Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
351 results
CVE-2026-89026 preview

CVE-2026-89026

GitHubaranfarzami/cve-2026-89026

PoC exploit and scanner for CVE-2026-89026, validating the Issabel PBXAPI authentication bypass via forged HS256 JWTs across single or listed targets.

authenticationexploitationpenetration-testing+5
1
6 days ago
CVE-2026-81000 preview

CVE-2026-81000

GitHubhorkimhab/cve-2026-81000

Educational CVE-2026-81000 proof-of-concept repository for authorized security research, vulnerability awareness, and controlled lab testing.

educationexploitationlabs-practice+4
6 days ago
cve-2019-15107-lab preview

cve-2019-15107-lab

GitHubshambhavim18/cve-2019-15107-lab

Docker-based lab demonstrating CVE-2019-15107, the Webmin unauthenticated RCE, covering deployment, exploitation, detection, and remediation.

container-securitydefensive-toolseducation+5
7 days ago
CVE-2026-19975 preview

CVE-2026-19975

GitHubhorkimhab/cve-2026-19975

Proof-of-concept and research repository for CVE-2026-19975 in Azuriom, with setup instructions and a linked technical writeup for authorized…

educationexploitationlabs-practice+3
10 days ago
cotonti-commentswidget-poc preview

cotonti-commentswidget-poc

GitHubharshrajsinghania/cotonti-commentswidget-poc

Safe local proof of concept for the Cotonti CommentsWidget PHP object injection vulnerability (CAN-2026-2035973 / CVE-2026-71294).

educationexploitationvulnerability-analysis+1
14 days ago
GitLabSniper preview

GitLabSniper

GitHubynsmroztas/gitlabsniper

Single-file Python scanner and exploit for CVE-2026-85706, an unauthenticated arbitrary file read in self-managed GitLab CE/EE, with project…

data-exfiltrationexploitationinformation-gathering+6
715 days ago
code-graph-rag-PoC preview

code-graph-rag-PoC

GitHubsqueeze440/code-graph-rag-poc

PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1).

educationexploitationpapers-research+3
16 days ago
CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184 preview

CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184

GitHubhorkimhab/cve-2026-13181-cve-2026-13182-cve-2026-13183-cve-2026-13184

Educational proof-of-concept for Telerik padding oracle vulnerabilities (CVE-2026-13181-184) with scripts for authorized security testing and…

curated-resourceseducationexploitation+3
20 days ago
CVE-2026-36392 preview

CVE-2026-36392

GitHubmoksh-nfsu/cve-2026-36392

Proof-of-concept for stored XSS in RISE CRM item title field (CVE-2026-36392), demonstrating session hijacking and account takeover with remediation…

exploitationpenetration-testingvulnerability-analysis+2
119 days ago
CVE-Chamilo-LMS preview

CVE-Chamilo-LMS

GitHubhorkimhab/cve-chamilo-lms

CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,…

curated-resourceseducationexploitation+3
23 days ago
NetSec-CVE-2023-4357 preview

NetSec-CVE-2023-4357

GitHubshihongsu/netsec-cve-2023-4357

Reproduces CVE-2023-4357 in Google Chrome to demonstrate XML/XSLT-based file access bypass, with analysis and proof-of-concept for educational…

educationexploitationlabs-practice+2
25 days ago
CVE-2026-27541-Analysis-Lab preview

CVE-2026-27541-Analysis-Lab

GitHubrootdirective-sec/cve-2026-27541-analysis-lab

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

educationexploitationlabs-practice+4
6 months ago
CVE-2023-27350-CVE-2023-27351 preview

CVE-2023-27350-CVE-2023-27351

GitHubhorkimhab/cve-2023-27350-cve-2023-27351

Educational proof-of-concept for PaperCut pre-auth RCE chain (CVE-2023-27350, CVE-2023-27351) with setup scripts and authorized testing guidance.

educationexploitationpenetration-testing+2
1 month ago
fastjson-cve preview

fastjson-cve

GitHubipisav/fastjson-cve

Reproduction project for CVE-2026-16723, a critical RCE in fastjson 1.2.68-1.2.83. Demonstrates AutoType bypass, JNDI injection, and TemplatesImpl…

educationexploitationpapers-research+2
1 month ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubeqstlab/cve-2026-19478

Proof-of-concept exploit for CVE-2026-19478, an unauthenticated GraphQL injection in GitLab CE/EE allowing arbitrary method invocation and project…

exploitationpenetration-testingred-teaming+3
41 month ago
CVE-2018-16763_fuel_cms_exploit preview

CVE-2018-16763_fuel_cms_exploit

GitHubgh0stuncle/cve-2018-16763_fuel_cms_exploit

A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

ctfeducationexploitation+3
1 month ago
CVE-2025-61456 preview

CVE-2025-61456

GitHubtansique-17/cve-2025-61456

Public disclosure and proof-of-concept for a reflected XSS vulnerability (CVE-2025-61456) in an e-commerce project, including technical details, CVSS…

educationexploitationpapers-research+3
11 months ago
CVE-2025-61454 preview

CVE-2025-61454

GitHubtansique-17/cve-2025-61454

Public disclosure and proof-of-concept for CVE-2025-61454, a reflected XSS vulnerability in E-commerce Project v1.0's search.php, including…

educationexploitationpapers-research+3
11 months ago
Previous12…20Next