Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
317 results
CVE-2026-57827 preview

CVE-2026-57827

GitHubcandisexterior171/cve-2026-57827

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

exploitationpenetration-testingreconnaissance+2
1 day ago
openfire-ssrf-cve-2019-18394 preview

openfire-ssrf-cve-2019-18394

GitHubl0lsec/openfire-ssrf-cve-2019-18394

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

exploitationpenetration-testingreconnaissance+4
4 days ago
CVE-2026-8732-PoC preview

CVE-2026-8732-PoC

GitHubfientix/cve-2026-8732-poc

CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation

exploitationpenetration-testingreconnaissance+3
5 days ago
tfo-connect-bypass preview

tfo-connect-bypass

GitHub4n4s4zi/tfo-connect-bypass

Using TCP Fast Open to bypass syscall-based networking rules (CVE-2026-63828/CVE-2026-72243 PoC)

exploitationids-ips-evasionnetwork-security+3
6 days ago
CVE-2026-34160 preview

CVE-2026-34160

GitHubromain-deperne/cve-2026-34160

Unauthenticated SSRF in the Chamilo LMS PENS plugin — CVE-2026-34160 / CVSS 8.6

exploitationpenetration-testingreconnaissance+3
6 days ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

exploitationphishingreconnaissance+2
6 days ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubghxstsec/cve-2026-39987

Exploit for Marimo pre-auth RCE via terminal WebSocket, providing command execution, interactive PTY shell, and reverse shell capabilities for…

exploitationpenetration-testingreconnaissance+3
112 days ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubmaxprog-svg/cve-2026-33017

CVE-2025-62593 — Ray Unauthenticated RCE Exploit is an unauthenticated remote code execution vulnerability in the Ray distributed AI compute engine.

command-and-controlexploitationreconnaissance+3
12 days ago
RCE-CVE-2026-10520-CVE-2026-10523 preview

RCE-CVE-2026-10520-CVE-2026-10523

GitHubimbas007/rce-cve-2026-10520-cve-2026-10523

Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

exploitationpenetration-testingreconnaissance+3
20 days ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubmr-leonardogomes/xss2shell-cve-2026-64638

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

exploitationpenetration-testingreconnaissance+3
11 month ago
CVE-2026-60004-poc-gitea preview

CVE-2026-60004-poc-gitea

GitHubgagaltotal/cve-2026-60004-poc-gitea

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

exploitationpenetration-testingreconnaissance+3
21 month ago
wp2shell-rce preview

wp2shell-rce

GitHubjohnlodan/wp2shell-rce

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

penetration-testingreconnaissancevulnerability-analysis+4
31 month ago
CVE-2026-66066 preview

CVE-2026-66066

GitHubshinthink/cve-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

exploitationpenetration-testingreconnaissance+3
11 month ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
CVE-2021-22986_Check preview
Archived

CVE-2021-22986_Check

GitHubzephrfish/cve-2021-22986_check

CVE-2021-22986 Checker Script in Python3

exploitationpenetration-testingreconnaissance+2
31 month ago
CVE-2021-41773-PoC preview

CVE-2021-41773-PoC

GitHubzephrfish/cve-2021-41773-poc

Proof-of-concept scanner that checks hosts for CVE-2021-41773 Apache path traversal vulnerability, reporting vulnerable or not vulnerable status.

exploitationpenetration-testingreconnaissance+2
171 month ago
CVE-2026-49492-PoC preview

CVE-2026-49492-PoC

GitHubbyte16384/cve-2026-49492-poc

Proof-of-concept exploit for CVE-2026-49492, demonstrating the vulnerability and providing a working exploit for security testing and validation.

exploitationpenetration-testingreconnaissance+2
1 month ago
CVE-2026-48205 preview

CVE-2026-48205

GitHuboscerd/cve-2026-48205

Reproducer for CVE-2026-48205: Apache Camel camel-dns dns.* header injection redirecting DNS queries to an attacker-controlled resolver (SSRF via…

dns-analysisexploitationreconnaissance+2
11 month ago
Previous12…18Next