Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
221 results
CVE-2019-9978-Social-Warfare-WordPress-RCE preview

CVE-2019-9978-Social-Warfare-WordPress-RCE

GitHubtokyohunter/cve-2019-9978-social-warfare-wordpress-rce

A complete walkthrough and exploit for CVE-2019-9978 - Unauthenticated Remote Code Execution in Social Warfare WordPress plugin ≤ 3.5.2. Includes…

code-analysiseducationexploitation+3
1
2 months ago
CVE-2020-7598 preview

CVE-2020-7598

GitHubrenewablehacking/cve-2020-7598

Educational lab demonstrating CVE-2020-7598 prototype pollution in minimist with a vulnerable Node.js/Express app, exploit payload, and…

code-analysiseducationlabs-practice+3
3 months ago
CVE-2025-65741 preview

CVE-2025-65741

GitHubvinicius-batistella/cve-2025-65741

Proof-of-concept for CVE-2025-65741 demonstrating dylib injection in Sublime Text 3 on macOS via unsigned code, with a compiled .dylib payload and…

binary-exploitationcode-analysisexploitation+2
8 months ago
CVE-2017-8046 preview

CVE-2017-8046

GitHubbkhablenko/cve-2017-8046

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

code-analysiseducationpenetration-testing+3
7 years ago
CVE-2022-21445-for-12.2.1.3.0-Weblogic preview

CVE-2022-21445-for-12.2.1.3.0-Weblogic

GitHubhienkiet/cve-2022-21445-for-12.2.1.3.0-weblogic

Pre-authentication remote code execution exploit for Oracle WebLogic ADF Faces (CVE-2022-21445, CVSS 9.8). Includes detailed environment setup,…

code-analysisexploitationpayload-development+4
52 years ago
CVE-2025-68147-OSPOS-Stored-XSS preview

CVE-2025-68147-OSPOS-Stored-XSS

GitHubnixon-h/cve-2025-68147-ospos-stored-xss

PoC repository for CVE-2025-68147: Stored Cross-Site Scripting (XSS) in OpenSourcePOS. Vulnerability allows privilege escalation via malicious…

code-analysiseducationexploitation+3
23 months ago
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection preview

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

GitHubhunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

Proof-of-concept exploit for CVE-2026-58116 demonstrating remote code execution in LLaMA-Factory WebUI via trust_remote_code model path injection.…

code-analysisctfeducation+5
2 months ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubtrganda/cve-2021-22204

In-depth technical analysis of CVE-2021-22204 (ExifTool RCE) with PoC reproduction, payload construction, and Perl code review of the vulnerable DjVu…

binary-exploitationcode-analysiseducation+3
34 years ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
4 months ago
CVE-2021-43503 preview

CVE-2021-43503

GitHubkang8/cve-2021-43503

Proof-of-concept exploit for CVE-2021-43503, a Laravel deserialization RCE vulnerability. Includes PHP POP chain generation and HTTP-based payload…

code-analysisexploitationpayload-generation+2
14 years ago
CVE-2026-22785 preview

CVE-2026-22785

GitHublangbyyi/cve-2026-22785

Exploit tool for CVE-2026-22785, a critical code injection in orval < 7.18.0. Provides shell command execution and file scanning to demonstrate the…

code-analysiseducationexploitation+2
17 months ago
CVE-2022-24434_POC preview

CVE-2022-24434_POC

GitHubnayankadamm/cve-2022-24434_poc

Proof-of-concept exploit for CVE-2022-24434 targeting the Dicer npm package v0.3.1. Demonstrates server-side vulnerability exploitation with a…

code-analysiseducationexploitation+2
11 months ago
CVE-2019-3396 preview

CVE-2019-3396

GitHubtranphuc2005/cve-2019-3396

Step-by-step analysis and exploitation guide for CVE-2019-3396, a critical SSTI vulnerability in Confluence Server & Data Center, including debugging…

code-analysiseducationexploitation+3
1 year ago
PoC-CVE-2019-10743 preview

PoC-CVE-2019-10743

GitHubalbisorua/poc-cve-2019-10743

Proof-of-concept exploit demonstrating the Zip Slip vulnerability (CVE-2019-10743) in mholt/archiver, with a vulnerable server and Python payload for…

code-analysiseducationexploitation+3
1 year ago
CVE-2024-53677-Exploitation preview

CVE-2024-53677-Exploitation

GitHubhopsypopsy8/cve-2024-53677-exploitation

Step-by-step walkthrough for exploiting Apache Struts CVE-2024-53677 RCE via file upload manipulation, including OGNL injection, payload embedding,…

code-analysiseducationexploitation+6
1 year ago
CVE-2025-24813-noPoC preview

CVE-2025-24813-noPoC

GitHubheimd411/cve-2025-24813-nopoc

Research repository documenting failed exploitation attempts for CVE-2025-24813, a deserialization vulnerability in Apache Tomcat, with tested…

code-analysisexploitationpenetration-testing+2
1 year ago
-CVE-2018-6574 preview

-CVE-2018-6574

GitHubjftierno/-cve-2018-6574

Exploit for CVE-2018-6574, a Go command injection vulnerability. Provides a targeted payload for testing and validating the flaw in affected systems.

binary-exploitationcode-analysisexploitation+2
2 years ago
CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape preview

CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape

GitHubgeorge0papasotiriou/cve-2026-1337-ai-coding-assistant-prompt-injection-to-sandbox-escape

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

adversarial-attackai-securitycode-analysis+4
1 month ago
Previous12…13Next