Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
CVE-2026-0920 preview

CVE-2026-0920

GitHubk3ystr0k3r/cve-2026-0920

Proof-of-concept exploit for CVE-2026-0920, an unauthenticated privilege escalation in LA-Studio Element Kit WordPress plugin, allowing creation of…

exploitationpenetration-testingprivilege-escalation+2
1 day ago
CVE-2026-19598- preview

CVE-2026-19598-

GitHub0xcyp1337/cve-2026-19598-

Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning…

exploitationpenetration-testingprivilege-escalation+2
1 day ago
WordPressMassExploiter preview

WordPressMassExploiter

GitHubdmonst3r/wordpressmassexploiter

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

exploitationinformation-gatheringreconnaissance+3
308 years ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubjuanpoch/cve-2026-73570

Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)

educationexploitationpapers-research+3
0 days ago
HackTheBox-Connected preview

HackTheBox-Connected

GitHubikmalhanaan/hackthebox-connected

Detailed penetration testing writeup for HackTheBox 'Connected' machine, covering exploitation of FreePBX CVE-2025-57819 (SQLi to RCE) and privilege…

ctfeducationexploitation+5
14 days ago
FreePBX-SQLi-Exploit-Privilege-escalation preview

FreePBX-SQLi-Exploit-Privilege-escalation

GitHubitsc1sco/freepbx-sqli-exploit-privilege-escalation

This walkthrough documents the complete compromise of the HTB machine Connected.

code-analysisctfeducation+5
120 days ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub4minx/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

exploitationpayload-developmentpenetration-testing+3
1 day ago
Langflow-RCE-CVE-2025-3248 preview

Langflow-RCE-CVE-2025-3248

GitHubleotheggman/langflow-rce-cve-2025-3248

Proof-of-concept exploit for CVE-2025-3248, a remote code execution vulnerability in Langflow, demonstrating exploitation of the vulnerable endpoint.

exploitationvulnerability-analysisweb-application-exploitation
1 day ago
CVE-2023-42793-TeamCity-Unauthenticated-RCE preview

CVE-2023-42793-TeamCity-Unauthenticated-RCE

GitHubburakacar6/cve-2023-42793-teamcity-unauthenticated-rce

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

authenticationexploitationpenetration-testing+3
1 day ago
CVE-2026-75865 preview

CVE-2026-75865

GitHubghostpels/cve-2026-75865

Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC

educationexploitationpenetration-testing+3
1 day ago
EXPLOIT-CVE-2026-22778 preview

EXPLOIT-CVE-2026-22778

GitHubjoaovicdev/exploit-cve-2026-22778

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

binary-exploitationeducationexploitation+5
1 day ago
CVE-2026-56718 preview

CVE-2026-56718

GitHubhellkkid/cve-2026-56718

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

embedded-systems-securityexploitationiot-security+3
2 days ago
CVE-2026-34197-PoC preview

CVE-2026-34197-PoC

GitHubnirvanasec/cve-2026-34197-poc

Proof-of-concept exploit for CVE-2026-34197, an RCE in Apache ActiveMQ via Jolokia's addNetworkConnector, with technical notes and reverse shell…

exploitationpenetration-testingred-teaming+3
2 days ago
cve-2026-19900-PoC preview

cve-2026-19900-PoC

GitHubon3sk-0x1/cve-2026-19900-poc

Proof-of-concept exploit for CVE-2026-19900, an authentication bypass and remote code execution vulnerability in LB-LINK X-PRO routers, allowing…

authenticationexploitationiot-security+3
2 days ago
tomcatfileread preview

tomcatfileread

GitHublem0n817/tomcatfileread

CVE-2020-1938 (Ghostcat) Tomcat AJP file read/file include PoC with python3 port

exploitationinformation-gatheringpenetration-testing+2
2 days ago
tfo-connect-bypass preview

tfo-connect-bypass

GitHub4n4s4zi/tfo-connect-bypass

Bypassing connect()-based syscall rules using TCP Fast Open (CVE-2026-63828 PoC)

exploitationids-ips-evasionnetwork-security+3
4 days ago
POC-CVE-2026-0768 preview

POC-CVE-2026-0768

GitHubrmhowe425/poc-cve-2026-0768

Proof-of-concept exploit for CVE-2026-0768 in Langflow, allowing remote command execution via crafted HTTP requests.

exploitationpenetration-testingred-teaming+2
4 days ago
CVE-2022-25765 preview

CVE-2022-25765

GitHubinnocentx0/cve-2022-25765

Python proof-of-concept for CVE-2022-25765, a command injection vulnerability in pdfkit, enabling remote code execution via crafted PDF generation.

command-and-controlctfeducation+4
4 days ago
Previous12…100Next