Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
CVE-2026-102425 preview

CVE-2026-102425

GitHubtonydelouvre/cve-2026-102425

GUI scanner and exploit for CVE-2026-102425, an unauthenticated RCE in Balbooa Forms (com_baforms) via PHP shortcode injection, with mass scanning…

exploitationpayload-developmentpenetration-testing+7
8 days ago
CVE-2026-44011-craft-rce-poc preview

CVE-2026-44011-craft-rce-poc

GitHubcyberuser-hash/cve-2026-44011-craft-rce-poc

Python proof-of-concept for CVE-2026-44011 in Craft CMS, exploiting authenticated remote code execution with command execution and base64-wrapped…

exploitationpayload-generationpenetration-testing+4
112 days ago
CVE-2026-63030 preview

CVE-2026-63030

GitHublangz337/cve-2026-63030

Python exploit tool chaining CVE-2026-63030 REST batch-route confusion with CVE-2026-60137 SQL injection to achieve unauthenticated WordPress RCE,…

command-and-controlexploitationpayload-development+8
113 days ago
CVE-2026-65660-Poc preview

CVE-2026-65660-Poc

GitHubshadowforge-cyber/cve-2026-65660-poc

Malicious Register Directive Code Injection Exploit

command-and-controldata-exfiltrationexploitation+8
114 days ago
CVE-2026-78006-POC preview

CVE-2026-78006-POC

GitHubdeadexpl0it/cve-2026-78006-poc

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

defensive-toolsexploitationpayload-development+7
427 days ago
veneficus preview

veneficus

GitHubabraxas/veneficus

Super elite end-to-end implant 0day. Full kill-chain. Exploit, escalate, pivot, poison, persistence.

command-and-controldata-exfiltrationids-ips-evasion+8
21 month ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubmaxprog-svg/cve-2026-33017

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

command-and-controlexploitationreconnaissance+3
1 month ago
CTT-Enhanced-CVE-2026-46339-Exploit-Engine preview

CTT-Enhanced-CVE-2026-46339-Exploit-Engine

GitHubsimoesctt/ctt-enhanced-cve-2026-46339-exploit-engine

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

exploitationpayload-developmentred-teaming+3
1 month ago
CVE-2026-75604-poc preview

CVE-2026-75604-poc

GitHubrafabd1/cve-2026-75604-poc

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js apps, with callback-based command…

exploitationpenetration-testingremote-access-trojan+2
1051 month ago
CVE-2026-75429_PowerJob_friend_process_RCE preview

CVE-2026-75429_PowerJob_friend_process_RCE

GitHubunpredictable21/cve-2026-75429_powerjob_friend_process_rce

Unauthenticated remote code execution exploit for PowerJob Server via Groovy injection in the /friend/process endpoint, enabling arbitrary command…

exploitationpenetration-testingremote-access-trojan+2
2 months ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubiicaicai/cve-2026-5524-poc

Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and…

exploitationinformation-gatheringpayload-development+8
3 months ago
Research-CVE-2026-21858 preview

Research-CVE-2026-21858

GitHubbannt08/research-cve-2026-21858

Technical analysis and proof-of-concept for CVE-2026-21858, an authentication bypass and RCE in n8n, demonstrating LFI, session forgery, and full…

authenticationexploitationremote-access-trojan+2
5 months ago
CVE-2026-33725 preview

CVE-2026-33725

GitHubhakaioffsec/cve-2026-33725

Proof-of-concept exploit for CVE-2026-33725, achieving remote code execution and arbitrary file read via H2 JDBC INIT injection in Metabase…

exploitationpenetration-testingremote-access-trojan+2
245 months ago
CVE-2026-22738 preview

CVE-2026-22738

GitHubrockmelodies/cve-2026-22738

SpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code Execution

educationexploitationpayload-development+3
26 months ago
CVE-2026-102607-ZoneMinder preview

CVE-2026-102607-ZoneMinder

GitHubd4kw1n/cve-2026-102607-zoneminder

Python PoC exploiting CVE-2026-102607, an authenticated OS command injection in ZoneMinder <= 1.38.1 exportEvents() enabling RCE, command output…

command-and-controlexploitationpenetration-testing+4
16 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubinzegosec/cve-2026-23744

Exploit for MCPJam Inspector <=1.4.2 that triggers remote code execution via crafted HTTP requests, enabling unauthorized installation of MCP servers…

exploitationpenetration-testingremote-access-trojan+2
16 months ago
CVE-2026-0770 preview

CVE-2026-0770

GitHub0xgh057r3c0n/cve-2026-0770

Langflow Remote Code Execution (RCE) Proof-of-Concept

educationexploitationpenetration-testing+3
17 months ago
CVE-2026-0770-PoC preview

CVE-2026-0770-PoC

GitHubaffix/cve-2026-0770-poc

Proof of Concept for CVE-2026-0770 - Langflow Remote Code Execution

exploitationpenetration-testingremote-access-trojan+2
67 months ago
Previous12Next