Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36810 results
CVE-2026-32743-PX4-Autopilot-MavlinkLogHandler-Stack-Buffer-Overflow-DoS- preview

CVE-2026-32743-PX4-Autopilot-MavlinkLogHandler-Stack-Buffer-Overflow-DoS-

GitHubmbanyamer/cve-2026-32743-px4-autopilot-mavlinkloghandler-stack-buffer-overflow-dos-

A remote Denial of Service (DoS) exploit for PX4 Autopilot versions ≤1.17.0-rc2 via a stack‑based buffer overflow in the MavlinkLogHandler.

embedded-systems-securityexploit-frameworksiot-security+3
4 months ago
CVE-2026-32707-PX4-Autopilot-tattu_can-Stack-Buffer-Overflow-DoS- preview

CVE-2026-32707-PX4-Autopilot-tattu_can-Stack-Buffer-Overflow-DoS-

GitHubmbanyamer/cve-2026-32707-px4-autopilot-tattu_can-stack-buffer-overflow-dos-

Proof-of-concept exploit for CVE-2026-32707, a stack buffer overflow in the PX4-Autopilot tattu_can driver, causing denial of service via crafted CAN…

embedded-systems-securityiot-securityvulnerability-analysis+4
4 months ago
CVE-2026-28372-GNU-inetutils-telnetd-Privilege-Escalation preview

CVE-2026-28372-GNU-inetutils-telnetd-Privilege-Escalation

GitHubmbanyamer/cve-2026-28372-gnu-inetutils-telnetd-privilege-escalation

Proof-of-concept exploit for CVE-2026-28372, demonstrating local privilege escalation in GNU inetutils telnetd via CREDENTIALS_DIRECTORY and…

privilege-escalationexploit-frameworksvulnerability-analysis+3
5 months ago
CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration preview

CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration

GitHubmbanyamer/cve-2026-27579-collabplatform-appwrite-cors-misconfiguration

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

phishing-toolsvulnerability-analysisexploitation+3
6 months ago
CVE-2026-27574-OneUptime-RCE preview

CVE-2026-27574-OneUptime-RCE

GitHubmbanyamer/cve-2026-27574-oneuptime-rce

Proof-of-concept exploit for CVE-2026-27574, a critical code injection in OneUptime enabling remote code execution and environment variable leakage.

vulnerability-analysisexploitationweb-application-exploitation+3
17 months ago
CVE-2026-27180-MajorDoMo-unauthenticated-RCE preview

CVE-2026-27180-MajorDoMo-unauthenticated-RCE

GitHubmbanyamer/cve-2026-27180-majordomo-unauthenticated-rce

Proof-of-concept exploit for CVE-2026-27180, an unauthenticated RCE in MajorDoMo via update URL poisoning, delivering a webshell to the web root.

vulnerability-analysisexploitationweb-application-exploitation+3
7 months ago
CVE-2026-26988-LibreNMS-SQLi preview

CVE-2026-26988-LibreNMS-SQLi

GitHubmbanyamer/cve-2026-26988-librenms-sqli

Proof-of-concept exploit for unauthenticated SQL injection in LibreNMS ajax_table.php, demonstrating time-based and boolean-based blind injection…

vulnerability-analysisexploitationweb-application-exploitation+3
7 months ago
CVE-2026-26335-Calero-VeraSMART-RCE preview

CVE-2026-26335-Calero-VeraSMART-RCE

GitHubmbanyamer/cve-2026-26335-calero-verasmart-rce

Automated exploit for CVE-2026-26335, a critical unauthenticated RCE in Calero VeraSMART via forged ASP.NET ViewState using static machine keys.…

payload-generationvulnerability-analysisexploitation+4
7 months ago
CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown preview

CVE-2026-26235-JUNG-Smart-Visu-Server-Unauthenticated-Reboot-Shutdown

GitHubmbanyamer/cve-2026-26235-jung-smart-visu-server-unauthenticated-reboot-shutdown

Proof-of-concept exploit for CVE-2026-26235, an unauthenticated denial-of-service vulnerability in JUNG Smart Visu Server <=1.1.1050, allowing remote…

iot-securityvulnerability-analysisexploitation+2
7 months ago
CVE-2026-26221-Hyland-OnBase-Timer-Service-Unauthenticated-RCE preview

CVE-2026-26221-Hyland-OnBase-Timer-Service-Unauthenticated-RCE

GitHubmbanyamer/cve-2026-26221-hyland-onbase-timer-service-unauthenticated-rce

Proof-of-concept exploit for unauthenticated remote code execution in Hyland OnBase Timer Service via .NET Remoting BinaryFormatter deserialization,…

payload-generationvulnerability-analysisexploitation+3
7 months ago
CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE preview

CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE

GitHubmbanyamer/cve-2026-26030-microsoft-semantic-kernel-1.39.4-rce

Proof-of-concept exploit for CVE-2026-26030, demonstrating remote code execution via unsafe filter expressions in Microsoft Semantic Kernel's…

vulnerability-analysiscode-analysisexploitation+2
16 months ago
CVE-2026-25961-SumatraPDF-3.5.0---3.5.2-RCE preview

CVE-2026-25961-SumatraPDF-3.5.0---3.5.2-RCE

GitHubmbanyamer/cve-2026-25961-sumatrapdf-3.5.0---3.5.2-rce

SumatraPDF versions 3.5.0 to 3.5.2 disable TLS hostname verification during update checks # (using INTERNET_FLAG_IGNORE_CERT_CN_INVALID) and do not…

payload-generationvulnerability-analysisexploitation+3
27 months ago
CVE-2026-25939-SCADA-FUXA-Unauthenticated-Remote-Arbitrary preview

CVE-2026-25939-SCADA-FUXA-Unauthenticated-Remote-Arbitrary

GitHubmbanyamer/cve-2026-25939-scada-fuxa-unauthenticated-remote-arbitrary

Proof-of-concept exploit for CVE-2026-25939, an unauthenticated authorization bypass in FUXA SCADA software allowing arbitrary scheduler manipulation…

vulnerability-analysisexploitationscada-ics-security+2
7 months ago
CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute preview

CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute

GitHubmbanyamer/cve-2026-25916-roundcube-webmail-dom-based-xss-exploit-via-svg-href-attribute

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

payload-generationvulnerability-analysisexploitation+3
37 months ago
CVE-2026-25890-FileBrowser-Access-Control-Bypass preview

CVE-2026-25890-FileBrowser-Access-Control-Bypass

GitHubmbanyamer/cve-2026-25890-filebrowser-access-control-bypass

Exploit for CVE-2026-25890, a path-based authorization bypass in FileBrowser <= v2.57.0, allowing authenticated low-privileged users to read, upload,…

vulnerability-analysisexploitationweb-application-exploitation+2
7 months ago
CVE-2026-25732-NiceGUI-3.6.1 preview

CVE-2026-25732-NiceGUI-3.6.1

GitHubmbanyamer/cve-2026-25732-nicegui-3.6.1

Exploit for CVE-2026-25732, a path traversal in NiceGUI's FileUpload that allows unauthenticated arbitrary file write. Includes usage examples for…

vulnerability-analysisexploitationweb-application-exploitation+2
7 months ago
CVE-2026-25546-godot-mcp-0.1.1-OS-Command-Injection preview

CVE-2026-25546-godot-mcp-0.1.1-OS-Command-Injection

GitHubmbanyamer/cve-2026-25546-godot-mcp-0.1.1-os-command-injection

Proof-of-concept exploit for CVE-2026-25546, demonstrating OS command injection in godot-mcp via malicious projectPath parameter, with Python PoC and…

vulnerability-analysiscode-analysisexploitation+2
7 months ago
CVE-2026-25512-PoC-Group-Office-Authenticated-RCE preview

CVE-2026-25512-PoC-Group-Office-Authenticated-RCE

GitHubmbanyamer/cve-2026-25512-poc-group-office-authenticated-rce

Authenticated remote code execution exploit for Group-Office via TNEF attachment handler, targeting CVE-2026-25512 with OS command injection.

vulnerability-analysisexploitationweb-application-exploitation+2
7 months ago
Previous1…99100Next