Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
243 results
CVE-2026-65660-Poc preview

CVE-2026-65660-Poc

GitHubshadowforge-cyber/cve-2026-65660-poc

Malicious Register Directive Code Injection Exploit

command-and-controldata-exfiltrationexploitation+8
1
13 days ago
CVE-2025-59287-WSUS-2 preview

CVE-2025-59287-WSUS-2

GitHubsamy4samy/cve-2025-59287-wsus-2

Proof-of-concept exploit for CVE-2025-59287, a remote code execution vulnerability in Microsoft WSUS via unsafe deserialization. Sends crafted SOAP…

educationexploitationpenetration-testing+2
10 months ago
msdt-follina preview

msdt-follina

GitHubjohnhammond/msdt-follina

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

command-and-controlexploitationpayload-development+2
1.6k4 years ago
CVE-2026-55040-Mass-Exploit preview

CVE-2026-55040-Mass-Exploit

GitHubmaxprog-svg/cve-2026-55040-mass-exploit

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

authentication-authorizationexploitationpayload-generation+3
1 month ago
CVE-2026-63520 preview

CVE-2026-63520

GitHubhypnguyen1209/cve-2026-63520

Exploit chain for unauthenticated RCE on Microsoft SharePoint, combining a JWT authentication bypass with unsafe .NET type instantiation to achieve…

authentication-authorizationexploitationpayload-development+5
11 month ago
CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE preview

CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE

GitHubmbanyamer/cve-2026-26030-microsoft-semantic-kernel-1.39.4-rce

Proof-of-concept exploit for CVE-2026-26030, demonstrating remote code execution via unsafe filter expressions in Microsoft Semantic Kernel's…

code-analysiseducationexploitation+2
17 months ago
Ashwesker-CVE-2026-21509 preview

Ashwesker-CVE-2026-21509

GitHubkimstars/ashwesker-cve-2026-21509

Proof-of-concept exploit for Microsoft Office security feature bypass (CVE-2026-21509). Generates malicious DOCX files with embedded OLE objects to…

exploitationmalware-analysispayload-generation+3
118 months ago
CVE-2026-20841-PoC preview

CVE-2026-20841-PoC

GitHubhackfaiz/cve-2026-20841-poc

Proof of concept demonstrating command execution in Microsoft Notepad via crafted files, enabling arbitrary code execution and system compromise.

command-and-controlexploitationpayload-development+2
17 months ago
CVE-2021-41349 preview

CVE-2021-41349

GitHubexploit-io/cve-2021-41349

Exploit tool for CVE-2021-41349 that generates an HTML form to deliver XSS payloads to Microsoft Exchange servers, enabling execution of arbitrary…

exploitationpayload-generationvulnerability-analysis+2
114 years ago
CVE-2026-20841-PoC preview

CVE-2026-20841-PoC

GitHubdogukankurnaz/cve-2026-20841-poc

Proof-of-concept demonstrating command injection in Windows Notepad via crafted Markdown links, enabling remote code execution. Includes attack…

educationexploitationpapers-research+2
27 months ago
SCTT-2026-33-0007-The-OLE-Vortex-Laminar-Bypass- preview

SCTT-2026-33-0007-The-OLE-Vortex-Laminar-Bypass-

GitHubsimoesctt/sctt-2026-33-0007-the-ole-vortex-laminar-bypass-

Microsoft just released emergency patches for CVE-2026-21509, a zero-day in the Office Suite that bypasses OLE/COM mitigations when a user simply…

exploitationmalware-analysispayload-generation+3
18 months ago
CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509 preview

CTT-MICROSOFT-OFFICE-OLE-MANIFOLD-BYPASS-CVE-2026-21509

GitHubsimoesctt/ctt-microsoft-office-ole-manifold-bypass-cve-2026-21509

Exploit for CVE-2026-21509, a Microsoft Office OLE validation bypass using a speculative race-condition technique to evade AMSI/EDR and achieve code…

binary-exploitationexploitationmalware-analysis+3
38 months ago
cve-2025-59287-exploit-poc preview

cve-2025-59287-exploit-poc

GitHubmaxymgorn/cve-2025-59287-exploit-poc

Proof-of-concept exploit for CVE-2025-59287, a critical unauthenticated RCE in WSUS via unsafe BinaryFormatter deserialization, achieving SYSTEM…

exploitationpayload-developmentpenetration-testing+3
11 months ago
testanull-CVE-2021-42321_poc.py preview

testanull-CVE-2021-42321_poc.py

GitHubtimb-machine-mirrors/testanull-cve-2021-42321_poc.py

Proof-of-concept exploit for CVE-2021-42321, demonstrating exploitation of a Microsoft Exchange Server vulnerability for security research and…

exploitationvulnerability-analysisweb-application-exploitation
4 years ago
CVE-2026-32201-exploit preview

CVE-2026-32201-exploit

GitHubb1tbit/cve-2026-32201-exploit

Python exploit for CVE-2026-32201, a reflected XSS in Microsoft SharePoint Server, enabling unauthenticated spoofing and data modification via…

exploitationpenetration-testingphishing-tools+3
15 months ago
CVE-2025-59287-hawktrace preview

CVE-2025-59287-hawktrace

GitHubdaddybigfish/cve-2025-59287-hawktrace

PoC for Remote Code Execution Vulnerability in Windows Server Update Service by Microsoft CVE-2025-59287 9.8 CRITICAL

exploitationpenetration-testingremote-access-trojan+2
11 months ago
CVE-2026-62911 preview

CVE-2026-62911

GitHubhypnguyen1209/cve-2026-62911

Proof-of-concept exploit for CVE-2026-62911: pre-auth RCE on Microsoft Exchange via NTLM relay to MRSProxy, writing an ASPX webshell for SYSTEM…

exploitationpayload-developmentpenetration-testing+2
1831 month ago
CVE-2026-69836-EXP preview

CVE-2026-69836-EXP

GitHubsentinel-aidefense/cve-2026-69836-exp

CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization

cloud-securityexploitationpenetration-testing+2
11 month ago
Previous12…14Next