proof-of-concept exploit for CVE-2026-33017, an unauthenticated RCE in Langflow's build_public_tmp endpoint, injecting a malicious custom component…

ai-securityexploitationpayload-development+6
11 month ago
METIS preview

METIS

GitHubk3ystr0k3r/metis

Modular Python exploitation framework with a Metasploit-style console, auto-registering Exploit and Auxiliary modules, tri-state checks, and multiple…

command-and-controlctfeducation+9
33 days ago
Koi preview

Koi

GitHubb3rt1ng/koi

Multi-session reverse shell handler with PTY upgrade, post-exploitation modules, Layer 3 tunneling, payload obfuscation for EDR evasion, session…

command-and-controlids-ips-evasionlateral-movement+9
274 days ago
CVE-2026-49869 preview

CVE-2026-49869

GitHubeqstlab/cve-2026-49869

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…

authenticationexploitationlabs-practice+6
15 days ago
CVE-2026-6951 preview

CVE-2026-6951

GitHubeqstlab/cve-2026-6951

Proof-of-concept exploit for CVE-2026-6951, a simple-git --config filter bypass enabling RCE via the Git ext protocol, with a Docker lab and reverse…

exploitationpayload-developmentpenetration-testing+4
15 days ago
CVE-2026-40897 preview

CVE-2026-40897

GitHubyym8538/cve-2026-40897

Proof-of-concept exploit for CVE-2026-40897, a Math.js expression parser sandbox bypass enabling remote code execution via crafted payloads and a…

exploitationpayload-developmentremote-access-tool+3
11 month ago
CVE-2026-39987-Marimo-Preauth-RCE preview

CVE-2026-39987-Marimo-Preauth-RCE

GitHublaarana12/cve-2026-39987-marimo-preauth-rce

Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab.

container-securityeducationexploitation+5
15 days ago
CVE-2026-44011-poc preview

CVE-2026-44011-poc

GitHubdennisdgr/cve-2026-44011-poc

Authenticated Craft CMS RCE PoC for CVE-2026-44011

command-and-controlexploitationpenetration-testing+5
6 days ago
watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 preview

watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-cve-2026-88772

Detection artifact generator for Citrix NetScaler CVE-2026-88772 that builds a DTLS pre-auth buffer overflow payload to verify remote code execution.

exploitationnetwork-securitypenetration-testing+3
14 days ago
watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 preview

watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-cve-2026-88771

Detection artifact generator for Citrix NetScaler CVE-2026-88771, exploiting a pre-auth command injection to achieve remote code execution against…

exploitationpapers-researchpayload-generation+5
196 days ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubyym8538/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal and arbitrary file write in Langflow's /api/v2/files endpoint, with Docker lab and…

exploitationpenetration-testingremote-access-tool+3
11 month ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubcrowsec-edtech/cve-2026-87902

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

exploitationlabs-practicepayload-development+5
38 days ago
flipper-mcp preview

flipper-mcp

GitHubroostercoopllc/flipper-mcp

AI-powered MCP server for Flipper Zero. Control SubGHz, NFC, RFID, IR, BLE, GPIO, and more over WiFi using Claude or any MCP client.

ai-securitybluetooth-securitycommand-and-control+9
277 months ago
Previous12…52Next