Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1681 results
ChamiloLMS-CVE-2023-4220 preview

ChamiloLMS-CVE-2023-4220

GitHubspeatx/chamilolms-cve-2023-4220

CVE-2023-4220 — Unauthenticated file upload RCE in Chamilo LMS ≤ 1.11.24. OSCP-style and auto exploit.

ctfeducationexploitation+5
3 months ago
CVE-2024-8949-POC preview

CVE-2024-8949-POC

GitHubgh-ost00/cve-2024-8949-poc

SourceCodester Online Eyewear Shop Remote File Inclusion Vulnerability

information-gatheringpenetration-testingvulnerability-analysis+2
21 year ago
CVE-2026-13001 preview

CVE-2026-13001

GitHubshinthink/cve-2026-13001

Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8

educationexploitationpayload-development+3
1 month ago
CVE-2025-52078 preview

CVE-2025-52078

GitHubyucaerin/cve-2025-52078

CVE-2025-52078 - Unauthenticated Arbitrary File Upload - Writebot SaaS React Template

educationexploitationpayload-generation+3
11 year ago
Jenkins-CVE-2024-23897-Lab preview

Jenkins-CVE-2024-23897-Lab

GitHubfineken/jenkins-cve-2024-23897-lab

Docker-based lab environment for practicing CVE-2024-23897 Jenkins arbitrary file read exploitation with automated and manual attack scripts.

educationexploitationlabs-practice+3
21 year ago
CVE-2022-46364---Apache-CXF-XOP-Include-LFI-PoC preview

CVE-2022-46364---Apache-CXF-XOP-Include-LFI-PoC

GitHubshashivanth009/cve-2022-46364---apache-cxf-xop-include-lfi-poc

Proof-of-concept exploit for CVE-2022-46364, a local file inclusion vulnerability in Apache CXF via crafted XOP Include elements in SOAP requests,…

ctfeducationexploitation+3
15 months ago
CVE-2026-24135 preview

CVE-2026-24135

GitHubreschjonas/cve-2026-24135

Arbitrary File Deletion in Gogs via Wiki Path Traversal

educationexploitationinformation-gathering+3
13 months ago
CrushFTP-CVE-2024-4040-Proof-of-Concept preview

CrushFTP-CVE-2024-4040-Proof-of-Concept

GitHubsidjaz/crushftp-cve-2024-4040-proof-of-concept

Proof-of-concept exploit for CVE-2024-4040, demonstrating unauthenticated SSTI and local file read in CrushFTP, with Docker lab and mitigation…

educationexploitationlabs-practice+3
3 months ago
CVE-2024-5932 preview

CVE-2024-5932

GitHubnishant-kumar-5173/cve-2024-5932

Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code…

code-analysiseducationexploitation+5
3 months ago
CVE-2026-2942 preview

CVE-2026-2942

GitHubxxconi/cve-2026-2942

Automated scanner for unauthenticated arbitrary file upload and remote code execution in ProSolution WP Client (CVE-2026-2942). Supports…

educationexploitationpayload-development+3
3 months ago
CVE-2025-60655 preview

CVE-2025-60655

GitHubdotadrien/cve-2025-60655

Proof-of-concept for CVE-2025-60655: Remote Code Execution via unrestricted file upload bypassing client-side JavaScript validation, enabling…

code-analysiseducationexploitation+3
5 months ago
POC_CVE-2024-36420 preview

POC_CVE-2024-36420

GitHubfineman999/poc_cve-2024-36420

Local reproduction lab and Nuclei template for CVE-2024-36420, an arbitrary file read vulnerability in Flowise via unsanitized fileName parameter.…

educationexploitationfuzzing+3
3 months ago
CVE-2026-6009 preview

CVE-2026-6009

GitHubpumila03/cve-2026-6009

Automated PoC exploit for CVE-2026-6009, a Java deserialization RCE in Jaspersoft Reports <=7.0.3. Generates malicious .jasper payloads via ysoserial…

educationexploitationpayload-generation+4
3 months ago
CVE-2026-5718-Lab preview

CVE-2026-5718-Lab

GitHubrootdirective-sec/cve-2026-5718-lab

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

ctfeducationexploitation+3
13 months ago
CVE-2026-36227 preview

CVE-2026-36227

GitHubnullbyte8080/cve-2026-36227

Benign proof-of-concept for CVE-2026-36227, a path traversal vulnerability in Easy Chat Server 3.1 user registration. Demonstrates unauthorized file…

educationexploitationlabs-practice+3
3 months ago
wordpress-rce-vapt-cve-2020-25213 preview

wordpress-rce-vapt-cve-2020-25213

GitHubcmadhushanka/wordpress-rce-vapt-cve-2020-25213

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

educationexploitationlabs-practice+6
3 months ago
Penetration-Test preview

Penetration-Test

GitHubjeevananand1202/penetration-test

Full penetration test report against `IP` (Ubuntu VM). Attack chain: directory enumeration → backup file discovery → password cracking → CMS file…

educationexploitationpassword-cracking+6
5 months ago
CVE-2026-27621 preview

CVE-2026-27621

GitHublukasz-rybak/cve-2026-27621

CVE-2026-27621 - TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload

educationpapers-researchvulnerability-analysis+2
4 months ago
Previous1…858687…94Next