Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
CVE-2025-32432-exploit-by-P34NUT preview

CVE-2025-32432-exploit-by-P34NUT

GitHubp34nut2/cve-2025-32432-exploit-by-p34nut

Reliable CVE-2025-32432 pre-auth RCE exploit for Craft CMS 3.x/4.x/5.x, works where other public PoCs fail

exploitationpayload-developmentpenetration-testing+6
2
21h 12m ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubnoname-elv/cve-2026-48907

Python CLI that exploits CVE-2026-48907 in Joomla JCE via profile-import upload, verifies shell paths, and opens an interactive command channel on…

exploitationpayload-developmentpenetration-testing+6
2 days ago
CVE-2024-2044 preview

CVE-2024-2044

GitHubhanzzly/cve-2024-2044

Python PoC exploiting CVE-2024-2044 in pgAdmin 4 (<=8.3) via authenticated path traversal and unsafe pickle deserialization to achieve remote code…

exploitationpayload-developmentpenetration-testing+5
4 days ago
CVE-2026-78006-POC preview

CVE-2026-78006-POC

GitHubdeadexpl0it/cve-2026-78006-poc

POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

defensive-toolsexploitationpayload-development+7
5 days ago
CVE-2026-21858-n8n-FullChain preview

CVE-2026-21858-n8n-FullChain

GitHubzerodayevil/cve-2026-21858-n8n-fullchain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

ai-securityexploitationpayload-development+7
5 days ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubjendmaoul/xss2shell-cve-2026-64638

CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC…

exploitationpayload-developmentpenetration-testing+4
11 month ago
weaponised-XSS-payloads preview

weaponised-XSS-payloads

GitHubhakluke/weaponised-xss-payloads

XSS payloads designed to turn alert(1) into P1

exploitationpayload-developmentpayload-generation+3
1.4k3 years ago
CVE-2026-60004 preview

CVE-2026-60004

GitHubhackspeak/cve-2026-60004

Gitea diffpatch RCE (CVE-2026-60004) PoC - repo-write to RCE as Gitea service account

exploitationpayload-developmentpenetration-testing+5
21 month ago
wp2shell preview

wp2shell

GitHubmcipekci/wp2shell

Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an…

command-and-controlexploitationpayload-development+7
151 month ago
CVE-2026-5718 preview

CVE-2026-5718

GitHubxxconi/cve-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

code-analysisexploitationpayload-development+5
3 months ago
CVE-2025-15403 preview

CVE-2025-15403

GitHubnxploited/cve-2025-15403

RegistrationMagic <= 6.0.7.1 - Unauthenticated Privilege Escalation via admin_order

exploitationpayload-developmentpenetration-testing+5
5 months ago
qu1ckdr0p2 preview

qu1ckdr0p2

GitHubbyinarie/qu1ckdr0p2

Quicky serve files over http or https using flask.

payload-developmentpayload-generationpenetration-testing+3
352 years ago
reverse-shell-generator preview

reverse-shell-generator

GitHub0dayctf/reverse-shell-generator

Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)

ctfexploitationpayload-development+6
4.1k4 months ago