Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
352 results
Microsoft-Edge-Information-Disclosure preview

Microsoft-Edge-Information-Disclosure

GitHubabsholi7ly/microsoft-edge-information-disclosure

CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

data-exfiltrationexploitationinformation-gathering+3
17
2 years ago
CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD preview

CVE-2017-18345-COM_JOOMANAGER-ARBITRARY-FILE-DOWNLOAD

GitHubluth1er/cve-2017-18345-com_joomanager-arbitrary-file-download

The Joomanager component through 2.0.0 for Joomla! has an Arbitrary File Download issue, resulting in exposing the Credentials of the DataBase.

data-exfiltrationexploitationinformation-gathering+3
77 years ago
CVE-2021-26837 preview

CVE-2021-26837

GitHubl0lsec/cve-2021-26837

CVE-2021-26837 - SQL Injection in the SearchTextbox parameter of HelpSystems/Fortra DeliverNow. Payloads, annotated requests, and evidence. Fixed in…

data-exfiltrationexploitationpenetration-testing+2
27 days ago
CVE-2026-43700 preview

CVE-2026-43700

GitHubdem0ns/cve-2026-43700

Safari 跨域读取视频

data-exfiltrationexploitationinformation-gathering+2
1 month ago
CVE-2026-39363 preview

CVE-2026-39363

GitHubsunynov/cve-2026-39363

方便实用的CVE-2026-39363利用工具

data-exfiltrationexploitationpenetration-testing+2
16 days ago
CVE-2026-63563 preview

CVE-2026-63563

GitHubredr0nin/cve-2026-63563

Unauthenticated Address Book Modification on Sharp MX/BP Multifunction Printers

data-exfiltrationexploitationhardware-iot-security+3
20 days ago
CVE-2026-60004 preview

CVE-2026-60004

GitHubshinthink/cve-2026-60004

CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

data-exfiltrationexploitationpenetration-testing+4
17 days ago
flowise-arbitrary-file-read-getFileFromStorage preview

flowise-arbitrary-file-read-getFileFromStorage

GitHubmajpuv/flowise-arbitrary-file-read-getfilefromstorage

Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path…

data-exfiltrationexploitationinformation-gathering+4
17 days ago
CVE-2025-10897 preview

CVE-2025-10897

GitHuberror-inside/cve-2025-10897

WooCommerce Designer Pro <= 1.9.28 - Unauthenticated Arbitrary File Read

data-exfiltrationexploitationinformation-gathering+4
19 days ago
CVE-2026-52886 preview

CVE-2026-52886

GitHubv3s9er/cve-2026-52886

Notepad++ CVE-2026-52886 — session.xml backupFilePath starts_with() path traversal (GHSA-rqfm-pw34-r7j6)

data-exfiltrationexploitationvulnerability-analysis
7 days ago
CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento preview

CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento

GitHubjakabakos/cve-2024-34102-cosmicsting-xxe-in-adobe-commerce-and-magento

CosmicSting: critical unauthenticated XXE vulnerability in Adobe Commerce and Magento (CVE-2024-34102)

data-exfiltrationexploitationinformation-gathering+3
92 years ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951
data-exfiltrationexploitationinformation-gathering+3
9 days ago
CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection preview

CVE-2026-9997-VPN-Split-Tunneling-Bypass-via-DHCP-Option-Injection

GitHubgeorge0papasotiriou/cve-2026-9997-vpn-split-tunneling-bypass-via-dhcp-option-injection
data-exfiltrationexploitationnetwork-security+3
18 days ago
CVE-2024-52806-PoC preview

CVE-2024-52806-PoC

GitHubheartlesseorg-dot/cve-2024-52806-poc
data-exfiltrationexploitationvulnerability-analysis+2
8 days ago
exploit-CVE-2022-0482 preview

exploit-CVE-2022-0482

GitHubacceis/exploit-cve-2022-0482

Easy!Appointments < 1.4.3 - Unauthenticated PII (events) disclosure

data-exfiltrationexploitationinformation-gathering+3
34 years ago
glpi-logbleed preview

glpi-logbleed

GitHub5kr1pt/glpi-logbleed

PoC for CVE-2026-53629, blind SQL injection in the GLPI history log filter

data-exfiltrationexploitationpenetration-testing+2
124 days ago
CVE-2025-48932-Invision-Community-SQLi-Exploit preview

CVE-2025-48932-Invision-Community-SQLi-Exploit

GitHubcerberusmrxi/cve-2025-48932-invision-community-sqli-exploit

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

data-exfiltrationexploitationinformation-gathering+6
118 days ago
CVE-2024-48914 preview

CVE-2024-48914

GitHubeqstlab/cve-2024-48914

Arbitrary File Read and DoS in vendure-ecommerce exploit

data-exfiltrationexploitationinformation-gathering+3
51 year ago
Previous1…17181920Next