Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Categories

Phishing

Phishing simulation, detection, analysis, and security awareness training tools.

Kitploit recommended

Top tools

10 selected
gophish preview#1

gophish

GitHubgophish/gophish
14.1k2 years ago
evilginx2 preview#2

evilginx2

GitHubkgretzky/evilginx2
15.5k3 months ago
social-engineer-toolkit preview#3

social-engineer-toolkit

GitHubtrustedsec/social-engineer-toolkit
15.2k3 months ago
Modlishka preview#4

Modlishka

GitHubdrk1wi/modlishka
5.4k1 month ago
muraena preview#5

muraena

GitHubmuraenateam/muraena
1.1k1 year ago
zphisher preview#6

zphisher

GitHubhtr-tech/zphisher
16.6k2 years ago
wifiphisher preview#7

wifiphisher

GitHubwifiphisher/wifiphisher
14.8k4 months ago
chlonium preview#9

chlonium

GitHubrxwx/chlonium
3163 years ago
SocialFish preview#10

SocialFish

GitHubundeadsec/socialfish
4.8k4 months ago
CredSniper preview#11

CredSniper

GitHubustayready/credsniper
1.4k6 years ago
NewestRelevanceMost popularRecently updated
323 results
Leantime-POC preview

Leantime-POC

GitHubdead1nfluence/leantime-poc

CVE-2024-27474, CVE-2024-27476, CVE-2024-27477

vulnerability-analysisexploitationweb-application-exploitation+2
1 year ago
CVE-2019-13633 preview

CVE-2019-13633

GitHubsecurity-avs/cve-2019-13633

Proof of concept for a blind/persistent XSS vulnerability in Blinger.io helpdesk, demonstrating remote code execution in admin panels via crafted…

vulnerability-analysisweb-application-exploitationinformation-gathering+3
5 years ago
CVE-2025-50363_BXSS_CVE preview

CVE-2025-50363_BXSS_CVE

GitHub1h3ll/cve-2025-50363_bxss_cve

Proof-of-concept for a blind XSS vulnerability in Maid Hiring Management System v1.0, capturing admin session cookies via a crafted application form…

privilege-escalationvulnerability-analysisexploitation+3
1 year ago
CVE-2025-3568 preview

CVE-2025-3568

GitHubshellkraft/cve-2025-3568

A security vulnerability has been identified in Krayin CRM <=2.1.0 that allows a low-privileged user to escalate privileges by tricking an admin into…

privilege-escalationvulnerability-analysisexploitation+3
1 year ago
CVE-2022-48429_poc preview

CVE-2022-48429_poc

GitHubecho-devim/cve-2022-48429_poc

Proof-of-concept exploit for CVE-2022-48429, a stored cross-site scripting vulnerability in JetBrains YouTrack dashboards enabling low-privileged…

vulnerability-analysisexploitationweb-application-exploitation+3
3 years ago
CVE-2025-28073 preview

CVE-2025-28073

GitHubmlniumm/cve-2025-28073

Proof-of-concept for a reflected XSS vulnerability in phpList 3.6.15 via the /lists/dl.php endpoint, enabling session hijacking and arbitrary…

vulnerability-analysisexploitationweb-application-exploitation+2
1 year ago
CVE-2023-48104 preview

CVE-2023-48104

GitHube1tex/cve-2023-48104

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

vulnerability-analysisexploitationweb-application-exploitation+2
2 years ago
cve-2019-17497 preview

cve-2019-17497

GitHubjm-lemmi/cve-2019-17497

POC Files for CVE-2019-17497

vulnerability-analysisexploitationinformation-gathering+2
4 years ago
CVE-2020-12625 preview

CVE-2020-12625

GitHubmbadanoiu/cve-2020-12625

CVE-2020-12625: Cross-Site Scripting via Malicious HTML Attachment in Roundcube Webmail

vulnerability-analysisexploitationweb-application-exploitation+2
2 years ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

osintpassword-crackingreconnaissance+5
1 year ago
CVE-2022-46087 preview

CVE-2022-46087

GitHubg37sys73m/cve-2022-46087

CloudSchool v3.0.1 is vulnerable to Cross Site Scripting (XSS). A normal user can steal session cookies of the admin users through notification…

vulnerability-analysisweb-application-exploitationphishing+2
3 years ago
CVE-2017-15394 preview

CVE-2017-15394

GitHubsudosammy/cve-2017-15394

Demonstrates an IDN homograph attack in Chromium extensions to spoof URLs, aiding in deception attacks by coercing victims into granting permissions…

exploitationphishingweb-security+2
8 years ago
CVE-2021-46366 preview

CVE-2021-46366

GitHubmbadanoiu/cve-2021-46366

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

password-attacksexploitationweb-application-exploitation+3
2 years ago
CVE-2024-6529 preview

CVE-2024-6529

GitHubabdurahmon3236/cve-2024-6529

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…

vulnerability-analysisexploitationweb-application-exploitation+3
2 years ago
CVE-2024-3867 preview

CVE-2024-3867

GitHubc4cnm/cve-2024-3867

This repository shows u some information on this vulnerability, which were found by me.

vulnerability-analysisexploitationweb-application-exploitation+3
2 years ago
CVE-2020-16270 preview

CVE-2020-16270

GitHubsecurity-avs/cve-2020-16270

Proof-of-concept for CVE-2020-16270, an XSS vulnerability in OLIMPOKS under 3.3.39, demonstrating remote injection of malicious JavaScript to steal…

vulnerability-analysisexploitationweb-application-exploitation+3
5 years ago
Mailphish preview

Mailphish

GitHubmcracker2002/mailphish

Creates professional phishing emails with 20+ templates for credential harvesting, including HTML generation and direct email delivery to targets.

phishing-toolsphishingsocial-engineering+1
5 years ago
LazyOwn preview

LazyOwn

GitHubgrisuno/lazyown

Red team framework and multi-operator C2 platform with AI agents, malleable implants, rootkits, phishing engine, and 741 CLI commands covering the…

penetration-testing-frameworksvulnerability-scannersexploit-frameworks+8
2281 day ago
Previous1…161718Next