Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
82 results
CVE-2026-70376 preview

CVE-2026-70376

GitHubilhomjonr/cve-2026-70376

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

educationexploitationpenetration-testing+3
1 month ago
CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille- preview

CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-

GitHubtheopaid/cve-2026-66754-remote-denial-of-service-via-reachable-assertion-in-url-prefix-handling-rouille-

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

educationpapers-researchvulnerability-analysis+1
2 months ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub0xblackash/cve-2026-32475

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

educationpenetration-testingvulnerability-analysis+2
1 month ago
CVE-2026-25632 preview

CVE-2026-25632

GitHublazarus0x1337/cve-2026-25632

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

code-analysiseducationexploitation+4
12 months ago
CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution preview

CVE-2026-3844-Breeze-Cache-WordPress-Plugin-Remote-Code-Execution

GitHubdhananjayasj/cve-2026-3844-breeze-cache-wordpress-plugin-remote-code-execution

Docker lab and manual exploitation guide for CVE-2026-3844, a critical unauthenticated arbitrary file upload vulnerability in the Breeze Cache…

educationexploitationlabs-practice+3
3 months ago
CVE-2017-11499 preview

CVE-2017-11499

GitHubopen-flaw/cve-2017-11499

Documentation of CVE-2017-11499: a hash flooding remote DoS vulnerability in Node.js caused by constant HashTable seeds, with analysis of the attack…

educationpapers-researchvulnerability-analysis+1
5 months ago
CVE-2026-31283 preview

CVE-2026-31283

GitHubsaykino/cve-2026-31283

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

api-securityeducationemail-security+3
5 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubazilrababe/cve-2026-42945

Technical analysis of CVE-2026-42945 (NGINX Rift), a critical heap buffer overflow in NGINX's rewrite engine caused by a state mismatch between…

binary-exploitationeducationexploitation+2
13 months ago
CVE-2008-1930 preview

CVE-2008-1930

GitHubheisenbergh4x/cve-2008-1930

CVE-2008-1930 is a critical improper authentication vulnerability affecting the core cookie integrity mechanism in WordPress version 2.5. It allows…

educationexploitationinformation-gathering+5
3 months ago
Ashwesker-CVE-2026-21440 preview

Ashwesker-CVE-2026-21440

GitHubredpack-kr/ashwesker-cve-2026-21440

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…

educationexploitationpenetration-testing+3
8 months ago
CVE-2024-10124-Poc preview

CVE-2024-10124-Poc

GitHubnxploited/cve-2024-10124-poc

Proof-of-concept exploit for CVE-2024-10124 in WordPress Vayu Blocks plugin, allowing unauthorized plugin installation and activation to potentially…

educationexploitationpenetration-testing+3
11 year ago
CVE-2025-49113_exploit_cookies preview

CVE-2025-49113_exploit_cookies

GitHubl4f2s4/cve-2025-49113_exploit_cookies

Authenticated remote code execution exploit for Roundcube Webmail (CVE-2025-49113) via insecure deserialization. Includes session injection, gadget…

code-analysiseducationexploitation+5
11 year ago
Fortinet-FortiWeb-Fabric-Connector-CVE-2025-25257-Detection preview

Fortinet-FortiWeb-Fabric-Connector-CVE-2025-25257-Detection

GitHubgarethmsheldon/fortinet-fortiweb-fabric-connector-cve-2025-25257-detection

This repository provides production-ready detection engineering content for **CVE-2025-25257**, a pre-authentication SQL Injection vulnerability in…

educationexploitationforensics+8
6 months ago
Open-Worldwide-Application-Security-Project-OWASP- preview

Open-Worldwide-Application-Security-Project-OWASP-

GitHubwaburig/open-worldwide-application-security-project-owasp-

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

educationpenetration-testingvulnerability-analysis+2
8 months ago
cve-2016-10033 preview

cve-2016-10033

GitHubcved-sources/cve-2016-10033

Docker container for CVE-2016-10033 (PHPMailer remote code execution) used for practicing exploitation in a controlled lab environment.

educationexploitationlabs-practice+2
5 years ago
CVE-2025-56311 preview

CVE-2025-56311

GitHubwrathfuldiety/cve-2025-56311

CSRF vulnerability in FD602GW-DX-R410 router allows remote attackers to reboot the device via a crafted POST request to /boaform/admin/formReboot…

educationexploitationpapers-research+3
1 year ago
Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Stored-Cross-Site-Scripting preview

Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Stored-Cross-Site-Scripting

GitHubsanupl/vehicle-service-management-system-multiple-file-upload-leads-to-stored-cross-site-scripting

CVE-2021-46078 - An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attacker can…

educationexploitationpenetration-testing+3
4 months ago
STIG-Edge-RCE-CVE2025-9478 preview

STIG-Edge-RCE-CVE2025-9478

GitHubkamgreen50/stig-edge-rce-cve2025-9478

Remediation of Microsoft Edge (Chromium) Remote Code Execution vulnerability (CVE-2025-9478, Plugin ID: 258091). Documentation includes before/after…

educationexploitationvulnerability-analysis+1
1 year ago
Previous12345Next