Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
TOP — TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things | Kitploit
Tools/GitHubGitHub/ghosttroops/top
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingCurated Resources
GitHubghosttroops/top

TOP

TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things

View Repository
73112811113h 11m agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Tweet Follow on Twitter GitHub Followers Top Langs

TOP

all Top Top Top_Codeql TOP All bugbounty pentesting CVE-2022- POC Exp Things

Table of Contents

  • 2026 year top total 30
  • 2025 year top total 30
  • 2024 year top total 30
  • 2023 year top total 30
  • 2022 year top total 30
  • 2021 year top total 30
  • 2020 year top total 30

2026

starupdated_atnameurldes
40752026-09-29T18:13:27Zcopy-fail-CVE-2026-31431https://github.com/theori-io/copy-fail-CVE-2026-31431Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
7842026-09-30T00:41:22Zwp2shell-pochttps://github.com/Icex0/wp2shell-pocwp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
1842026-09-22T21:10:42Znext-16.2.4-pocshttps://github.com/dwisiswant0/next-16.2.4-pocsNext.js v16.2.4 Security PoC Collection (CVE-2026-23870, CVE-2026-44575, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573, CVE-2026-44581, CVE-2026-44580, CVE-2026-44577, CVE-2026-44576, CVE-2026-44582, CVE-2026-44572)
12422026-09-30T03:05:55Zghostlock-apphttps://github.com/YuKongA/ghostlock-appGhostLock One-Tap Execution App (CVE-2026-43499)
9622026-09-29T05:15:07ZBYOVDhttps://github.com/BlackSnufkin/BYOVDBYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
5762026-09-17T06:14:13Zcve_2026_31431https://github.com/rootsecdev/cve_2026_31431Exploit POC for CVE_2026_31431
5652026-09-26T16:05:39Zwp2shell-PoChttps://github.com/arvindear/wp2shell-PoCCVE-2026-63030 & CVE-2026-60137 RCE chain proof-of-concept
3312026-09-30T03:20:27ZCVE-2026-54121https://github.com/aniqfakhrul/CVE-2026-54121Certighost POC
2462026-09-25T21:18:15ZCVE-2026-43499-popsiclehttps://github.com/x-spy/CVE-2026-43499-popsicleCVE-2026-43499 Implementation for 6.12.23-android16-5-g75e9b1c7ae7c-abogki463945075-4k
2312026-09-20T20:12:00ZCVE-2026-41089https://github.com/0xABCD01/CVE-2026-41089Netlogon and CLDAP vulnerability research with a proof of concept.
3032026-09-28T08:18:46ZCVE-2026-21858https://github.com/Chocapikk/CVE-2026-21858n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)
13152026-09-30T02:36:29ZRoot-My-Galaxyhttps://github.com/BuSung-dev/Root-My-GalaxyKSU installer for supported Samsung Galaxy firmware with CVE-2026-43499
2612026-09-28T02:20:04ZCVE-2026-40369-EXPLOIThttps://github.com/orinimron123/CVE-2026-40369-EXPLOITFull exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox
2082026-09-11T02:48:30ZCVE-2026-24061https://github.com/SafeBreach-Labs/CVE-2026-24061Exploitation of CVE-2026-24061
1602026-09-26T04:26:40ZCVE-2026-43499https://github.com/MobiusM/CVE-2026-43499CVE-2026-43499 PoC
3592026-09-23T10:28:19Zcopyfail-gohttps://github.com/badsectorlabs/copyfail-goA Go implementation of copyfail (CVE-2026-31431)
1822026-09-29T04:12:12ZCVE-2026-62911https://github.com/hypnguyen1209/CVE-2026-62911POC pre-auth RCE on Exchange
1102026-09-23T12:37:51Zwp2shellhttps://github.com/0xsha/wp2shellCVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core
8252026-09-26T15:54:26ZCVE-2026-24061https://github.com/jacubes/CVE-2026-24061CVE-2026-24061 exploit PoC
1412026-09-24T18:40:10ZCVE-2026-42980-POChttps://github.com/G4sp4rCS/CVE-2026-42980-POCCVE-2026-42980 PUBLIC EXPLOIT + RESEARCH
5052026-09-30T00:41:14ZcPanelSniperhttps://github.com/ynsmroztas/cPanelSniperCVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection
4092026-09-29T07:18:38ZRoot-My-Pixelhttps://github.com/alex193a/Root-My-PixelJailbreak supported Google Pixel phones with CVE-2026-43499
4302026-09-30T02:23:38ZLSPromisehttps://github.com/LSPosed/LSPromiseAndroid complete exploit chain that enables privilege escalation from a local untrusted app to root/kernel, combination of CVE-2026-49881 and CVE-2026-43284
1022026-09-25T12:06:37ZCVE-2026-75604-pochttps://github.com/rafabd1/CVE-2026-75604-pocCVE-2026-75604 Next.js Windows RCE poc
2192026-09-24T15:41:52ZResetNightmarehttps://github.com/Semperis-Community/ResetNightmarePOC tool for ResetNightmare (CVE-2026-27912)
542026-09-27T21:53:28Zsamsung-android-lpehttps://github.com/Vikramaditya015/samsung-android-lpePoc for CVE-2026-20980, CVE-2026-20981, CVE-2026-20982
662026-09-23T13:49:05Zwp2shell-scannerhttps://github.com/ZephrFish/wp2shell-scannerCVE-2026-63030, CVE-2026-60137, wp2shell scanner
1292026-09-24T18:06:13ZCVE-2026-20817https://github.com/oxfemale/CVE-2026-20817Windows Error Reporting ALPC Elevation of Privilege (CVE-2026-20817) - Proof-of-Concept exploit demonstrating local privilege escalation via WER service.
3742026-09-30T02:22:15Zghostlock-oneplushttps://github.com/JoinChang/ghostlock-oneplusGhostLock (CVE-2026-43499) kernel exploit for Android devices with locked bootloader
1242026-09-17T13:21:31ZCVE-2026-41651https://github.com/Vozec/CVE-2026-41651

2025

starupdated_atnameurldes
14292026-09-28T12:48:24ZCVE-2025-55182https://github.com/msanft/CVE-2025-55182Explanation and full RCE PoC for CVE-2025-55182
24522026-09-25T12:05:45Zreact2shell-scannerhttps://github.com/assetnote/react2shell-scannerHigh Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
7922026-09-17T03:00:41ZCVE-2025-55182-researchhttps://github.com/ejpir/CVE-2025-55182-researchCVE-2025-55182 POC
4932026-08-11T09:12:24ZCVE-2018-20250https://github.com/WyAtu/CVE-2018-20250exp for https://research.checkpoint.com/extracting-code-execution-from-winrar
7202026-09-26T22:43:27ZCVE-2025-33073https://github.com/mverschu/CVE-2025-33073PoC Exploit for the NTLM reflection SMB flaw.
9622026-09-29T05:15:07ZBYOVDhttps://github.com/BlackSnufkin/BYOVDBYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
5302026-09-29T05:01:51ZCVE-2025-32463_chwoothttps://github.com/pr0v3rbs/CVE-2025-32463_chwootEscalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463
2482026-09-28T18:08:15ZIngressNightmare-PoChttps://github.com/hakaioffsec/IngressNightmare-PoCThis is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
3442026-09-28T05:13:17Zredis_exploithttps://github.com/raminfp/redis_exploitCVE-2025-49844 (RediShell)
4772026-09-17T02:59:49ZCVE-2025-32463https://github.com/kh4sh3i/CVE-2025-32463Local Privilege Escalation to Root via Sudo chroot in Linux
2672026-09-28T19:09:42ZCVE-2025-48799https://github.com/Wh04m1001/CVE-2025-48799
1422026-09-17T03:00:41ZNextjs_RCE_Exploit_Toolhttps://github.com/pyroxenites/Nextjs_RCE_Exploit_ToolExploit for CVE-2025-55182 & CVE-2025-66478
3142026-09-25T12:05:22ZCVE-2025-53770-Exploithttps://github.com/soltanali0/CVE-2025-53770-ExploitSharePoint WebPart Injection Exploit Tool
Download Tool