Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
180 results
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
13
22 days ago
CVE-2026-76569 preview

CVE-2026-76569

GitHubtoanln-cov/cve-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

exploitationpenetration-testingvulnerability-analysis+2
24 days ago
CVE-2026-76565 preview

CVE-2026-76565

GitHubtoanln-cov/cve-2026-76565

Reflected XSS via price_from & price_to Filter Parameters in PhocaCart

exploitationpapers-researchvulnerability-analysis+2
1 month ago
DSXS preview

DSXS

GitHubstamparm/dsxs

Damn Small XSS Scanner

vulnerability-scannersweb-application-exploitationweb-security+1
4301 month ago
DSSS preview

DSSS

GitHubstamparm/dsss

Damn Small SQLi Scanner

vulnerability-scannersweb-application-exploitationweb-security
8801 month ago
CVE-2026-74251 preview

CVE-2026-74251

GitHubtoanln-cov/cve-2026-74251

Unauthenticated SQL Injection via Attribute Filter in Phoca Cart - CVSS 9.3

database-securitydata-exfiltrationexploitation+3
1 month ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
CVE-2025-68937 preview

CVE-2025-68937

GitHubscratchappy/cve-2025-68937

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

exploitationpenetration-testingprivilege-escalation+3
1 month ago
CVE-2025-64512 preview

CVE-2025-64512

GitHubstoic-crawler/cve-2025-64512

Exploit for CVE-2025-64512 to get a reverse shell.

educationexploitationpayload-development+3
2 months ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
2 months ago
CVE-2025-8110 preview

CVE-2025-8110

GitHubixzodiak/cve-2025-8110

Gogs service Exploit and get the root user

ctfeducationexploitation+4
2 months ago
tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE preview

tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE

GitHub4qu4r1um/tugtainer-1.30.2-cve-2026-55494-and-cve-2026-62308-to-rce

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

container-escapecontainer-securityeducation+5
2 months ago
CVE-2026-15282 preview

CVE-2026-15282

GitHubshinthink/cve-2026-15282

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

educationexploitationpayload-generation+5
2 months ago
wasmforge preview

wasmforge

GitHubpraetorian-inc/wasmforge

WasmForge — compile Go and C# programs to single-binary, WASM-sandboxed native executables with polymorphic output.

binary-analysiscommand-and-controlexploit-frameworks+9
1313 months ago
mvn_pwn preview

mvn_pwn

GitHubmbadanoiu/mvn_pwn

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

educationexploitationpayload-development+3
3 months ago
CVE-2026-10290-SQLI preview

CVE-2026-10290-SQLI

GitHubxmyronn/cve-2026-10290-sqli

Proof-of-concept for unauthenticated SQL injection in Hotel and Tourism Reservation System 1.0, demonstrating database extraction via the tour…

database-securityeducationexploitation+3
3 months ago
oxasploits preview

oxasploits

GitHuboxasploits/oxasploits

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

binary-exploitationbluetooth-securityexploitation+6
3 months ago
Inject-PHP-to-JPG-Using-Jhead preview

Inject-PHP-to-JPG-Using-Jhead

GitHubjenderal92/inject-php-to-jpg-using-jhead

PHP script and guide for injecting PHP webshells into JPEG images using Jhead. Used to bypass file upload filters and achieve remote command…

educationpayload-developmentsteganography+1
13 months ago
Previous12…10Next