Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
82 results
CVE-2025-50754-PoC preview

CVE-2025-50754-PoC

GitHubfurk4nyildiz/cve-2025-50754-poc

Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)

exploitationpayload-developmentpenetration-testing+3
4
1 year ago
CVE-2026-25769 preview

CVE-2026-25769

GitHubnjeru-codes/cve-2026-25769

POC for deserialization of untrusted data in wazuh leading to RCE

exploitationpenetration-testingvulnerability-analysis+1
5 months ago
CVE-2025-24813 preview

CVE-2025-24813

GitHubmuhammadwaseem29/cve-2025-24813

Apache Tomcat is vulnerable to a Path Equivalence / Path Traversal issue due to improper handling of ../ sequences in paths.

educationexploitationpenetration-testing+3
21 year ago
CVE-2026-25769 preview

CVE-2026-25769

GitHubhakaioffsec/cve-2026-25769

Remote Code Execution via Insecure Deserialization in Wazuh Cluster

educationexploitationpenetration-testing+2
416 months ago
CVE-2017-12635 preview

CVE-2017-12635

GitHubassalielmehdi/cve-2017-12635

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

database-securityeducationexploitation+4
106 years ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubadityabhatt3010/react2shell-cve-2025-55182

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

code-analysisctfeducation+6
72 months ago
CVE-2025-64446-PoC---FortiWeb-Path-Traversal preview

CVE-2025-64446-PoC---FortiWeb-Path-Traversal

GitHubfevar54/cve-2025-64446-poc---fortiweb-path-traversal

Proof-of-concept exploit and detection scanner for CVE-2025-64446, a critical path traversal vulnerability in Fortinet FortiWeb allowing remote…

educationexploitationpenetration-testing+3
710 months ago
mgo3-rce preview

mgo3-rce

GitHubalicealys/mgo3-rce

Proof-of-concept remote code execution exploit for CVE-2026-19874 in Metal Gear Online 3, with documentation and video demo for academic research.

educationexploitationvulnerability-analysis+1
31 month ago
CVE-2026-38526-KrayinCRM preview

CVE-2026-38526-KrayinCRM

GitHubish3ng0m4/cve-2026-38526-krayincrm

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

educationexploitationpapers-research+5
10 days ago
CVE-2026-19912-CVE-2026-19913-CVE-2026-19914 preview

CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

GitHubhorkimhab/cve-2026-19912-cve-2026-19913-cve-2026-19914

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

educationexploitationpenetration-testing+3
1 month ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubdinosn/cve-2026-3844

Proof-of-concept exploit for CVE-2026-3844, an unauthenticated arbitrary file upload leading to remote code execution in Breeze Cache <= 2.4.4.…

educationexploitationpenetration-testing+3
55 months ago
CVE-2026-63223-POC preview

CVE-2026-63223-POC

GitHubimbas007/cve-2026-63223-poc

CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload…

educationexploitationlabs-practice+5
31 month ago
wp2shell-Wordpress-TOWN preview

wp2shell-Wordpress-TOWN

GitHublucifer0xf/wp2shell-wordpress-town

Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining…

code-analysisctfeducation+3
22 months ago
CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept preview

CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

GitHubkra1t0/cve-2025-33053-webdav-rce-poc-and-c2-concept

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

command-and-controleducationexploitation+5
31 year ago
CVE-2026-5029-Exploit preview

CVE-2026-5029-Exploit

GitHub0x00phantom-hat/cve-2026-5029-exploit

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

code-analysiseducationexploitation+3
2 months ago
CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass preview

CVE-2026-11104-Python-SSTI-via-Jinja2-attr-Filter-Bypass

GitHubgeorge0papasotiriou/cve-2026-11104-python-ssti-via-jinja2-attr-filter-bypass

PoC exploit for CVE-2026-11104 demonstrating Jinja2 attr filter bypass in Flask, enabling server-side template injection and remote code execution.

educationexploitationpenetration-testing+3
1 month ago
CVE-2026-33937 preview

CVE-2026-33937

GitHubeqstlab/cve-2026-33937

Handlebars.js AST Injection Remote Code Execution Vulnerability

educationexploitationlabs-practice+5
25 months ago
CVE-2026-45806 preview

CVE-2026-45806

GitHub0xmrma/cve-2026-45806

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because…

educationexploitationpapers-research+3
3 months ago
Previous12345Next