Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2812 results
CVE-2026-49048-JoomCCK-SQLi preview

CVE-2026-49048-JoomCCK-SQLi

GitHubkara-git/cve-2026-49048-joomcck-sqli

CVE-2026-49048 — JoomCCK 6.4.0 Unauthenticated SQL Injection (CVSS 9.8)

database-securityexploitationpenetration-testing+3
1
2 months ago
CVE-2026-69084-PoC preview

CVE-2026-69084-PoC

GitHubboreas37/cve-2026-69084-poc

CVE-2026-69084/69085 — SiYuan arbitrary SQL execution via searchEmbedBlock + searchDocs SQLi (CVSS 9.9). Verified on v3.7.2, rejected on v3.7.3.

database-securityexploitationpenetration-testing+3
11 month ago
CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules preview

CVE-2026-33057---Mesop-Unauthenticated-RCE-PoC-and-yara-rules

GitHubhackpatato/cve-2026-33057---mesop-unauthenticated-rce-poc-and-yara-rules

Proof-of-concept exploit for CVE-2026-33057, an unauthenticated RCE in Mesop, with accompanying YARA rules for detection.

exploitationmalware-analysisvulnerability-analysis+1
11 month ago
CVE-2026-14282 preview

CVE-2026-14282

GitHubnullwhisper/cve-2026-14282

GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)

exploitationlabs-practicepenetration-testing+3
11 month ago
CVE-2026-19500-poc preview

CVE-2026-19500-poc

GitHubtypedefabcd1234ntd/cve-2026-19500-poc

Proof-of-concept for CVE-2026-19500, a DoS vulnerability in the SureForms WordPress plugin that exhausts server resources via oversized key-value…

exploitationvulnerability-analysisweb-application-exploitation+1
11 month ago
CVE-2026-64638 preview

CVE-2026-64638

GitHub4minx/cve-2026-64638

CVE-2026-64638 (XSS2shell) POC.

exploitationpayload-developmentpenetration-testing+3
12 months ago
CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework preview

CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework

GitHubcerberusmrxi/cve-2026-44680-mikroorm-sql-injection-exploit-framework

PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features…

code-analysisdatabase-securityexploitation+3
12 months ago
CVE-2026-65650 preview

CVE-2026-65650

GitHubswornim619/cve-2026-65650

PoC for CVE-2026-65650 - Elgg avatar upload DoS

exploitationpenetration-testingvulnerability-analysis+2
12 months ago
CVE-2026-26980 preview

CVE-2026-26980

GitHubyym8538/cve-2026-26980

Python PoC and Docker lab demonstrating unauthenticated SQL injection in TryGhost Ghost CMS Content API slug filter, extracting database values via a…

database-securityeducationexploitation+5
11 month ago
XSS-CVE-2022-30489 preview

XSS-CVE-2022-30489

GitHubbadboycxcc/xss-cve-2022-30489

Proof-of-concept exploit for CVE-2022-30489, a stored XSS vulnerability in WAVLINK WN535G3 routers, demonstrating a POST-based attack via the…

exploitationiot-securitypenetration-testing+3
24 years ago
rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android preview

rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android

GitHubhunt-benito/rendering-code-outside-the-sandbox-cve-2026-76036-dawn-webgpu-buffer-overflow-in-chrome-on-android

Differential detection harness for CVE-2026-76036, a Dawn WebGPU heap buffer overflow in Chrome on Android. Probes vulnerable depth/stencil texture…

android-securitybinary-analysisdefensive-tools+3
11 month ago
By-Poloss..-..CVE-2026-15038-POC preview

By-Poloss..-..CVE-2026-15038-POC

GitHubpolosss/by-poloss..-..cve-2026-15038-poc

POC 4 CVE-2026-15038

authenticationexploitationpenetration-testing+3
12 months ago
CVE-2026-73034-PoC preview

CVE-2026-73034-PoC

GitHubboreas37/cve-2026-73034-poc

CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

exploitationpayload-developmentpenetration-testing+3
11 month ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubyym8538/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal and arbitrary file write in Langflow's /api/v2/files endpoint, with Docker lab and…

exploitationpenetration-testingremote-access-tool+3
11 month ago
cve-2026-22874-gitea-ssrf-allowlist preview

cve-2026-22874-gitea-ssrf-allowlist

GitHubm8seven/cve-2026-22874-gitea-ssrf-allowlist

CVE-2026-22874 writeup: incomplete SSRF allow-list in Gitea webhook/migration (IPv6 transition and cloud metadata). Fixed in Gitea 1.26.3.

cloud-securitycurated-resourceseducation+3
23 months ago
CVE-2026-2796-and-CVE-2026-2768-escape-the-wasm-box preview

CVE-2026-2796-and-CVE-2026-2768-escape-the-wasm-box

GitHubsneakynachos/cve-2026-2796-and-cve-2026-2768-escape-the-wasm-box

Full Firefox chain: CVE-2026-2796 wasm type confusion -> content-process RCE, plus CVE-2026-2768 parent-process escape analysis (both fixed in…

binary-exploitationexploitationvulnerability-analysis+1
11 month ago
Wordpress_cve-2019-9787_defense preview

Wordpress_cve-2019-9787_defense

GitHubsijiahi/wordpress_cve-2019-9787_defense

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

exploitationpenetration-testingvulnerability-analysis+2
35 years ago
vulhub-apache preview

vulhub-apache

GitHubninthsgrsj-source/vulhub-apache

cve-2021-41773

exploitationpenetration-testingvulnerability-analysis+2
3 months ago
Previous1…99100Next