Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13165 results
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityiot-securityexploitation+5
1
9 days ago
CVE-2024-52806-PoC preview

CVE-2024-52806-PoC

GitHubheartlesseorg-dot/cve-2024-52806-poc
vulnerability-analysisexploitationweb-application-exploitation+2
9 days ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubl0ggg/cve-2026-55040

Exploit code for CVE-2026-55040, it can create auth header for any validate account.

exploitationweb-application-exploitationweb-security+2
224 days ago
CVE-2025-64512 preview

CVE-2025-64512

GitHubdodgenefoli/cve-2025-64512
vulnerability-analysisexploitationweb-application-exploitation+2
9 days ago
CVE-2025-55182-Exploit preview

CVE-2025-55182-Exploit

GitHubdotnetguard/cve-2025-55182-exploit

CVE-2025-55182 — Next.js Flight Deserialization RCE exploit with interactive shell, single-command execution and multi-payload reverse shell chain.…

exploitationweb-application-exploitationweb-security+3
9 days ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951
vulnerability-scannersvulnerability-analysisexploitation+3
9 days ago
CVE-2025-5781 preview

CVE-2025-5781

GitHubjasonbernier/cve-2025-5781

Proof-of-concept exploit for CVE-2025-57819 in FreePBX: SQL injection in the AJAX API to execute arbitrary PHP, create a persistent webshell, and…

persistence-mechanismsexploitationweb-application-exploitation+3
9 days ago
1day-archive preview

1day-archive

GitHub1dayexploit/1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

vulnerability-analysisexploitationreverse-engineering+5
294 days ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationreconnaissanceexploitation+4
5210 days ago
CVE-2026-48710 preview

CVE-2026-48710

GitHubcuteecat/cve-2026-48710

CVE-2026-48710漏洞验证代码

authentication-authorizationvulnerability-analysisweb-application-exploitation+1
10 days ago
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal preview

two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

GitHubhunt-benito/two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

android-securityvulnerability-analysisexploitation+4
10 days ago
CVE-2023-48084-Revised preview

CVE-2023-48084-Revised

GitHubmetthk/cve-2023-48084-revised
vulnerability-analysisexploitationweb-application-exploitation+4
10 days ago
CVE-2026-44401 preview

CVE-2026-44401

GitHubsn0x-sharma/cve-2026-44401

Persistent XSS in Typemill CMS: the Markdown parser lets javascript: URIs through unfiltered. Writeup + PoC.

vulnerability-analysisexploitationweb-application-exploitation+3
10 days ago
CVE-2022-35914-RCE preview

CVE-2022-35914-RCE

GitHubcyb3rk0ala/cve-2022-35914-rce

PoC exploit for CVE-2022-35914 — GLPI v.10.0.2 htmLawed command injection, command execution, and reverse shell support.

exploitationweb-application-exploitationpenetration-testing+1
9 days ago
CVE-2026-9198 preview

CVE-2026-9198

GitHubcuteecat/cve-2026-9198

CVE-2026-9198利用代码

vulnerability-analysisexploitationweb-application-exploitation+3
10 days ago
CVE-2026-23744-PoC preview

CVE-2026-23744-PoC

GitHubmluex0/cve-2026-23744-poc

CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted…

vulnerability-analysisexploitationweb-application-exploitation+1
210 days ago
CVE-2025-2945 preview

CVE-2025-2945

GitHubg0d150ne/cve-2025-2945

Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

payload-generationvulnerability-analysisexploitation+3
10 days ago
WP2Shell preview

WP2Shell

GitHubg0d150ne/wp2shell

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

penetration-testing-frameworksreconnaissancevulnerability-scanners+7
10 days ago
Previous1…8910…732Next