Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
180 results
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
13
22 days ago
CVE-2026-76569 preview

CVE-2026-76569

GitHubtoanln-cov/cve-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

exploitationpenetration-testingvulnerability-analysis+2
24 days ago
CVE-2024-12856 preview

CVE-2024-12856

GitHubnu113d/cve-2024-12856

An exploit for Four-Faith routers to get a reverse shell

exploitationpenetration-testingremote-access-tool+2
31 year ago
CVE-2021-43798 preview

CVE-2021-43798

GitHublalkaltest/cve-2021-43798

Proof-of-concept exploit for Grafana arbitrary file reading vulnerability (CVE-2021-43798) affecting versions 8.0.0 to 8.3.0, demonstrating…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
poc-cve-2026-32255 preview

poc-cve-2026-32255

GitHubkoadt/poc-cve-2026-32255

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

educationexploitationpenetration-testing+3
26 months ago
CVE-2026-7028-SQLI preview

CVE-2026-7028-SQLI

GitHubxmyronn/cve-2026-7028-sqli

Proof-of-concept exploit for SQL injection in CodeAstro Online Job Portal allowing authenticated deletion of all job records via crafted GET request.

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
CVE-2026-35584 preview

CVE-2026-35584

GitHubspoo1k/cve-2026-35584

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

exploitationinformation-gatheringpenetration-testing+3
5 months ago
CVE-2026-76565 preview

CVE-2026-76565

GitHubtoanln-cov/cve-2026-76565

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

exploitationpapers-researchvulnerability-analysis+2
1 month ago
CVE-2026-74251 preview

CVE-2026-74251

GitHubtoanln-cov/cve-2026-74251

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

database-securitydata-exfiltrationexploitation+3
1 month ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
SQLi_Sleeps preview

SQLi_Sleeps

GitHubhernanrodriguez1/sqli_sleeps

Detects time-based SQL injection by sending crafted GET requests to multiple URLs and measuring delayed responses; includes cookie support for…

penetration-testingweb-application-exploitationweb-security+1
1251 year ago
CVE-2025-68937 preview

CVE-2025-68937

GitHubscratchappy/cve-2025-68937

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

exploitationpenetration-testingprivilege-escalation+3
1 month ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
Homework-of-Python preview

Homework-of-Python

GitHub3gstudent/homework-of-python

Python codes of my blog.

exploitationinformation-gatheringpassword-attacks+5
4103 years ago
ninja-forms-brute preview

ninja-forms-brute

GitHubrandomrobbiebf/ninja-forms-brute

Exploit for Ninja Forms plugin vulnerability allowing unauthenticated download of submission CSVs to disclose email addresses.

information-gatheringvulnerability-analysisweb-application-exploitation
4 years ago
CVE-2024-7135 preview

CVE-2024-7135

GitHubnxploited/cve-2024-7135

Proof-of-concept exploit for authenticated arbitrary file read via directory traversal in WordPress Tainacan plugin (CVE-2024-7135).

data-exfiltrationexploitationinformation-gathering+2
1 year ago
revshell preview

revshell

GitHubprodigiousmind/revshell

Pentestmonkeys' PHP reverse shell with dynamic host and port passing through GET request parameters

exploitationpayload-generationpenetration-testing+3
43 years ago
eos preview

eos

GitHubsynacktiv/eos

Enemies Of Symfony - Debug mode Symfony looter

information-gatheringmisconfigurationpenetration-testing+3
3631 year ago
Previous12…10Next