Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
113 results
langflow-CVE-2026-17633-PoC preview

langflow-CVE-2026-17633-PoC

GitHuboscar-collado/langflow-cve-2026-17633-poc

PoC for CVE-2026-17633 — Authenticated RCE in IBM Langflow OSS 1.0.0–1.10.3 via custom_component endpoint. Includes CVE-2026-17632 AST scanner bypass…

code-analysisexploitationpenetration-testing+2
18 days ago
CVE-2026-27876 preview

CVE-2026-27876

GitHubatiilla/cve-2026-27876

Grafana SQL Expressions Arbitrary File Write to RCE

educationexploitationpenetration-testing+3
18 days ago
PAN-OS-User-ID-Buffer-Overflow-PoC preview

PAN-OS-User-ID-Buffer-Overflow-PoC

GitHubqassam-315/pan-os-user-id-buffer-overflow-poc

A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™…

binary-exploitationexploitationpenetration-testing+2
34 months ago
CVE-2026-0300-POC preview

CVE-2026-0300-POC

GitHubp3nt3st3r-star/cve-2026-0300-poc

Proof-of-concept for CVE-2026-0300, a critical buffer overflow in PAN-OS User-ID Portal enabling unauthenticated remote code execution with root…

exploitationpayload-developmentpenetration-testing+3
224 months ago
CVE-2026-0300-PANOS preview

CVE-2026-0300-PANOS

GitHubmatad0r-maghribi/cve-2026-0300-panos

Security Research and Proof-of-Concept (PoC) for CVE-2026-0300 : Unauthenticated Remote Code Execution (RCE) in Palo Alto Networks PAN-OS User-ID…

educationexploitationpenetration-testing+3
44 months ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubjishino567/cve-2026-73570

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

email-securityexploitationpenetration-testing+3
229 days ago
BadBizness-CVE-2023-51467 preview

BadBizness-CVE-2023-51467

GitHubjakeotte/badbizness-cve-2023-51467

Auto exploit script for the Java web framework OF Biz under CVE-2023-51467.

exploitationpenetration-testingred-teaming+2
2 years ago
cve-2026-33937 preview

cve-2026-33937

GitHubdinhvaren/cve-2026-33937

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

code-analysisexploitationpayload-development+2
4 months ago
cpanelCVE-2026-41940 preview

cpanelCVE-2026-41940

GitHubbughunt4me/cpanelcve-2026-41940

Proof-of-concept exploit for CVE-2026-41940, a critical cPanel & WHM authentication bypass via session-file CRLF injection, enabling automatic root…

authentication-authorizationexploitationpenetration-testing+3
134 months ago
cve-2025-3248 preview

cve-2025-3248

GitHubbambooqj/cve-2025-3248

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

command-and-controlexploitationpenetration-testing+3
111 months ago
CVE-2024-3400-poc preview

CVE-2024-3400-poc

GitHubghassansabir/cve-2024-3400-poc

Proof-of-concept exploit for CVE-2024-3400, a command injection vulnerability in Palo Alto firewalls, demonstrating file creation and remote command…

command-and-controlexploitationpenetration-testing+2
1 year ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
11 month ago
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
21 month ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

educationexploitationpayload-development+3
21 month ago
POC-CVE-2026-0300-exploit preview

POC-CVE-2026-0300-exploit

GitHubsam00/poc-cve-2026-0300-exploit

Palo Alto - CVE-2026-0300 exploit

binary-exploitationexploitationnetwork-security+6
1 month ago
CVE-2026-33937 preview

CVE-2026-33937

GitHubc0gnit00/cve-2026-33937

Python POC, Exploit for Handlebars.js AST Injection RCE, Handlebars.js versions 4.0.0 through 4.7.8 are affected. CVSS score: 9.8 Critical.

educationexploitationpayload-development+3
11 month ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
CVE-2024-12252 preview

CVE-2024-12252

GitHubrandomrobbiebf/cve-2024-12252

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

authentication-authorizationexploitationmisconfiguration+5
1 year ago
Previous1234567Next