Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
551 results
CVE-2023-6553-PoC preview

CVE-2023-6553-PoC

GitHubmotikan2010/cve-2023-6553-poc

Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration…

code-analysisexploitationpayload-development+3
4
2 years ago
CVE-2021-2471 preview

CVE-2021-2471

GitHubdrunkenshells/cve-2021-2471

PoC for CVE-2021-2471 - XXE in MySQL Connector/J

code-analysisdatabase-securityexploitation+3
34 years ago
CVE-2022-39425 preview

CVE-2022-39425

GitHubbob11vrdp/cve-2022-39425

CVE-2022-39425 PoC

binary-exploitationcode-analysisexploitation+2
33 years ago
CVE-2023-46818 preview

CVE-2023-46818

GitHubrvzsec/cve-2023-46818

CVE-2023-46818 - ISPConfig PHP Code Injection PoC Exploit (Bash)

code-analysisexploitationpayload-development+3
41 year ago
CVE-2023-46694 preview

CVE-2023-46694

GitHubinvisiblebyte/cve-2023-46694

Proof-of-concept exploit for CVE-2023-46694: authenticated remote code execution via arbitrary file upload in Vtenext 21.02 Ckeditor file manager.

code-analysisexploitationpenetration-testing+2
42 years ago
CVE-2025-70830 preview

CVE-2025-70830

GitHubxiaoxiaoranxxx/cve-2025-70830

A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows authenticated attackers to…

code-analysisexploitationpayload-development+3
57 months ago
CVE-2025-56815 preview

CVE-2025-56815

GitHubxiaoxiaoranxxx/cve-2025-56815

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

code-analysisexploitationmisconfiguration+3
51 year ago
CVE-2017-16082 preview

CVE-2017-16082

GitHubnulldreams/cve-2017-16082

NodeJS + Postgres (Remote Code Execution) 🛰

code-analysisdatabase-securityexploitation+3
57 years ago
enforcement-coverage preview

enforcement-coverage

GitHubarian-gogani/enforcement-coverage

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

api-securitycode-analysisdevsecops+3
117 days ago
React2Shell_Rce-cve-2025-55182 preview

React2Shell_Rce-cve-2025-55182

GitHubmuhammadwaseem29/react2shell_rce-cve-2025-55182

React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0, including react-server-dom-parcel, react-server-dom-turbopack, and…

code-analysisexploitationpayload-development+3
39 months ago
CVE-2023-34212 preview

CVE-2023-34212

GitHubmbadanoiu/cve-2023-34212

CVE-2023-34212: Java Deserialization via JNDI Components in Apache NiFi

code-analysisexploitationpenetration-testing+2
32 years ago
CVE-2019-12086-jackson-databind-file-read preview

CVE-2019-12086-jackson-databind-file-read

GitHubmotoyasu-saburi/cve-2019-12086-jackson-databind-file-read

Proof-of-concept exploit for CVE-2019-12086: Jackson databind deserialization vulnerability enabling arbitrary file read via rogue MySQL server when…

code-analysisexploitationpenetration-testing+2
17 years ago
CVE-2022-22947-POC preview

CVE-2022-22947-POC

GitHubstayfoolish777/cve-2022-22947-poc

批量检测Spring Cloud Gateway 远程代码执行漏洞 Spring_Cloud_Gateway_RCE_POC-CVE-2022-22947

api-securitycode-analysisexploitation+3
34 years ago
poc-cve-2018-1273 preview

poc-cve-2018-1273

GitHubwebr0ck/poc-cve-2018-1273

Proof-of-concept exploit for CVE-2018-1273, a Spring Data Commons property binder vulnerability leading to remote code execution via crafted HTTP…

code-analysisexploitationpenetration-testing+2
27 years ago
CVE-2025-58440 preview

CVE-2025-58440

GitHubph-hitachi/cve-2025-58440

Remote Code Execution (RCE) via Polyglot File Attack and Null Byte Injection on Laravel FileManager

code-analysisexploitationpayload-development+3
31 year ago
CVE-2022-34265 preview

CVE-2022-34265

GitHubzhaoqi99/cve-2022-34265

PoC for CVE-2022-34265

code-analysisdatabase-securityexploitation+3
44 years ago
cve-2024-50330-ivanti_epm_sqli_reproduction preview

cve-2024-50330-ivanti_epm_sqli_reproduction

GitHubrazureink/cve-2024-50330-ivanti_epm_sqli_reproduction

CVE Reproduction: cve-2024-50330-ivanti_epm_sqli_reproduction

code-analysisexploitationpayload-development+3
2 months ago
CVE-2019-17570 preview

CVE-2019-17570

GitHubr00t4dm/cve-2019-17570

xmlrpc common deserialization vulnerability

code-analysisexploitationpenetration-testing+2
46 years ago
Previous1…8910…31Next