Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
Web-App-PenTesting preview

Web-App-PenTesting

GitHubsarthak4126/web-app-pentesting

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

educationlabs-practicepenetration-testing+4
2 days ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
3 days ago
CVE-2026-84434 preview

CVE-2026-84434

GitHubmurrez/cve-2026-84434

Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields.…

exploitationpenetration-testingreconnaissance+5
5 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubmatakucing-ofc/cve-2026-49049

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

exploitationpenetration-testingremote-access-tool+4
13 days ago
CVE-2026-18351 preview

CVE-2026-18351

GitHubjohenlastgen-jlg/cve-2026-18351

Mass exploit tool for CVE-2026-18351, an unauthenticated arbitrary file upload to RCE in Elementor Forms <= 1.6.0, with passive probing, shell…

exploitationpayload-developmentpenetration-testing+5
113 days ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

educationexploitationpayload-development+3
21 month ago
rsfiles-CVE-2026-57827 preview

rsfiles-CVE-2026-57827

GitHubmohammad-008/rsfiles-cve-2026-57827

Unauthenticated File Upload → RCE PoC for CVE-2026-57827 (RSFiles! Joomla < 1.17.12). Authorized security research use only.

exploitationinformation-gatheringpayload-development+2
91 month ago
CVE-2021-21972 preview

CVE-2021-21972

GitHubhurrrraaaa/cve-2021-21972

Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection,…

educationexploitationlabs-practice+4
1 month ago
ninja-form-exploit preview

ninja-form-exploit

GitHubmadexploits/ninja-form-exploit

CVE-2026-0740

exploitationfuzzinginformation-gathering+3
32 months ago
CVE-2026-56291 preview

CVE-2026-56291

GitHub0xdenis77/cve-2026-56291

Mendeteksi versi (passive detection) & Exploitation CVE POC

exploitationinformation-gatheringpenetration-testing+3
12 months ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

command-and-controlexploitationinformation-gathering+8
12 months ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubiicaicai/cve-2026-5524-poc

Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and…

exploitationinformation-gatheringpayload-development+8
2 months ago
pbck-exploit preview

pbck-exploit

GitHubshinthink/pbck-exploit

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

exploit-frameworkspayload-developmentpenetration-testing+4
32 months ago
CVE-2024-9290 preview

CVE-2024-9290

GitHubjenderal92/cve-2024-9290

The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.

exploitationpenetration-testingvulnerability-scanners+1
13 months ago
CVE-2026-6271 preview

CVE-2026-6271

GitHubxxconi/cve-2026-6271

Automated scanner for CVE-2026-6271, a critical unauthenticated arbitrary file upload leading to RCE in the WordPress Career Section plugin. Supports…

educationexploitationpayload-generation+4
4 months ago
CVE-2026-2942 preview

CVE-2026-2942

GitHubxxconi/cve-2026-2942

Automated scanner for unauthenticated arbitrary file upload and remote code execution in ProSolution WP Client (CVE-2026-2942). Supports…

educationexploitationpayload-development+3
4 months ago
CVE-2026-0740 preview

CVE-2026-0740

GitHubmurrez/cve-2026-0740

Exploit script for CVE-2026-0740 targeting Ninja Forms file upload endpoints to upload a PHP shell, scanning a list of URLs and logging successful…

exploitationvulnerability-scannersweb-application-exploitation+1
15 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHub0xgh057r3c0n/cve-2026-3844

WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload

exploitationpenetration-testingvulnerability-scanners+2
15 months ago
Previous123Next