Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1166 results
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubritinify/cve-2025-29927-poc

Proof-of-concept exploit for CVE-2025-29927, a Next.js middleware authorization bypass. Includes a vulnerable target lab and Python script to verify…

ctfeducationexploitation+3
1 day ago
cve-2026-32475-elementor-pro-lab preview

cve-2026-32475-elementor-pro-lab

GitHubdinosn/cve-2026-32475-elementor-pro-lab

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

educationexploitationlabs-practice+4
21 day ago
CVE-2026-19632 preview

CVE-2026-19632

GitHubghostpels/cve-2026-19632

Unauthenticated account takeover PoC for TranslatePress Multilingual <= 3.3.1 (WordPress)

authenticationexploitationpenetration-testing+3
1 day ago
CVE-2026-78070 preview

CVE-2026-78070

GitHubtoanln-cov/cve-2026-78070

SQL Injection via ORDER BY Shortcode in plg_content_dpcalendar — DPCalendar Free ≤ 10.11.2

database-securityexploitationpenetration-testing+3
3 days ago
CVE-2026-78071 preview

CVE-2026-78071

GitHubtoanln-cov/cve-2026-78071

Stored XSS via Location Title in DPCalendar Free

code-analysisexploitationvulnerability-analysis+2
3 days ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubbyt3l0rd/cve-2026-73570

Python proof-of-concept for testing SMTP command injection (CVE-2026-73570) by sending malformed RCPT TO addresses to detect shell command…

email-securityexploitationpenetration-testing+2
3 days ago
HavocPwn preview

HavocPwn

GitHubundefinedcs/havocpwn

Expanded Exploit based on CVE-2024-41570

command-and-controlexploitationpenetration-testing+3
9 months ago
CTT-Enhanced-CVE-2026-46339-Exploit-Engine preview

CTT-Enhanced-CVE-2026-46339-Exploit-Engine

GitHubsimoesctt/ctt-enhanced-cve-2026-46339-exploit-engine

Python framework exploiting CVE-2026-46339 for unauthenticated RCE on 9Router via MCP bridge, using temporal sharding and dispersion to evade…

exploitationpayload-developmentred-teaming+3
9 days ago
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass preview

the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

GitHubhunt-benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

api-securityauthenticationexploitation+3
9 days ago
CVE-2023-38831-POC preview

CVE-2023-38831-POC

GitHubmystuffyt/cve-2023-38831-poc

Proof-of-concept demonstrating CVE-2023-38831, a WinRAR path traversal vulnerability, by crafting a malicious ZIP archive that executes arbitrary…

exploitationmalware-analysispayload-development+2
2 years ago
CVE-2026-42167-PoC preview

CVE-2026-42167-PoC

GitHubjimmexploit/cve-2026-42167-poc

Functional SQL injection exploit for CVE-2026-42167 in ProFTPD mod_sql, enabling unauthenticated attackers to inject commands via USER parameter.…

exploitationpenetration-testingred-teaming+2
14 months ago
keycloak-CVE-2026-18963 preview

keycloak-CVE-2026-18963

GitHubgman0x00/keycloak-cve-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

authenticationexploitationlabs-practice+3
11 days ago
CVE-2021-21017 preview

CVE-2021-21017

GitHubtzwlhack/cve-2021-21017

Proof-of-concept exploit for CVE-2021-21017, an Adobe Reader type confusion leading to out-of-bounds read and heap overflow, with technical analysis…

binary-analysisexploitationmemory-forensics+2
4 years ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubtypeconfused/cve-2026-24061

GNU telnetd service from GNU InetUtils authentication-bypass

authentication-authorizationexploitationpenetration-testing+2
7 months ago
CVE-2024-42845-Exploit preview

CVE-2024-42845-Exploit

GitHubtheexploiters/cve-2024-42845-exploit

Exploit For: CVE-2024-42845: Remote Code Execution (RCE) in Invesalius 3.1

exploitationmalware-analysispayload-generation+2
21 year ago
CVE-2024-36840-Exploit preview

CVE-2024-36840-Exploit

GitHubtheexploiters/cve-2024-36840-exploit

Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)

exploitationinformation-gatheringpenetration-testing+2
21 year ago
CVE-2023-50164-PoC preview

CVE-2023-50164-PoC

GitHubsunnyvale-it/cve-2023-50164-poc

CVE-2023-50164 (Apache Struts path traversal to RCE vulnerability) - Proof of Concept

exploitationpayload-developmentpenetration-testing+2
22 years ago
CVE-2026-23744-Remote-Code-Execution-POC preview

CVE-2026-23744-Remote-Code-Execution-POC

GitHubsuljov/cve-2026-23744-remote-code-execution-poc

Proof-of-concept exploit for CVE-2026-23744, a remote code execution vulnerability in MCPJam inspector <=1.4.2, triggered via crafted HTTP requests…

exploitationpenetration-testingremote-access-tool+2
115 months ago
Previous12…65Next