Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1405 results
Joomla-webshell-plugin preview

Joomla-webshell-plugin

GitHubp0dalirius/joomla-webshell-plugin

A webshell plugin and interactive shell for pentesting a Joomla website.

command-and-controlexploitationpayload-development+6
62
4 years ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubsi13nttt/cve-2025-24813

Python PoC exploiting Apache Tomcat CVE-2025-24813 partial PUT deserialization RCE, with auto variant detection, ysoserial gadget chains, and reverse…

educationexploitationpayload-development+6
24 days ago
CVE-2026-102489 preview

CVE-2026-102489

GitHubhorizon3ai/cve-2026-102489

Proof-of-concept exploit for CVE-2026-102489 in Zammad: chains a WebSocket session leak into authenticated session hijacking and unauthenticated…

exploitationpayload-developmentpost-exploitation+4
12 days ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubsi13nttt/cve-2025-32432

Python PoC exploiting CVE-2025-32432, an unauthenticated RCE in Craft CMS via Yii DI gadget injection, with assetId scanning, reverse shell, and…

defensive-toolsexploitationincident-response+6
24 days ago
CVE-2022-0543 preview

CVE-2022-0543

GitHubfulxey/cve-2022-0543

Redis RCE through Lua Sandbox Escape vulnerability

exploitationpayload-developmentpenetration-testing+5
14 years ago
FreePBX-SQLi-RCE preview

FreePBX-SQLi-RCE

GitHubthescriptkiddoz/freepbx-sqli-rce

Proof-of-concept exploit for CVE-2025-57819, an unauthenticated SQL injection in FreePBX that chains admin account creation, webshell deployment, and…

exploitationpapers-researchpayload-development+7
3 months ago
CVE-2026-104826 preview

CVE-2026-104826

GitHubkiwknr/cve-2026-104826

Proof-of-concept exploit chain for CVE-2026-104826, a path traversal in DropzoneFileExplorer's chunked upload handler that writes a PHP webshell for…

exploitationpenetration-testingremote-access-tool+3
12 months ago
CVE-2026-102427 preview

CVE-2026-102427

GitHubmurrez/cve-2026-102427

Python 3 PoC for CVE-2026-102427, an unauthenticated upload RCE in OrdaSoft Joomla CCK (com_os_cck) via task=getContent and site/uploader.php using a…

exploitationpayload-developmentpenetration-testing+4
9 days ago
CVE-2026-102425 preview

CVE-2026-102425

GitHubmurrez/cve-2026-102425

Python PoC for CVE-2026-102425: unauthenticated RCE in Joomla Balbooa Forms (com_baforms) via field shortcode injection in post-submission PHP…

exploitationpayload-developmentpenetration-testing+5
9 days ago
CVE-2026-100520-laranode-path-traversal preview

CVE-2026-100520-laranode-path-traversal

GitHubwvllxe/cve-2026-100520-laranode-path-traversal

Path Traversal -> RCE in Laranode < 1.2.1 (CWE-22). PoC + advisory writeup.

exploitationpenetration-testingremote-access-tool+3
27 days ago
CVE-2026-13249 preview

CVE-2026-13249

GitHubmurrez/cve-2026-13249

Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit…

embedded-systems-securityexploitationhardware-iot-security+6
13 days ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubyym8538/cve-2026-16723

Proof-of-concept exploit for CVE-2026-16723, a Fastjson 1.x @JSONType remote code execution flaw, with a payload JAR builder and reverse-shell…

exploitationpayload-generationpenetration-testing+4
11 month ago
CVE-2026-87930 preview

CVE-2026-87930

GitHubwinrarzipsexploit/cve-2026-87930

Joomla multi-CVE RCE suite with seven exploit modules for Balbooa Forms, Page Builder CK, SP Page Builder, JCE, iCagenda, Helix3, and SP LMS, plus…

exploitationpayload-generationpenetration-testing+7
122 days ago
CVE-2026-27540 preview

CVE-2026-27540

GitHubwinrarzipsexploit/cve-2026-27540

Python exploit suite for CVE-2026-27540, an unauthenticated file upload RCE in the WooCommerce Wholesale Lead Capture plugin, with fingerprinting,…

exploitationpayload-generationpenetration-testing+5
22 days ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubwinrarzipsexploit/cve-2026-48908

Python exploit suite for CVE-2026-48908, an unauthenticated ZIP upload RCE in Joomla SP Page Builder (<=6.6.1), with fingerprinting, batch mode, and…

exploitationpayload-developmentpenetration-testing+5
22 days ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubyym8538/cve-2026-21858

Docker-based PoC environment and exploit script for CVE-2026-21858, an n8n 1.120.4 arbitrary file read and RCE flaw, providing secret extraction and…

container-securityexploitationpenetration-testing+5
11 month ago
CVE-2026-28695-craft-rce-bypass preview

CVE-2026-28695-craft-rce-bypass

GitHubgbuyssens/cve-2026-28695-craft-rce-bypass

Authenticated, **blind** remote code execution in Craft CMS. Fix for CVE-2026-28695

exploitationpayload-developmentpenetration-testing+5
112 days ago
CVE-2026-28695 preview

CVE-2026-28695

GitHubpredyy/cve-2026-28695

Python PoC exploit for CVE-2026-28695, an authenticated blind RCE in Craft CMS that bypasses the create() BaseObject patch and spawns a reverse shell.

exploitationpenetration-testingpost-exploitation+5
1312 days ago
Previous12…79Next