Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
SGLang-0.5.9-RCE preview

SGLang-0.5.9-RCE

GitHubstuub/sglang-0.5.9-rce

Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF

code-analysisctfeducation+5
5
4 months ago
CVE-2022-46169 preview

CVE-2022-46169

GitHubnou-man/cve-2022-46169

Proof of concept / CTF script for exploiting CVE-2022-46169 in Cacti, versions >=1.2.22

ctfexploitationpayload-generation+3
3 years ago
AutoPwn-Titanic.htb preview

AutoPwn-Titanic.htb

GitHubmaikneysm/autopwn-titanic.htb

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

ctfexploitationinformation-gathering+5
1 year ago
php-8.1.0-dev-exploit preview

php-8.1.0-dev-exploit

GitHubuseru1k/php-8.1.0-dev-exploit

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)

ctfexploitationpayload-generation+3
10 months ago
CVE-2024-24590 preview

CVE-2024-24590

GitHubj3r1ch0123/cve-2024-24590

Created this exploit for the Hack The Box machine, Blurry.

ctfexploitationpayload-generation+3
1 year ago
CVE-2023-30547 preview

CVE-2023-30547

GitHubuser0x1337/cve-2023-30547

PoC to CVE-2023-30547 (Library vm2)

ctfexploitationpayload-generation+3
2 years ago
CVE-2024-23346-exploit preview

CVE-2024-23346-exploit

GitHubdavidaroca27/cve-2024-23346-exploit

This is a exploit for the known Remote Code Execution (RCE) vulnerability in the `pymatgen` (CVE-2024-23346) Python library by uploading a malicious…

ctfexploitationpayload-generation+3
41 year ago
GDA-android-reversing-Tool preview

GDA-android-reversing-Tool

GitHubcharles2gan/gda-android-reversing-tool

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

android-securityctfdynamic-analysis-sandboxing+9
4.8k5 months ago
rogue-jndi preview

rogue-jndi

GitHubveracode-research/rogue-jndi

A malicious LDAP server for JNDI injection attacks

ctfeducationexploitation+4
1.1k2 years ago
CVE-2023-50164 preview

CVE-2023-50164

GitHubpixel-defaultbr/cve-2023-50164

Educational exploit for CVE-2023-50164 (Apache Struts 2) demonstrating path traversal and remote code execution via malicious file upload, designed…

ctfeducationexploitation+3
11 year ago
demo-CVE-2021-29447-lezione preview

demo-CVE-2021-29447-lezione

GitHubspecializzazione-cyber-security/demo-cve-2021-29447-lezione

Proof-of-concept exploit for CVE-2021-29447, an authenticated XXE vulnerability in WordPress 5.6-5.7. Includes lab setup, malicious WAV generation,…

ctfeducationexploitation+3
1 year ago
CVE-2024-23724 preview

CVE-2024-23724

GitHubyoussefdds/cve-2024-23724

Proof-of-concept exploit for CVE-2024-23724 in Ghost CMS, demonstrating privilege escalation via malicious SVG profile image upload.

ctfeducationexploitation+3
1 year ago
dejavu preview

dejavu

GitHubbattleofthebots/dejavu

Challenge based on CVE-2021-22204 where users send a malicious file to a web application to gain RCE

ctfeducationexploitation+3
2 years ago
Security-Datasets preview

Security-Datasets

GitHubotrf/security-datasets

Re-play Security Events

ctfcurated-resourcesdigital-forensics+4
1.8k2 years ago
CVE-2025-39601 preview

CVE-2025-39601

GitHubnxploited/cve-2025-39601

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

ctfeducationexploitation+3
11 year ago
CVE-2022-30190-Analysis-With-LetsDefends-Lab preview

CVE-2022-30190-Analysis-With-LetsDefends-Lab

GitHubabdibimantara/cve-2022-30190-analysis-with-letsdefends-lab

this is my simple article about CVE 2022-30190 (Follina) analysis. I use the lab from Letsdefend.

ctfeducationexploitation+3
4 years ago
CVE-2023-33733-Exploit-PoC preview

CVE-2023-33733-Exploit-PoC

GitHubl41kaa/cve-2023-33733-exploit-poc

Python exploit script for CVE-2023-33733 targeting web applications. Automates authentication, session extraction, and reverse shell delivery for…

ctfexploitationpayload-generation+3
32 years ago
CVE-2025-4138_tarfile_filter_bypass preview

CVE-2025-4138_tarfile_filter_bypass

GitHubthefizzyfish/cve-2025-4138_tarfile_filter_bypass

CVE-2025-4138 - Python Arbitrary file write outside extraction directory

ctfexploitationpayload-generation+3
36 months ago
Previous12Next