Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1680 results
CVE-2026-1357 preview

CVE-2026-1357

GitHubsahmsec/cve-2026-1357

Proof-of-concept exploit for CVE-2026-1357, an unauthenticated arbitrary file upload in WPvivid Backup & Migration leading to remote code execution.…

educationexploitationpenetration-testing+3
16h 9m ago
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write preview

CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

GitHubbiitts/cve-2026-82286-gpt-crawler-arbitrary-file-write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

educationexploitationlabs-practice+3
1 day ago
beef preview

beef

GitHubbeefproject/beef

The Browser Exploitation Framework Project

command-and-controlexploitationexploit-frameworks+8
11.0k1 day ago
CVE-2026-23751-poc preview

CVE-2026-23751-poc

GitHubsiebrum/cve-2026-23751-poc

Patched RemotingClient to exploit CVE-2026-23751 (Tungsten Automation - Kofax Capture Unauthenticated File Read/Write and SMB coercion via .NET HTTP…

exploitationpenetration-testingred-teaming+2
1 day ago
CVE-2025-10952-ml-logger-AFR preview

CVE-2025-10952-ml-logger-AFR

GitHubkhashayarnzk/cve-2025-10952-ml-logger-afr

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

exploitationinformation-gatheringpenetration-testing+2
2 days ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubmachiavelliii/cve-2024-23897

Unauthenticated arbitrary file read exploit for Jenkins CVE-2024-23897, with HTTPS and CSRF-crumb support to bypass hardened instances.

exploitationinformation-gatheringpenetration-testing+2
2 days ago
CVE-2025-55182-shellinteractive preview

CVE-2025-55182-shellinteractive

GitHubalyaapm/cve-2025-55182-shellinteractive

Interactive shell for exploiting CVE-2025-55182 in React Server Components, enabling remote command execution, file transfer, and vulnerability…

command-and-controlexploitationpayload-generation+4
2 days ago
CVE-2026-32475 preview

CVE-2026-32475

GitHubsahmsec/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

educationexploitationpenetration-testing+3
2 days ago
htb-labs-connected preview

htb-labs-connected

GitHubdiegorivas1/htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

ctfeducationexploitation+7
2 days ago
By-Poloss..-..CVE-2026-18080 preview

By-Poloss..-..CVE-2026-18080

GitHubpolosss/by-poloss..-..cve-2026-18080

Exploit for CVE-2026-18080, an unauthenticated arbitrary file upload leading to RCE in ERP Complete HR, Accounting & CRM Suite. Includes Python and…

exploitationpayload-developmentpenetration-testing+3
3 days ago
hiphp preview

hiphp

GitHubyasserbdj96/hiphp

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

command-and-controlpayload-generationremote-access-tool+1
2193 days ago
CVE-2026-19912-CVE-2026-19913-CVE-2026-19914 preview

CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

GitHubhorkimhab/cve-2026-19912-cve-2026-19913-cve-2026-19914

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

educationexploitationpenetration-testing+3
3 days ago
CVE-2026-56705 preview

CVE-2026-56705

GitHubboreas37/cve-2026-56705

PoC exploit for Adminer < 5.4.3 unauthenticated RCE via MSSQL PDO DSN injection, including Docker lab and negative test.

educationexploitationlabs-practice+4
24 days ago
OpenSTA-Exploit preview

OpenSTA-Exploit

GitHublolw0/opensta-exploit

Proof of Concept (PoC) of CVE-2025-69212 related with P7M File Processing

exploitationpayload-generationpenetration-testing+2
4 days ago
CVE-2026-32475-PoC preview

CVE-2026-32475-PoC

GitHubboreas37/cve-2026-32475-poc

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

exploitationpayload-developmentpenetration-testing+3
15 days ago
CVE-2026-41551 preview

CVE-2026-41551

GitHubselecthch/cve-2026-41551

Proof-of-concept exploit for CVE-2026-41551, a path traversal vulnerability in Siemens ROS# file_server, demonstrating remote file read via crafted…

exploitationinformation-gatheringpenetration-testing+3
15 days ago
cve-2026-64638-banner-poc preview

cve-2026-64638-banner-poc

GitHubxal6/cve-2026-64638-banner-poc

Generates a self-submitting HTML trigger page that exploits a reflected HTML injection in WordPress login (CVE-2026-64638) to display a custom…

exploitationpenetration-testingred-teaming+3
5 days ago
CVE-2026-60093 preview

CVE-2026-60093

GitHuboscerd/cve-2026-60093

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-60093) in camel-azure-storage-datalake, demonstrating arbitrary…

educationexploitationpapers-research+2
5 days ago
Previous12…94Next