Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
339 results
CVE-2024-31835 preview

CVE-2024-31835

GitHubparagbagul111/cve-2024-31835

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a craftedpayload to the…

code-analysisexploitationpenetration-testing+2
1 year ago
CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description preview

CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description

GitHubsromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description

Quick CMS 6.7 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

educationexploitationpenetration-testing+3
2 years ago
CVE-2023-43345-Quick-CMS-Stored-XSS---Pages-Content preview

CVE-2023-43345-Quick-CMS-Stored-XSS---Pages-Content

GitHubsromanhu/cve-2023-43345-quick-cms-stored-xss---pages-content

Quick CMS 6.7 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

educationexploitationpenetration-testing+2
2 years ago
CVE-2023-43343-Quick-CMS-Stored-XSS---Pages-Files preview

CVE-2023-43343-Quick-CMS-Stored-XSS---Pages-Files

GitHubsromanhu/cve-2023-43343-quick-cms-stored-xss---pages-files

Quick CMS 6.7 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2023-43346-Quick-CMS-Stored-XSS---Languages-Backend preview

CVE-2023-43346-Quick-CMS-Stored-XSS---Languages-Backend

GitHubsromanhu/cve-2023-43346-quick-cms-stored-xss---languages-backend

Quick CMS 6.7 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

educationexploitationpenetration-testing+3
2 years ago
CVE-2023-41436-CSZ-CMS-Stored-XSS---Pages-Content preview

CVE-2023-41436-CSZ-CMS-Stored-XSS---Pages-Content

GitHubsromanhu/cve-2023-41436-csz-cms-stored-xss---pages-content

CSZ CMS 1.3.0 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2022-26265 preview

CVE-2022-26265

GitHubredteamsecurity2023/cve-2022-26265

The first proof of concept of the Contao CMS RCE

exploitationpayload-generationpenetration-testing+2
3 years ago
CVE-2022-42095 preview

CVE-2022-42095

GitHubbypazs/cve-2022-42095

Backdrop CMS version 1.23.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Page content.

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
WBCE-CMS-Stored-XSS---Pages-Menu preview

WBCE-CMS-Stored-XSS---Pages-Menu

GitHubsromanhu/wbce-cms-stored-xss---pages-menu

WBCE CMS 1.6.1 is affected by a cross-site stored scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a payload crafted…

exploitationpenetration-testingvulnerability-analysis+1
3 years ago
CockpitCMS-Arbitrary-File-Upload--XSS---Assets preview

CockpitCMS-Arbitrary-File-Upload--XSS---Assets

GitHubsromanhu/cockpitcms-arbitrary-file-upload--xss---assets

Cockpit CMS 2.7.0 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will…

exploitationvulnerability-analysisweb-application-exploitation
2 years ago
RCE-RealEstateVIDEOPOC preview

RCE-RealEstateVIDEOPOC

GitHubvulnerablecms/rce-realestatevideopoc

RCE-POC-RealEstate CMS

exploitationvulnerability-analysisweb-application-exploitation
2 years ago
CVE-2026-29598 preview

CVE-2026-29598

GitHubpadayali-jd/cve-2026-29598

Proof-of-concept for a stored XSS vulnerability in cm3 Acora CMS 10.7.1, demonstrating script injection via user management endpoints.

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
ghost-cve-2026-26980 preview

ghost-cve-2026-26980

GitHubdinosn/ghost-cve-2026-26980

CVE-2026-26980 — Ghost CMS Content API SQL Injection Lab (unauthenticated blind SQLi via slug filter ordering)

database-securityeducationexploitation+5
164 months ago
CVE-2026-1953 preview

CVE-2026-1953

GitHubdewaguard-red-team/cve-2026-1953

Stored cross-site scripting (XSS) vulnerability in the edit profile feature at Nukegraphic CMS V3.1.2

exploitationpenetration-testingvulnerability-analysis+2
26 months ago
CVE-2025-41089 preview

CVE-2025-41089

GitHubmarinafabregat/cve-2025-41089

Reflected Cross-Site Scripting (XSS) in Xibo CMS v4.1.2 from Xibo Signage, due to a lack of proper validation of user input.

exploitationpapers-researchvulnerability-analysis+2
410 months ago
CVE-2026-42141-xibo-ssrf preview

CVE-2026-42141-xibo-ssrf

GitHubh4zaz/cve-2026-42141-xibo-ssrf

Proof-of-concept for SSRF in Xibo CMS via uploadUrl endpoint, demonstrating authenticated server-side request forgery to internal resources.

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
CVE-2026-29053 preview

CVE-2026-29053

GitHubac8999/cve-2026-29053

(RCE) vulnerability discovered in Ghost CMS (specifically affecting versions 0.7.2 through 6.19.0)

exploitationpayload-developmentpenetration-testing+2
14 months ago
CVE-2025-15467 preview

CVE-2025-15467

GitHubguiimoraes/cve-2025-15467

Command Execution PoC for OpenSSL Stack buffer overflow CVE-2025-15467

binary-exploitationcryptographyeducation+5
156 months ago
Previous1…16171819Next