Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
172 results
cve-2011-2553 preview

cve-2011-2553

GitHubcarlosrpastrana/cve-2011-2553

Bash exploit for CVE-2011-2553 enabling remote code execution and privilege escalation on vulnerable FTP services via a special character in the USER…

ctfeducationexploitation+3
1
1 year ago
terminal-bench-2 preview

terminal-bench-2

GitHubharbor-framework/terminal-bench-2

Benchmark for evaluating AI agents on real-world tasks including vulnerability resolution, code debugging, and protein assembly in containerized…

ctfdevsecopseducation+5
4195 months ago
CVE-2024-28397-Exploit-Automation preview

CVE-2024-28397-Exploit-Automation

GitHubl1337xi/cve-2024-28397-exploit-automation

A Python automation script for exploiting the **js2py Sandbox Escape** vulnerability (CVE-2024-28397). This tool automates the payload generation and…

ctfeducationexploitation+3
210 months ago
Pwn ARM NFC preview

Pwn ARM NFC

GitLabaperikube/pwn-arm-nfc

ARM buffer overflow challenge exploiting NFC tag input on Raspberry Pi. Includes hardware assembly guide, server code, and flag retrieval for CTF and…

binary-exploitationctfeducation+3
18 years ago
exploit_laravel_cve-2018-15133 preview

exploit_laravel_cve-2018-15133

GitHubaljavier/exploit_laravel_cve-2018-15133

Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133)

ctfeducationexploitation+3
575 years ago
files preview

files

GitHubphoenhex/files

Curated repository of exploits, proof-of-concept code, and vulnerability research presentations from the phoenhex team, focused on binary…

binary-exploitationctfexploitation+3
5196 years ago
Z-Jail preview

Z-Jail

GitHubdivision-36/z-jail

A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine…

binary-analysiscontainer-securityctf+7
741 month ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubuziii2208/cve-2025-33073

Universal exploitation tool for CVE-2025-33073 targeting Windows Domain Controllers with DNSAdmins privileges and WinRM enabled.

ctfexploitationexploit-frameworks+4
6710 months ago
CVE-2024-28397 preview

CVE-2024-28397

GitHubnaclapor/cve-2024-28397

This repository contains a python exploit code for CVE-2024-28397 intended for use on the "CodePartTwo" machine on Hack The Box (HTB).

ctfeducationexploitation+3
121 year ago
Drupal_REST-RCE_Unauthenticated preview

Drupal_REST-RCE_Unauthenticated

GitHubjoaoaugustom/drupal_rest-rce_unauthenticated

This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed…

ctfeducationexploitation+3
4 months ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubcd-ratel/cve-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

ctfeducationexploitation+4
24 months ago
CVE-2026-22686 preview

CVE-2026-22686

GitHubamusedx/cve-2026-22686

CTF challenge focused on sandbox escape via source code review of a JavaScript execution environment, designed for hands-on vulnerability analysis…

ctfeducationlabs-practice+1
18 months ago
cve-2024-36401-geoserver-rce preview

cve-2024-36401-geoserver-rce

GitHubdanielegiovanardi2408/cve-2024-36401-geoserver-rce

Reproducible study of CVE-2024-36401: unauthenticated RCE in GeoServer via JXPath eval injection. Includes technical report, working…

ctfeducationexploitation+3
4 months ago
CVE-2026-30225-OliveTin-RCE preview

CVE-2026-30225-OliveTin-RCE

GitHubhackerking24/cve-2026-30225-olivetin-rce

Proof-of-concept exploit for OliveTin unauthenticated RCE (CVE-2026-30225) via insecure guest defaults and unvalidated argument types, enabling root…

ctfeducationexploitation+5
25 days ago
bordair-detector preview

bordair-detector

GitHubjosh-blythe/bordair-detector

Two-stage prompt-injection and jailbreak detector: regex gates plus a quantised DeBERTa-v3 ONNX classifier, with image, document, and audio support.…

adversarial-attackai-securitycode-analysis+5
2 months ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
92725 days ago
react2shell-lab preview

react2shell-lab

GitHubalsaut1/react2shell-lab

CVE-2025-55182 React2Shell PoC lab

code-analysisctfeducation+7
710 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubycseo-git/cve-2025-55182

a.k.a. React2Shell

code-analysiscontainer-securityctf+7
4 months ago
Previous12…10Next