Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5042 results
CVE-2025-55182-React-RSC-Exploit preview

CVE-2025-55182-React-RSC-Exploit

GitHublutraat/cve-2025-55182-react-rsc-exploit

Basic Proof of Concept (Poc) Exploit for React RSC - CVE-2025-55182

educationexploitationpayload-development+3
5 months ago
CVE-2026-3854 preview

CVE-2026-3854

GitHub5kr1pt/cve-2026-3854

Technical breakdown of CVE-2026-3854, a GitHub RCE via header injection in git push, explaining the vulnerability, exploitation technique, and…

educationexploitationpapers-research+2
4 months ago
CVE-2026-7028-SQLI preview

CVE-2026-7028-SQLI

GitHubxmyronn/cve-2026-7028-sqli

Proof-of-concept exploit for SQL injection in CodeAstro Online Job Portal allowing authenticated deletion of all job records via crafted GET request.

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
CVE-2025-11973 preview

CVE-2025-11973

GitHubjfriedli/cve-2025-11973

Proof-of-concept exploit for CVE-2025-11973 demonstrating local file inclusion (LFI) in WordPress via file:// protocol, with automated exfiltration…

data-exfiltrationexploitationinformation-gathering+2
5 months ago
CVE-2026-24417 preview

CVE-2026-24417

GitHublukasz-rybak/cve-2026-24417

CVE-2026-24417 - OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service

database-securityeducationexploitation+3
4 months ago
Binary-Exploitation-and-Kernel-Escalation preview

Binary-Exploitation-and-Kernel-Escalation

GitHubanilkashyap01/binary-exploitation-and-kernel-escalation

Secured root-level access by identifying and exploiting misconfigurations and outdated software. Buffer overflow vulnerability in an outdated version…

binary-exploitationeducationexploitation+7
4 months ago
CVE-2026-6356 preview

CVE-2026-6356

GitHubpenguinsecq/cve-2026-6356

Exploit PoC of CVE-2026-6356

educationexploitationpenetration-testing+3
4 months ago
CVE-2025-7847-POC preview

CVE-2025-7847-POC

GitHubericardiansa/cve-2025-7847-poc

Wordpress Plugin AI Engine 2.9.3 - 2.9.4 Proof Of Concept

exploitationpayload-generationpenetration-testing+3
11 year ago
poc-CVE-2021-44521 preview

poc-CVE-2021-44521

GitHubyeyvo/poc-cve-2021-44521

full PoC of CVE-2021-44521

binary-exploitationexploitationpenetration-testing+2
13 years ago
CVE-2025-3102-exploit preview

CVE-2025-3102-exploit

GitHubsupraaa-1337/cve-2025-3102-exploit

Exploitation of an authorization bypass vulnerability in the SureTriggers plugin for WordPress versions <= 1.0.78, allowing unauthenticated attackers…

authentication-authorizationexploitationpenetration-testing+2
11 year ago
CVE-2026-10243-AUTH preview

CVE-2026-10243-AUTH

GitHubxmyronn/cve-2026-10243-auth

Proof of concept demonstrating unauthenticated access to critical admin functions in Smart Parking System 1.0, allowing account creation, data…

authenticationexploitationpenetration-testing+2
4 months ago
CVE-2025-25279-Mattermost-Path-Traversal preview

CVE-2025-25279-Mattermost-Path-Traversal

GitHubabokormahammadmousse/cve-2025-25279-mattermost-path-traversal

Proof-of-concept exploit for CVE-2025-25279, a Mattermost Focalboard path traversal enabling authenticated arbitrary file read and exfiltration of…

educationexploitationlabs-practice+3
4 months ago
CVE-2026-21710 preview

CVE-2026-21710

GitHubopen-flaw/cve-2026-21710

Proof-of-concept exploit for CVE-2026-21710, a Node.js HTTP request handling flaw causing uncaught TypeError via __proto__ header, leading to denial…

exploitationvulnerability-analysisweb-application-exploitation
5 months ago
CVE-2026-23744-POC preview

CVE-2026-23744-POC

GitHubfcjaviergarcia/cve-2026-23744-poc

Proof of Concept (PoC) exploit for CVE-2026-23744, a vulnerability affecting MCPJam Inspector that allows remote command execution (RCE) through…

exploitationpenetration-testingremote-access-tool+2
5 months ago
CVE-2025-69216 preview

CVE-2025-69216

GitHublukasz-rybak/cve-2025-69216

Proof-of-concept repository for CVE-2025-69216, an authenticated SQL injection in OpenSTAManager's Scadenzario print template, enabling extraction of…

database-securityeducationexploitation+3
4 months ago
CVE-2026-23744-POC preview

CVE-2026-23744-POC

GitHubsbouabid-sec/cve-2026-23744-poc

CVE-2026-23744 — Proof of concept exploit for an unauthenticated Remote Code Execution vulnerability in MCPJam Inspector <= 1.4.2.

exploitationpayload-generationpenetration-testing+3
3 months ago
CVE-2021-41773-PoC preview

CVE-2021-41773-PoC

GitHuba24ac1/cve-2021-41773-poc

「🪶」PoC (Proof of concept) of Path traversal + RCE in Apache HTTP Server 2.4.49

educationexploitationpenetration-testing+2
3 months ago
CVE-2018-7600 preview

CVE-2018-7600

GitHub0xaj2k/cve-2018-7600

Drupal 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting…

exploitationpenetration-testingremote-access-tool+2
15 years ago
Previous1…939495…100Next