Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
333 results
CVE-2026-104286-POC preview

CVE-2026-104286-POC

GitHubshadowforge-cyber/cve-2026-104286-poc

Unauthenticated path traversal exploit for CVE-2026-104286 in FortiMail, writing arbitrary files via crafted HTTP/HTTPS requests for red team…

exploitationpayload-developmentpenetration-testing+5
4 days ago
CVE-2026-103978 preview

CVE-2026-103978

GitHubkiwknr/cve-2026-103978

Proof-of-concept and writeup for CVE-2026-103978, an unauthenticated path traversal in OPNMGR's snyk_scan_progress.php allowing arbitrary .json file…

exploitationinformation-gatheringpenetration-testing+3
14 days ago
CVE-2026-103584 preview

CVE-2026-103584

GitHubbombobombone/cve-2026-103584

Sanitized report and loopback-only PoC script for CVE-2026-103584, a javascript: URL scheme XSS in MediaWiki CommonsMetadata LicenseUrl rendering.

exploitationpapers-researchvulnerability-analysis+2
5 days ago
CVE-2026-100520-laranode-path-traversal preview

CVE-2026-100520-laranode-path-traversal

GitHubwvllxe/cve-2026-100520-laranode-path-traversal

Path Traversal -> RCE in Laranode < 1.2.1 (CWE-22). PoC + advisory writeup.

exploitationpenetration-testingremote-access-tool+3
24 days ago
CVE-2026-12227 preview

CVE-2026-12227

GitHubbe-keb/cve-2026-12227

Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI in the WordPress Visual Composer plugin (<=45.16.0) enabling file…

exploitationinformation-gatheringpenetration-testing+5
19 days ago
CVE-2026-12227 preview

CVE-2026-12227

GitHubmrdark-ops/cve-2026-12227

Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI/RCE in the WordPress Visual Composer plugin via the vcv-template…

exploitationinformation-gatheringpenetration-testing+4
6 days ago
CVE-2026-18143 preview

CVE-2026-18143

GitHubmurrez/cve-2026-18143

Python PoC that checks and exploits CVE-2026-18143, an unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via…

exploitationpayload-developmentpenetration-testing+5
10 days ago
CVE-2026-18143 preview

CVE-2026-18143

GitHubwayang1337/cve-2026-18143

Request a Quote for WooCommerce (Addify) <= 2.9.2 Unauthenticated arbitrary file upload via afrfq_submit_quote_via_popup

exploitationvulnerability-analysisweb-application-exploitation+2
8 days ago
CVE-2026-18143 preview

CVE-2026-18143

GitHubghannyxploit404/cve-2026-18143

Python proof-of-concept exploiting CVE-2026-18143, an unauthenticated arbitrary file upload vulnerability, for security testing and validation.

exploitationpenetration-testingvulnerability-analysis+2
6 days ago
CVE-2026-27540 preview

CVE-2026-27540

GitHubwinrarzipsexploit/cve-2026-27540

Python exploit suite for CVE-2026-27540, an unauthenticated file upload RCE in the WooCommerce Wholesale Lead Capture plugin, with fingerprinting,…

exploitationpayload-generationpenetration-testing+5
19 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubeqstlab/cve-2026-85706

PoC and Docker lab for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE via the commits API route bypass and urlencoded error…

data-exfiltrationexploitationinformation-gathering+5
238 days ago
CVE-2026-48356 preview

CVE-2026-48356

GitHubabraxas/cve-2026-48356

Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.

exploitationlabs-practicepayload-generation+5
6 days ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubyym8538/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal and arbitrary file write in Langflow's /api/v2/files endpoint, with Docker lab and…

exploitationpenetration-testingremote-access-tool+3
11 month ago
CVE-2026-87902-PoC-pwnVader preview

CVE-2026-87902-PoC-pwnVader

GitHubpwnvader/cve-2026-87902-poc-pwnvader

Shell PoC for CVE-2026-87902, an unauthenticated WordPress core LFI via page-template resolution that chains to RCE through pearcmd.php.

exploitationpayload-developmentpenetration-testing+5
14 days ago
CVE-2026-12227-visualcomposer-lfi-poc preview

CVE-2026-12227-visualcomposer-lfi-poc

GitHubhassham1/cve-2026-12227-visualcomposer-lfi-poc

Docker validation lab and safe-oracle PoC for CVE-2026-12227, an unauthenticated LFI in Visual Composer via vcv-template, with a nuclei detection…

exploitationlabs-practicepenetration-testing+5
112 days ago
CVE-2026-12227 preview

CVE-2026-12227

GitHubmurrez/cve-2026-12227

Python 3 PoC and scanner for CVE-2026-12227, an unauthenticated local file inclusion in WordPress Visual Composer Website Builder via the…

exploitationinformation-gatheringpenetration-testing+5
12 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubbhideki/cve-2026-87902

Python PoC and scanner for CVE-2026-87902, a WordPress core path traversal leading to LFI and PEAR-based RCE, with WAF bypass and automated…

exploitationpayload-developmentpenetration-testing+6
13 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
12 days ago
Previous12…19Next