Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
CVE-2026-22599 preview

CVE-2026-22599

GitHubabraxas/cve-2026-22599

Python PoC and Docker lab for CVE-2026-22599, an authenticated SQL injection in Strapi's Content-Type Builder write API via Knex raw defaultTo.

database-securityexploitationlabs-practice+5
1
3 days ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
13 days ago
Comment2Shell preview

Comment2Shell

GitHubdeathshotxd/comment2shell

Zero-click pre-auth WordPress CVE-2026-93485 exploit chain: stored XSS in wpautop() escalates to admin-session plugin upload and a self-deleting…

exploitationlabs-practicepayload-development+7
634 days ago
cve-2026-103956-loom-unauth preview

cve-2026-103956-loom-unauth

GitHubabraxas/cve-2026-103956-loom-unauth

CVE-2026-103956 - Loom for AWS - Critical - Auth bypass - unauthenticated super-admin when no IdP is configured

authenticationcloud-securityexploitation+5
36 days ago
cve-2026-100671-poc preview

cve-2026-100671-poc

GitHubcanhieu/cve-2026-100671-poc

Local-only proof-of-concept verifier for CVE-2026-100671, reproducing Grav Twig page-cache session-cookie disclosure and replay against loopback…

exploitationpenetration-testingsecurity-virtualization+3
8 days ago
CVE-2026-52782 preview

CVE-2026-52782

GitHubabraxas/cve-2026-52782

Reproduction pack and PoC script for CVE-2026-52782, an authenticated IDOR in OpenProject project storage settings that hijacks Nextcloud/OneDrive…

exploitationinformation-gatheringlabs-practice+5
9 days ago
CVE-2026-62062 preview

CVE-2026-62062

GitHubabraxas/cve-2026-62062

Proof-of-concept and lab pack for CVE-2026-62062, an unauthenticated CSRF REST nonce bypass in Elementor 4.3.0-4.3.1 enabling administrator account…

exploitationlabs-practicepenetration-testing+4
19 days ago
CVE-2026-81648 preview

CVE-2026-81648

GitHubabraxas/cve-2026-81648

Proof-of-concept exploit and lab for CVE-2026-81648, an unauthenticated arbitrary file deletion flaw in the WordPress CryptoPayment Gateway plugin.

exploitationlabs-practicepenetration-testing+5
9 days ago
CVE-2026-48356 preview

CVE-2026-48356

GitHubabraxas/cve-2026-48356

Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.

exploitationlabs-practicepayload-generation+5
9 days ago
adm-zip_LPE-PoC preview

adm-zip_LPE-PoC

GitHubx86byte/adm-zip_lpe-poc

CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction

exploitationpayload-developmentprivilege-escalation+4
109 days ago
CVE-2026-102261 preview

CVE-2026-102261

GitHub7acini/cve-2026-102261

Non-destructive Go verifier that checks whether a Camaleon CMS instance applies the authorization fix for CVE-2026-102261 in the media crop endpoint.

authentication-authorizationdefensive-toolspenetration-testing+5
10 days ago
CVE-2026-49869 preview

CVE-2026-49869

GitHubeqstlab/cve-2026-49869

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…

authenticationexploitationlabs-practice+6
410 days ago
CVE-2021-41773-Apache-Path-Traversal-Lab preview

CVE-2021-41773-Apache-Path-Traversal-Lab

GitHub1833ravikumar-max/cve-2021-41773-apache-path-traversal-lab

Docker-based cybersecurity lab for studying and reproducing CVE-2021-41773 in an isolated environment.

ctfeducationexploitation+6
12 days ago
CVE-2026-61500 preview

CVE-2026-61500

GitHubaramosf/cve-2026-61500

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

cryptographyeducationexploitation+7
13 days ago
CVE-2026-5430 preview

CVE-2026-5430

GitHubabraxas/cve-2026-5430

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

api-securityauthenticationcryptography+6
114 days ago
CVE-2026-12227-visualcomposer-lfi-poc preview

CVE-2026-12227-visualcomposer-lfi-poc

GitHubhassham1/cve-2026-12227-visualcomposer-lfi-poc

Docker validation lab and safe-oracle PoC for CVE-2026-12227, an unauthenticated LFI in Visual Composer via vcv-template, with a nuclei detection…

exploitationlabs-practicepenetration-testing+5
115 days ago
CVE-2026-89274-wp-recipe-maker-poc preview

CVE-2026-89274-wp-recipe-maker-poc

GitHubhassham1/cve-2026-89274-wp-recipe-maker-poc

Docker validation lab and Python PoC for CVE-2026-89274, proving arbitrary shortcode execution in WP Recipe Maker <= 10.8.1 via rating-comment…

exploitationlabs-practicepenetration-testing+5
16 days ago
CVE-2026-87902-PoC-pwnVader preview

CVE-2026-87902-PoC-pwnVader

GitHubpwnvader/cve-2026-87902-poc-pwnvader

Shell PoC for CVE-2026-87902, an unauthenticated WordPress core LFI via page-template resolution that chains to RCE through pearcmd.php.

exploitationpayload-developmentpenetration-testing+5
17 days ago
Previous123Next