Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
174 results
CVE-2026-3300 preview

CVE-2026-3300

GitHubadamshaikhma/cve-2026-3300

Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

code-analysisexploitationpayload-development+3
2 months ago
CVE-2019-17234b-Exploit preview

CVE-2019-17234b-Exploit

GitHubadministra1tor/cve-2019-17234b-exploit

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

code-analysisexploitationpenetration-testing+2
5 years ago
CVE-2021-44228_scanner preview

CVE-2021-44228_scanner

GitHubjeremyrsellars/cve-2021-44228_scanner

Aims to find JndiLookup.class in nearly any directory or zip, jar, ear, war file, even deeply nested.

code-analysisforensicsincident-response+3
4 years ago
cve-2023-50164 preview

cve-2023-50164

GitHubhelsecert/cve-2023-50164

Detection scripts for CVE-2023-50164 in Apache Struts2, providing PowerShell and Bash tools to scan for vulnerable versions across file systems and…

code-analysisexploitationinformation-gathering+3
12 years ago
CVE-2026-0766 preview

CVE-2026-0766

GitHubbitt0n/cve-2026-0766

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

code-analysiseducationexploitation+3
5 months ago
CVE-2024-13869 preview

CVE-2024-13869

GitHubd0n601/cve-2024-13869

Migration,Backup, Staging – WPvivid <= 0.9.112 - Authenticated (Admin+) Arbitrary File Upload via wpvivid_upload_file

code-analysisexploitationpayload-generation+3
1 year ago
CVE-2022-45771 preview

CVE-2022-45771

GitHubyuriisanin/cve-2022-45771

[PoC] Privilege escalation & code execution via LFI in PwnDoC

code-analysisexploitationpayload-development+4
63 years ago
CVE-2024-50340 preview

CVE-2024-50340

GitHubnyamort/cve-2024-50340

Proof-of-concept exploit for CVE-2024-50340 demonstrating Symfony ArgvInput environment variable injection via crafted URL query parameters, enabling…

code-analysiseducationexploitation+3
121 year ago
Git-Secret preview
Archived

Git-Secret

GitHubdaffainfo/git-secret

Go scripts for finding sensitive data like API key / some keywords in the github repository

code-analysisinformation-gatheringosint+3
1584 years ago
CVE-2024-37032-PoC preview

CVE-2024-37032-PoC

GitHubitzsh4dowxz/cve-2024-37032-poc

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

code-analysisexploitationpayload-development+5
82 months ago
CVE-2026-13157 preview

CVE-2026-13157

GitHubminhhk68/cve-2026-13157

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

code-analysisexploitationpayload-development+4
29 days ago
CVE-2024-52302 preview

CVE-2024-52302

GitHubd3sca/cve-2024-52302

PoC exploit for CVE-2024-52302: unrestricted file upload in common-user-management Spring Boot app leading to remote code execution via…

code-analysisexploitationpayload-generation+3
11 year ago
CVE-2025-69906-Monstra-CMS-3.0.4-Arbitrary-File-Upload-to-RCE preview

CVE-2025-69906-Monstra-CMS-3.0.4-Arbitrary-File-Upload-to-RCE

GitHubcypherdavy/cve-2025-69906-monstra-cms-3.0.4-arbitrary-file-upload-to-rce

Technical analysis and proof-of-concept for CVE-2025-69906, an arbitrary file upload vulnerability in Monstra CMS 3.0.4 leading to remote code…

code-analysiseducationexploitation+3
36 months ago
CVE-2023-46694 preview

CVE-2023-46694

GitHubinvisiblebyte/cve-2023-46694

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

code-analysisexploitationpenetration-testing+2
42 years ago
py_certificate_extractor preview

py_certificate_extractor

GitHubpassword123456/py_certificate_extractor

Extracts and exports certificate information from digitally signed PE files using Python and pefile, enabling forensic analysis of code-signing…

code-analysisdigital-forensicsmalware-analysis+1
3 years ago
CVE-2026-14361 preview

CVE-2026-14361

GitHub0xmrma/cve-2026-14361

Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output…

code-analysiseducationexploitation+1
28 days ago
POC-CVE-2025-66034 preview

POC-CVE-2025-66034

GitHubv3cn4x00/poc-cve-2025-66034

Automated exploit for CVE-2025-66034, chaining path traversal and XML injection in fontTools varLib to achieve unauthenticated remote code execution…

binary-analysiscode-analysiseducation+5
45 months ago
CVE-2024-6330 preview

CVE-2024-6330

GitHubrandomrobbiebf/cve-2024-6330

GEO my WordPress < 4.5.0.2 - Unauthenticated LFI to RCE/PHAR Deserialization

code-analysisexploitationpayload-development+3
1 year ago
Previous1…456…10Next