Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1681 results
CVE-2025-1307 preview

CVE-2025-1307

GitHubnxploited/cve-2025-1307

Newscrunch <= 1.8.4 - Authenticated (Subscriber+) Arbitrary File Upload

educationexploitationpayload-development+3
2
1 year ago
CVE-2026-48282-coldfusion-rds-detection preview

CVE-2026-48282-coldfusion-rds-detection

GitHubg0thamrabb1t/cve-2026-48282-coldfusion-rds-detection

Laboratory validation of CVE-2026-48282 in Adobe ColdFusion RDS with arbitrary CFM file write, code execution, auditd/PCAP evidence, event timeline…

educationexploitationforensics+5
1 month ago
Popcorn-TJNULL-OSCP- preview

Popcorn-TJNULL-OSCP-

GitHubr3fr4kt/popcorn-tjnull-oscp-

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

ctfeducationexploitation+7
2 months ago
CVE-2026-65694-PoC preview

CVE-2026-65694-PoC

GitHubabdugafforov-bobur/cve-2026-65694-poc

PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

educationexploitationinformation-gathering+3
11 month ago
CVE-2025-34085 preview

CVE-2025-34085

GitHub0xgh057r3c0n/cve-2025-34085

WordPress Simple File List Unauthenticated RCE Exploit

educationexploitationpayload-generation+3
21 year ago
CVE-2025-2539 preview

CVE-2025-2539

GitHubrootharpy/cve-2025-2539

Unauthenticated Arbitrary File Read exploit for WordPress File Away Plugin ≤ 3.9.9.0.1

educationexploitationinformation-gathering+3
21 year ago
CVE-2025-47423 preview

CVE-2025-47423

GitHubhaluka92/cve-2025-47423

Detailed disclosure of CVE-2025-47423: Local File Inclusion in Personal Weather Station Dashboard 12_lts. Includes PoC, vulnerable code analysis, and…

curated-resourceseducationexploitation+3
16 days ago
CVE-2026-55579 preview

CVE-2026-55579

GitHubch4120n/cve-2026-55579

CVE-2026-55579 – Unauthenticated RCE in Pheditor via hardcoded default password "admin". Full Python exploit with file upload & terminal execution.…

educationexploitationlabs-practice+6
11 month ago
By-Poloss..-..CVE-2026-7515-PoC preview

By-Poloss..-..CVE-2026-7515-PoC

GitHubpolosss/by-poloss..-..cve-2026-7515-poc

Unauthenticated Local File Inclusion

code-analysiseducationexploitation+3
12 months ago
CVE-2024-49668 preview

CVE-2024-49668

GitHubnxploited/cve-2024-49668

WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability

educationexploitationpayload-generation+3
21 year ago
CVE-2024-7703 preview

CVE-2024-7703

GitHublfillaz/cve-2024-7703

Proof-of-concept exploit for CVE-2024-7703, a Stored XSS vulnerability in the ARMember WordPress plugin via malicious SVG file uploads by…

educationexploitationpayload-generation+3
22 years ago
CVE-2024-51788 preview

CVE-2024-51788

GitHubnxploited/cve-2024-51788

CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vulnerability

educationexploitationpayload-generation+3
21 year ago
duplicate-CVE-2025-4720- preview

duplicate-CVE-2025-4720-

GitHubxmyronn/duplicate-cve-2025-4720-

Proof-of-concept exploit for CVE-2025-4720, a path traversal vulnerability in SourceCodester SRMS 1.0 allowing arbitrary file deletion via the…

educationexploitationpenetration-testing+2
4 months ago
CVE-2025-25279-Mattermost-Path-Traversal preview

CVE-2025-25279-Mattermost-Path-Traversal

GitHubabokormahammadmousse/cve-2025-25279-mattermost-path-traversal

Proof-of-concept exploit for CVE-2025-25279, a Mattermost Focalboard path traversal enabling authenticated arbitrary file read and exfiltration of…

educationexploitationlabs-practice+3
4 months ago
CVE-2021-29447-PoC preview

CVE-2021-29447-PoC

GitHubrdana55/cve-2021-29447-poc

Proof-of-concept exploit for CVE-2021-29447, an XXE injection vulnerability in WordPress 5.6–5.7 via malicious WAV file upload, enabling arbitrary…

educationexploitationpenetration-testing+3
3 months ago
CVE-2025-34096 preview

CVE-2025-34096

GitHubthemalwareguardian/cve-2025-34096

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

binary-exploitationeducationexploitation+6
5 months ago
cve-2022-23636-poc preview

cve-2022-23636-poc

GitHubcyhe50/cve-2022-23636-poc

Authenticated remote code execution exploit for m1k1o's Blog v1.3 via unvalidated file upload, with webshell deployment and reverse shell…

educationexploitationpayload-generation+3
4 months ago
Ghostcat-Tomcat-AJP-Exploit-Py3 preview

Ghostcat-Tomcat-AJP-Exploit-Py3

GitHubsi1ence90/ghostcat-tomcat-ajp-exploit-py3

A fully refactored, Python 3 compatible exploit script for Tomcat Ghostcat (CVE-2020-1938 / CNVD-2020-10487) AJP Local File Inclusion

educationexploitationinformation-gathering+3
3 months ago
Previous1…848586…94Next