Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
549 results
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

code-analysisdevsecopseducation+4
14 days ago
CVE-2021-29505 preview

CVE-2021-29505

GitHubmyblackmanba/cve-2021-29505

对CVE-2021-29505进行复现,并分析学了下Xstream反序列化过程

binary-exploitationcode-analysiseducation+3
65 years ago
CVE-2026-72530-TrueConf-Sandbox-Escape- preview

CVE-2026-72530-TrueConf-Sandbox-Escape-

GitHubfevar54/cve-2026-72530-trueconf-sandbox-escape-

Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-72530**, una vulnerabilidad crítica de **Code…

code-analysiseducationexploitation+2
1 month ago
CVE-2026-14361 preview

CVE-2026-14361

GitHub0xmrma/cve-2026-14361

Consul Template's writeToFile helper opened an operator-supplied destination directly and followed linked path components, allowing rendered output…

code-analysiseducationexploitation+1
1 month ago
Office-Malware-Forensics-Lab-REMnux-Static-Analysis preview

Office-Malware-Forensics-Lab-REMnux-Static-Analysis

GitHubmo200909/office-malware-forensics-lab-remnux-static-analysis

Static analysis of 2 malicious Office documents on REMnux using oletools; identified CVE-2017-11882 and obfuscated macros.

code-analysisdigital-forensicseducation+6
14 days ago
Fern Pattern Scanner preview

Fern Pattern Scanner

GitLabgitlab-da/tutorials/security-and-governance/custom-scanner-integration/fern-pattern-scanner

Scans selected files for patterns stated in rules. This is used in order to find secrets you may have accidentally written to a file. This scanner is…

code-analysisdevsecopseducation+3
52 years ago
CVE-2020-8277 preview

CVE-2020-8277

GitHubmasahiro331/cve-2020-8277

Proof-of-concept exploit for CVE-2020-8277, a Node.js DNS resolver denial-of-service vulnerability triggered by large record responses, with…

code-analysiseducationexploitation+1
75 years ago
CVE-2021-2471 preview

CVE-2021-2471

GitHubcckuailong/cve-2021-2471

Maven-based reproduction environment for CVE-2021-2471, demonstrating JDBC SQLXML XXE exploitation with step-by-step guide and reference code.

code-analysiseducationexploitation+2
34 years ago
CVE-2026-63030-Wp2Shell preview

CVE-2026-63030-Wp2Shell

GitHubghostinexile/cve-2026-63030-wp2shell

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

code-analysiseducationexploitation+3
42 months ago
CVE-2020-8840 preview

CVE-2020-8840

GitHubveraxy00/cve-2020-8840

Jackson-databind远程代码执行漏洞(CVE-2020-8840)分析复现环境代码

code-analysiseducationexploitation+3
45 years ago
PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043- preview

PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-

GitHubalewong/php-fpm-remote-code-execution-vulnerability-cve-2019-11043-

PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python

code-analysiseducationexploitation+3
46 years ago
react2shell-lab preview

react2shell-lab

GitHubalsaut1/react2shell-lab

CVE-2025-55182 React2Shell PoC lab

code-analysisctfeducation+7
79 months ago
CVE-2023-32571-POC preview

CVE-2023-32571-POC

GitHubtris0n/cve-2023-32571-poc

Proof-of-concept for CVE-2023-32571, demonstrating remote code execution via Dynamic Linq injection in ASP.NET applications. Includes payloads and a…

code-analysiseducationexploitation+4
72 years ago
ReactOOPS-WriteUp preview

ReactOOPS-WriteUp

GitHubthestingr/reactoops-writeup

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

code-analysisctfeducation+8
79 months ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubgh-ost00/cve-2024-4879

Proof-of-concept exploit for CVE-2024-4879, a Jelly template injection vulnerability in ServiceNow enabling unauthenticated remote code execution.…

code-analysiseducationexploitation+3
42 years ago
wp2shell preview

wp2shell

GitHubcrypto-cat/wp2shell

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

code-analysiseducationexploitation+2
32 months ago
chub-supply-chain-poc preview

chub-supply-chain-poc

GitHubmickmicksh/chub-supply-chain-poc

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

ai-securitycode-analysiseducation+5
46 months ago
CVE-2024-53924 preview

CVE-2024-53924

GitHubaelmosalamy/cve-2024-53924

A PoC of CVE-2024-53924

code-analysiseducationexploitation+3
51 year ago
Previous1…8910…31Next