Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
438 results
CVE-2025-32432 preview

CVE-2025-32432

GitHubsachinart/cve-2025-32432

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability…

code-analysiseducationexploitation+3
27
1 year ago
BlockChainSec preview

BlockChainSec

GitHubal1ex/blockchainsec

BlockChain Security

code-analysiscryptographyctf+5
285 years ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubeqstlab/cve-2026-33017

Langflow RCE

code-analysiseducationexploitation+3
88 days ago
springshell-rce-poc preview

springshell-rce-poc

GitHubdduarte/springshell-rce-poc

CVE-2022-22965 - CVE-2010-1622 redux

code-analysiseducationexploitation+3
193 years ago
CVE-2026-0776 preview

CVE-2026-0776

GitHubwhenx/cve-2026-0776

Security research and proof-of-concept for CVE-2026-0776 affecting Discord Desktop Client.

code-analysiseducationexploitation+2
91 month ago
wp2shell-lab preview

wp2shell-lab

GitHub47cid/wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

code-analysisctfeducation+7
141 month ago
Jackson_RCE-CVE-2019-12384 preview

Jackson_RCE-CVE-2019-12384

GitHubmagiczer0/jackson_rce-cve-2019-12384

CVE-2019-12384 漏洞测试环境

code-analysiseducationexploitation+2
213 years ago
mininode preview

mininode

GitHubwspr-ncsu/mininode

Static analysis CLI tool that reduces Node.js application attack surface by constructing dependency graphs and removing unused modules and functions…

code-analysiseducationpapers-research+3
213 years ago
CVE-2026-2002-poc preview

CVE-2026-2002-poc

GitHubtypedefabcd1234ntd/cve-2026-2002-poc

CVE-2026-2002 writeup and Proof-of-concept

code-analysiseducationexploitation+3
111 month ago
CVE-2024-52301 preview

CVE-2024-52301

GitHubnyamort/cve-2024-52301

Proof-of-concept exploit for CVE-2024-52301 demonstrating environment manipulation in Laravel via injected URL parameters, with detailed code…

code-analysiseducationexploitation+3
211 year ago
poc-cve-2025-55182 preview

poc-cve-2025-55182

GitHubkoadt/poc-cve-2025-55182

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

code-analysisctfdynamic-analysis-sandboxing+7
155 months ago
CVE-2026-48908-PoC preview

CVE-2026-48908-PoC

GitHubpapageo75/cve-2026-48908-poc

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning,…

code-analysiseducationexploitation+5
152 months ago
Spring-Data-Mongodb-Example preview

Spring-Data-Mongodb-Example

GitHubkuron3k0/spring-data-mongodb-example

Dockerized PoC environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection) with a working exploit demonstrating remote code execution via…

code-analysiseducationexploitation+2
144 years ago
CVE-2020-36184 preview

CVE-2020-36184

GitHubal1ex/cve-2020-36184

CVE-2020-36184 && Jackson-databind RCE

code-analysiseducationexploitation+3
155 years ago
lightweight_static_analysis preview

lightweight_static_analysis

GitHubnccgroup/lightweight_static_analysis

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

code-analysiseducationpenetration-testing+4
136 years ago
CVE-2021-26121 preview

CVE-2021-26121

GitHubsourceincite/cve-2021-26121

Proof-of-concept exploit for CVE-2021-26121: Server-Side Template Injection in CS-Cart <=4.12.x allowing shop admin to achieve remote code execution…

code-analysiseducationexploitation+3
125 years ago
CVE-2021-26700 preview

CVE-2021-26700

GitHubjackadamson/cve-2021-26700

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

code-analysiseducationexploitation+3
205 years ago
cve-2022-22947-spring-cloud-gateway preview

cve-2022-22947-spring-cloud-gateway

GitHubenokiy/cve-2022-22947-spring-cloud-gateway

Detailed analysis and exploit for CVE-2022-22947, a remote code execution vulnerability in Spring Cloud Gateway via SpEL injection in the Actuator…

code-analysiseducationexploitation+4
184 years ago
Previous1…456…25Next