Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
tplmap preview

tplmap

GitHubepinna/tplmap

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

code-analysisexploitationpenetration-testing+2
4.2k4 years ago
EXPLOIT-CVE-2026-8832- preview

EXPLOIT-CVE-2026-8832-

GitHubfunixone/exploit-cve-2026-8832-

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

code-analysisexploitationpayload-development+5
4 months ago
EXPLOIT-CVE-2026-8832 preview

EXPLOIT-CVE-2026-8832

GitHubfunixone/exploit-cve-2026-8832

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

code-analysisexploitationpayload-development+5
14 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubmahaveer-choudhary/cve-2025-55182

A Python-based security scanner for detecting and exploiting **React Server Components (RSC)** vulnerabilities in Next.js applications. This tool…

code-analysisexploitationpenetration-testing+3
9 months ago
CVE-2024-36104 preview

CVE-2024-36104

GitHubggfzx/cve-2024-36104

Exploit tool for CVE-2024-36104 targeting Apache OFBiz code execution vulnerability. Supports single and batch URL scanning with proxy and threading…

code-analysisexploitationpenetration-testing+3
22 years ago
CVE-2022-22965-susceptibility preview

CVE-2022-22965-susceptibility

GitHubfransvanbuul/cve-2022-22965-susceptibility

Java-based tool to detect and test for CVE-2022-22965 (Spring4Shell) vulnerability in web applications, enabling security validation and exploitation…

code-analysisexploitationpenetration-testing+2
4 years ago
jsPDF-Bulk-Detector-CVE-2025-68428- preview

jsPDF-Bulk-Detector-CVE-2025-68428-

GitHubnurjaman2004/jspdf-bulk-detector-cve-2025-68428-

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

code-analysisinformation-gatheringreconnaissance+3
18 months ago
CVE-2026-0766 preview

CVE-2026-0766

GitHubbitt0n/cve-2026-0766

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

code-analysiseducationexploitation+3
6 months ago
detect-log4j-exploitable preview

detect-log4j-exploitable

GitHubm0rath/detect-log4j-exploitable

Bash script to detect Log4j (CVE-2021-44228) exploitable systems by scanning running Java processes for vulnerable log4j-core components without…

code-analysisexploitationscripting-automation+2
4 years ago
kadimus preview
Archived

kadimus

GitHubp0cl4bs/kadimus

kadimus is a tool to check and exploit lfi vulnerability.

code-analysisexploitationpenetration-testing+3
5756 years ago
CVE-2019-17571 preview

CVE-2019-17571

GitHubshadow-horse/cve-2019-17571

Apache Log4j 1.2.X存在反序列化远程代码执行漏洞

code-analysisexploitationpenetration-testing+2
786 years ago
CVE-2020-1947 preview

CVE-2020-1947

GitHubjas502n/cve-2020-1947

Apache ShardingSphere UI YAML解析远程代码执行漏洞

code-analysisexploitationpenetration-testing+3
316 years ago
CVE-2019-17564 preview

CVE-2019-17564

GitHubfairyming/cve-2019-17564

CVE-2019-17564:Apache Dubbo反序列化漏洞

code-analysisexploitationpayload-development+3
86 years ago
CVE-2018-20718 preview

CVE-2018-20718

GitHubus3r777/cve-2018-20718

Proof-of-concept exploit for CVE-2018-20718, a PHP object injection vulnerability in Pydio before 8.2.1 enabling unauthenticated remote code…

code-analysisexploitationpenetration-testing+3
37 years ago
CVE-2021-23369 preview

CVE-2021-23369

GitHubfazilbaig1/cve-2021-23369

Python exploit script for CVE-2021-23369, a Remote Code Execution vulnerability in Handlebars template engine versions before 4.7.7. Accepts a target…

code-analysisexploitationremote-access-tool+2
21 year ago
CVE-2022-40635 preview

CVE-2022-40635

GitHubmbadanoiu/cve-2022-40635

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

code-analysisexploitationremote-access-tool+2
22 years ago
CVE-2021-27651 preview

CVE-2021-27651

GitHuborangmuda/cve-2021-27651

bypass all stages of the password reset flow

authenticationcode-analysisexploitation+3
14 years ago
CVE-2020-1947 preview

CVE-2020-1947

GitHubstarkchristmas/cve-2020-1947

Proof-of-concept and analysis for CVE-2020-1947, a YAML deserialization remote code execution vulnerability in Apache ShardingSphere UI, including…

code-analysisexploitationmisconfiguration+3
16 years ago
Previous12Next