Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2060 results
external_expat_AOSP10_r33_CVE-2022-22822toCVE-2022-22827 preview

external_expat_AOSP10_r33_CVE-2022-22822toCVE-2022-22827

GitHubnanopathi/external_expat_aosp10_r33_cve-2022-22822tocve-2022-22827

Patched version of the Expat XML parser library addressing multiple CVEs (CVE-2022-22822 through CVE-2022-22827) for AOSP 10 r33, providing…

code-analysisgeneral-purpose-utilitiesstatic-analysis+2
3 years ago
OWASP__json-sanitizer_CVE-2020-13973_1-2-0 preview

OWASP__json-sanitizer_CVE-2020-13973_1-2-0

GitHubshoucheng3/owasp__json-sanitizer_cve-2020-13973_1-2-0

Java library that converts malformed JSON-like content into standards-compliant, safe JSON, preventing code injection and ensuring embeddability in…

code-analysisencryption-decryption-toolsgeneral-purpose-utilities+3
1 year ago
DSpace__DSpace_CVE-2022-31194_5-10 preview

DSpace__DSpace_CVE-2022-31194_5-10

GitHubshoucheng3/dspace__dspace_cve-2022-31194_5-10

Security patch for DSpace repository software addressing CVE-2022-31194, a vulnerability in the Java-based digital asset management platform.

code-analysiscurated-resourceseducation+2
1 year ago
apache__sling-org-apache-sling-xss_CVE-2016-5394_1-0-8 preview

apache__sling-org-apache-sling-xss_CVE-2016-5394_1-0-8

GitHubshoucheng3/apache__sling-org-apache-sling-xss_cve-2016-5394_1-0-8

Java library providing XSS escaping and filtering services (XSSAPI, XSSFilter) to sanitize user-submitted content and prevent cross-site scripting…

api-securitycode-analysisstatic-analysis+2
1 year ago
magento2-template-filter-patch preview

magento2-template-filter-patch

GitHubwubinworks/magento2-template-filter-patch

Magento 2 patch for CVE-2022-24086, CVE-2022-24087. Fix the RCE vulnerability and related bugs by performing deep template variable escaping. If you…

code-analysisexploitationmisconfiguration+3
1 year ago
jfrog-CVE-2022-24675 preview

jfrog-CVE-2022-24675

GitHubjfrog/jfrog-cve-2022-24675

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

binary-analysiscode-analysisstatic-code-analysis+2
4 years ago
-CVE-2024-31211 preview

-CVE-2024-31211

GitHubabdurahmon3236/-cve-2024-31211

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

code-analysisexploit-frameworkspayload-development+3
2 years ago
Pluck-Exploitation-by-skdevils preview

Pluck-Exploitation-by-skdevils

GitHubskdevils/pluck-exploitation-by-skdevils

# Exploit Title: Pluck CMS 4.7.16 - Remote Code Execution (RCE) (Authenticated) # Date: 13.03.2022 # Exploit Author: Ashish Koli (Shikari) # Vendor…

code-analysisexploitationpenetration-testing+2
3 years ago
exploit-CVE-2016-10033 preview

exploit-CVE-2016-10033

GitHubzeeshanbhattined/exploit-cve-2016-10033

PHPMailer < 5.2.18 Remote Code Execution

code-analysiseducationexploitation+5
4 years ago
multer-sca-rule-test_cve-2025-7338 preview

multer-sca-rule-test_cve-2025-7338

GitHubr2c-cse/multer-sca-rule-test_cve-2025-7338

Test to validate CVE-2025-7338 https://semgrep.dev/orgs/-/advisories?f=CAAQGRoTCg1jdmUtMjAyNS03MzM4GgAiAA%3D%3D

code-analysisdevsecopsstatic-analysis+3
9 months ago
gradle-cve-2021-29427-demo preview

gradle-cve-2021-29427-demo

GitHubarsalanraja987/gradle-cve-2021-29427-demo

gradle cve

code-analysiseducationexploitation+2
1 year ago
OpenSSL-1_0_1g_CVE-2015-1790 preview

OpenSSL-1_0_1g_CVE-2015-1790

GitHubtrinadh465/openssl-1_0_1g_cve-2015-1790

OpenSSL toolkit implementing SSL/TLS protocols and a general-purpose cryptography library with ciphers, digests, public key algorithms, and X.509…

authenticationcode-analysiscryptography+3
2 years ago
CVE-2016-0793 preview

CVE-2016-0793

GitHubtafamace/cve-2016-0793
code-analysisexploitationpenetration-testing+2
7 years ago
OpenSSL_1_0_1g_CVE-2015-1788 preview

OpenSSL_1_0_1g_CVE-2015-1788

GitHubpazhanivel07/openssl_1_0_1g_cve-2015-1788

General-purpose cryptography library implementing SSL/TLS protocols, symmetric/ asymmetric ciphers, message digests, and X.509 certificate handling…

authentication-authorizationcode-analysiscryptography+3
2 years ago
Spring-Cloud-Gateway-CVE-2022-22947 preview

Spring-Cloud-Gateway-CVE-2022-22947

GitHubsummer177/spring-cloud-gateway-cve-2022-22947

Spring Cloud Gateway远程代码执行漏洞

code-analysisexploitationpenetration-testing+2
4 years ago
CVE-2024-42471-PoC preview

CVE-2024-42471-PoC

GitHubthemcsam/cve-2024-42471-poc

unzip-stream file write/overwrite vulnerability

code-analysisexploitationpenetration-testing+2
1 year ago
CVE-2015-0235 preview

CVE-2015-0235

GitHubtobyzxj/cve-2015-0235

glibc gethostbyname bug

binary-analysiscode-analysisexploitation+2
11 years ago
CVE-2020-0601-spoofkey preview

CVE-2020-0601-spoofkey

GitHubexploitblizzard/cve-2020-0601-spoofkey

Proof-of-concept exploit for CVE-2020-0601 demonstrating spoofed cryptographic key generation and code signing using OpenSSL and Ruby.

code-analysiscryptographyeducation+2
5 years ago
Previous1…919293…100Next