Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
551 results
CVE-2024-40110 preview

CVE-2024-40110

GitHubabdurahmon3236/cve-2024-40110

Proof-of-concept script demonstrating unauthenticated remote code execution in Sourcecodester Poultry Farm Management System via the vulnerable…

code-analysisexploitationpayload-development+3
2 years ago
RCE-QloApps-CVE-2024-40318 preview

RCE-QloApps-CVE-2024-40318

GitHub3v1lc0d3/rce-qloapps-cve-2024-40318

Remote code execution Vulnerability in QloApps  (version 1.6.0.0)

code-analysisexploitationpenetration-testing+2
2 years ago
go-get-rce preview

go-get-rce

GitHubahmetmanga/go-get-rce

cve-2018-6574 @pentesterlab

code-analysisexploitationpenetration-testing+2
8 years ago
CVE-2021-31856 preview

CVE-2021-31856

GitHubssst0n3/cve-2021-31856

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

code-analysisdatabase-securitypenetration-testing+2
5 years ago
CVE-2018-16370 preview

CVE-2018-16370

GitHubsnappyjack/cve-2018-16370

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

code-analysisexploitationpenetration-testing+2
8 years ago
CVE-2024-6330 preview

CVE-2024-6330

GitHubrandomrobbiebf/cve-2024-6330

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

code-analysisexploitationpayload-development+3
1 year ago
text4shell preview

text4shell

GitHubhotblac/text4shell

Demonstration of CVE-2022-42889 (Text4Shell) remote code execution vulnerability in Apache Commons Text with a proof-of-concept exploit.

code-analysisexploitationpenetration-testing+2
3 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubnoname-nohost/cve-2018-6574

Proof-of-concept exploit for CVE-2018-6574, a remote code execution vulnerability in Go's net/http package via crafted HTTP requests.

code-analysisexploitationpenetration-testing+2
5 years ago
GHSA-4cx5-89vm-833x-POC preview

GHSA-4cx5-89vm-833x-POC

GitHubjacklosingheart/ghsa-4cx5-89vm-833x-poc

GHSA-4cx5-89vm-833x/CVE-2024-52800

code-analysisexploitationpenetration-testing+2
1 year ago
CVE-2024-10728 preview

CVE-2024-10728

GitHubrandomrobbiebf/cve-2024-10728

PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation

authenticationcode-analysisexploitation+3
1 year ago
CVE-2024-10124 preview

CVE-2024-10124

GitHubrandomrobbiebf/cve-2024-10124

Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Plugin…

code-analysisexploitationpenetration-testing+3
1 year ago
CVE-2019-5420 preview

CVE-2019-5420

GitHubtrickstersec/cve-2019-5420

Exploit for the Rails CVE-2019-5420

code-analysisexploitationpenetration-testing+2
4 years ago
CVE-2025-22777 preview

CVE-2025-22777

GitHubrandomrobbiebf/cve-2025-22777

GiveWP – Donation Plugin and Fundraising Platform <= 3.19.3 - Unauthenticated PHP Object Injection

code-analysisexploitationpenetration-testing+3
1 year ago
CVE-2021-46362 preview

CVE-2021-46362

GitHubmbadanoiu/cve-2021-46362

CVE-2021-46362: FreeMarker Server-Side Template Injection in Magnolia CMS

code-analysisexploitationpenetration-testing+2
2 years ago
CVE-2016-2098 preview

CVE-2016-2098

GitHubdebalinax64/cve-2016-2098

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

code-analysisexploitationpenetration-testing+2
5 years ago
CVE-2024-50507 preview

CVE-2024-50507

GitHubrandomrobbiebf/cve-2024-50507

DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection

code-analysisexploitationpenetration-testing+3
1 year ago
CVE-2018-17240 preview

CVE-2018-17240

GitHubbbge/cve-2018-17240

CVE-2018-17240

code-analysisexploitationpenetration-testing+2
4 years ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubnsbyte/cve-2018-6574

Go-based proof-of-concept exploit for CVE-2018-6574, demonstrating remote code execution via crafted requests to vulnerable Go applications.

code-analysisexploitationpenetration-testing+2
3 years ago
Previous1…202122…31Next