Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
339 results
CVE-2026-3395-Lab preview

CVE-2026-3395-Lab

GitHubrootdirective-sec/cve-2026-3395-lab

Educational Docker lab demonstrating CVE-2026-3395, an unauthenticated RCE in MaxSite CMS via the run_php plugin, with vulnerable and patched…

educationexploitationlabs-practice+2
1
5 months ago
CVE-2018-16763_fuel_cms_exploit preview

CVE-2018-16763_fuel_cms_exploit

GitHubgh0stuncle/cve-2018-16763_fuel_cms_exploit

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

ctfeducationexploitation+3
3 days ago
CVE-2026-25099 preview

CVE-2026-25099

GitHubyahiahamza/cve-2026-25099

Python exploit for Bludit CMS API unrestricted file upload leading to remote code execution, providing command execution and interactive shell for…

exploitationpayload-developmentpenetration-testing+3
5 months ago
CVE-2026-29053 preview

CVE-2026-29053

GitHubrootxran/cve-2026-29053

Proof-of-concept exploit for Ghost CMS remote code execution via prototype pollution in jsonpath and static-eval, with a vulnerable environment setup…

exploitationpayload-developmentpenetration-testing+2
5 months ago
CVE-2026-29598 preview

CVE-2026-29598

GitHubpadayali-jd/cve-2026-29598

Proof-of-concept for a stored XSS vulnerability in cm3 Acora CMS 10.7.1, demonstrating script injection via user management endpoints.

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
CVE-2026-29597 preview

CVE-2026-29597

GitHubpadayali-jd/cve-2026-29597

Demonstrates an improper access control vulnerability in DDSN Interactive cm3 Acora CMS 10.7.1, allowing editor-privileged users to retrieve…

exploitationinformation-gatheringpenetration-testing+2
5 months ago
CVE-2026-3395-MaxSite-CMS-Unauthenticated-RCE preview

CVE-2026-3395-MaxSite-CMS-Unauthenticated-RCE

GitHubmbanyamer/cve-2026-3395-maxsite-cms-unauthenticated-rce

Proof-of-concept exploit for unauthenticated remote code execution in MaxSite CMS <= 109.1 via MarkItUp editor AJAX endpoints, with detection and…

educationexploitationpenetration-testing+3
56 months ago
CVE-2025-10353-POC preview

CVE-2025-10353-POC

GitHubivansmc/cve-2025-10353-poc

Exploit for CVE-2025-10353. Unauthenticated File Upload on Melis Platform Framework that leads to RCE

exploitationpayload-generationpenetration-testing+2
110 months ago
CVE-2026-31891 preview

CVE-2026-31891

GitHubffasterss/cve-2026-31891

SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw()

database-securityexploitationpenetration-testing+3
5 months ago
ghost-cve-2026-26980 preview

ghost-cve-2026-26980

GitHubdinosn/ghost-cve-2026-26980

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

database-securityeducationexploitation+5
164 months ago
CVE-2026-1953 preview

CVE-2026-1953

GitHubdewaguard-red-team/cve-2026-1953

Stored cross-site scripting (XSS) vulnerability in the edit profile feature at Nukegraphic CMS V3.1.2

exploitationpenetration-testingvulnerability-analysis+2
26 months ago
CVE-2026-41177-Squidex-CMS preview

CVE-2026-41177-Squidex-CMS

GitHubturkios/cve-2026-41177-squidex-cms

CVE-2026-41177, a Blind SSRF vulnerability in Squidex CMS (prior to v7.23.0). Includes root cause analysis, reproduction steps, and impact assessment…

educationexploitationvulnerability-analysis+1
4 months ago
CVE-2025-41089 preview

CVE-2025-41089

GitHubmarinafabregat/cve-2025-41089

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input.

exploitationpapers-researchvulnerability-analysis+2
410 months ago
CVE-2026-42141-xibo-ssrf preview

CVE-2026-42141-xibo-ssrf

GitHubh4zaz/cve-2026-42141-xibo-ssrf

Proof-of-concept for SSRF in Xibo CMS via uploadUrl endpoint, demonstrating authenticated server-side request forgery to internal resources.

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
CVE-2026-29053 preview

CVE-2026-29053

GitHubac8999/cve-2026-29053

(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)

exploitationpayload-developmentpenetration-testing+2
14 months ago
halo-cors-csrf-CVE-2026-67921 preview

halo-cors-csrf-CVE-2026-67921

GitHubunpredictable21/halo-cors-csrf-cve-2026-67921

Proof-of-concept demonstrating a combined CORS misconfiguration and CSRF protection bypass in Halo CMS, enabling cross-site request forgery attacks…

exploitationvulnerability-analysisweb-application-exploitation+1
18 days ago
halo-2.25.4-backup-write-CVE-2026-67920 preview

halo-2.25.4-backup-write-CVE-2026-67920

GitHubunpredictable21/halo-2.25.4-backup-write-cve-2026-67920

Proof-of-concept exploit for an arbitrary file write vulnerability in Halo CMS backup restoration, enabling RCE via plugin JAR replacement or…

code-analysisexploitationpenetration-testing+3
1 month ago
CVE-2026-63072 preview

CVE-2026-63072

GitHub0xblackash/cve-2026-63072

Technical analysis of CVE-2026-63072, a heap buffer overflow in OpenSSL CMS key unwrapping, covering root cause, affected versions, detection, and…

curated-resourceseducationexploitation+1
2 days ago
Previous12…19Next