Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
159 results
Web-App-PenTesting preview

Web-App-PenTesting

GitHubsarthak4126/web-app-pentesting

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

educationlabs-practicepenetration-testing+4
2 days ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
3 days ago
CVE-2026-84434 preview

CVE-2026-84434

GitHubmurrez/cve-2026-84434

Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields.…

exploitationpenetration-testingreconnaissance+5
5 days ago
CVE-2026-87796 preview

CVE-2026-87796

GitHubabraxas/cve-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

educationexploitationlabs-practice+6
16 days ago
CVE-2026-88533 preview

CVE-2026-88533

GitHubhemlock-lyk/cve-2026-88533

PoC and lab reproduction for CVE-2026-88533, an unauthenticated arbitrary file write leading to root RCE in QAnything via path traversal in the…

educationexploitationlabs-practice+4
7 days ago
CVE-2026-38526-KrayinCRM preview

CVE-2026-38526-KrayinCRM

GitHubish3ng0m4/cve-2026-38526-krayincrm

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

educationexploitationpapers-research+5
8 days ago
CVE-2026-92247 preview

CVE-2026-92247

GitHubd1n3sh-0x3/cve-2026-92247

Python PoC for CVE-2026-92247, an authenticated RCE in SynaptikCMS file manager via PHP upload and rename validation bypass.

exploitationpayload-developmentpenetration-testing+3
18 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubmatakucing-ofc/cve-2026-49049

Python scanner and proof-of-concept for CVE-2026-49049, an arbitrary file write in Joomla Helix3 that enables PHP web shell upload and remote code…

exploitationpenetration-testingremote-access-tool+4
13 days ago
CVE-2026-18351 preview

CVE-2026-18351

GitHubjohenlastgen-jlg/cve-2026-18351

Mass exploit tool for CVE-2026-18351, an unauthenticated arbitrary file upload to RCE in Elementor Forms <= 1.6.0, with passive probing, shell…

exploitationpayload-developmentpenetration-testing+5
113 days ago
Exploit-CVE-2026-18351 preview

Exploit-CVE-2026-18351

GitHubchiefyoru/exploit-cve-2026-18351

Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥

exploitationpayload-developmentpenetration-testing+3
13 days ago
CVE-2020-13671 preview

CVE-2020-13671

GitHubivanesk315/cve-2020-13671

Proof-of-concept exploit for CVE-2020-13671, a Drupal file upload vulnerability enabling remote code execution via crafted filenames.

exploitationpapers-researchvulnerability-analysis+2
14 days ago
CVE-2026-81780-Hash-Form preview

CVE-2026-81780-Hash-Form

GitHub0xterror/cve-2026-81780-hash-form

Exploit for CVE-2026-81780: unauthenticated file upload in WordPress Hash Form plugin leading to remote code execution via crafted PHP payloads.

exploitationpenetration-testingvulnerability-analysis+2
17 days ago
amasty-chekout-POC-rce preview

amasty-chekout-POC-rce

GitHubchrissec2014/amasty-chekout-poc-rce

my poc for CVE-2026-53787

exploitationpenetration-testingweb-application-exploitation+1
18 days ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub4minx/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

exploitationpayload-developmentpenetration-testing+3
119 days ago
cve-2026-32475-elementor-pro-lab preview

cve-2026-32475-elementor-pro-lab

GitHubdinosn/cve-2026-32475-elementor-pro-lab

A/B Docker lab + PoC for CVE-2026-32475 (Elementor Pro Forms unauthenticated arbitrary file upload -> RCE via validation/move loop desync)

educationexploitationlabs-practice+4
819 days ago
CVE-2026-32475-PoC preview

CVE-2026-32475-PoC

GitHubboreas37/cve-2026-32475-poc

PoC for CVE-2026-32475: Elementor Pro <=4.2.1 unauthenticated file upload to RCE. Stdlib-only Python.

exploitationpayload-developmentpenetration-testing+3
51 month ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub0xblackash/cve-2026-32475

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

educationpenetration-testingvulnerability-analysis+2
1 month ago
CVE-2020-13671 preview

CVE-2020-13671

GitHubdungsocool/cve-2020-13671

Detailed analysis and proof-of-concept for CVE-2020-13671, a Drupal core remote code execution vulnerability via file upload, including root cause,…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
Previous12…9Next