Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
618 results
drupal-jsonapi-sqli-scanner preview

drupal-jsonapi-sqli-scanner

GitHubridhinva/drupal-jsonapi-sqli-scanner

Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

database-securitydata-exfiltrationexploitation+5
2
1 month ago
CVE-2025-48708 preview

CVE-2025-48708

GitHubb1tbreaker/cve-2025-48708

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

data-exfiltrationdigital-forensicsexploitation+3
51 year ago
multicat preview

multicat

GitHubdakotanelson/multicat

PoC RAT using the sneaky-creeper data exfiltration library

command-and-controldata-exfiltrationpayload-development+3
310 years ago
ztewaste preview

ztewaste

GitHubjoshatticus/ztewaste

Extract a concerning amount of user information from Unisoc ZTE devices using CVE-2022-38694.

android-securitydata-exfiltrationdigital-forensics+6
33 months ago
Rootsmart-v2.0 preview

Rootsmart-v2.0

GitHubcrackercat/rootsmart-v2.0

Android Ransomware Development - AES256 encryption + CVE-2019-2215 (reverse root shell) + Data Exfiltration

android-securitycommand-and-controldata-exfiltration+8
24 years ago
CVE-2026-42527 preview

CVE-2026-42527

GitHuboscerd/cve-2026-42527

Reproducer for CVE-2026-42527 — Apache Camel permissive default ObjectInputFilter admits java.net.URL, enabling a DNS-based out-of-band side channel

data-exfiltrationdns-analysisexploitation+3
2 months ago
Xworm RAT preview

Xworm RAT

GitLabmanturever/xworm-rat

⭐️The famous XWorm RAT, version 2.1. Educational purposes only

command-and-controlcryptographydata-exfiltration+8
33 months ago
CVE-2023-36802 preview

CVE-2023-36802

GitHubnhh9905/cve-2023-36802

Old CVE, but new way to leak everything.

binary-exploitationdata-exfiltrationexploitation+3
2 months ago
CVE-2024-42009 preview

CVE-2024-42009

GitHub0xbassiouny1337/cve-2024-42009

This script exploits a stored XSS vulnerability (CVE-2024-42009) in Roundcube Webmail version 1.6.7. It injects a malicious payload into the webmail…

data-exfiltrationeducationexploitation+3
41 year ago
CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting preview

CVE-2026-21004-SQLite-FTS3-Match-Infoleak-via-Query-Crafting

GitHubgeorge0papasotiriou/cve-2026-21004-sqlite-fts3-match-infoleak-via-query-crafting

Proof-of-concept exploit for CVE-2026-21004: uses crafted SQLite FTS3/4 MATCH prefix queries as a blind oracle to recover indexed secret data…

database-securitydata-exfiltrationexploitation+1
1 month ago
cve-2026-54316-lab preview

cve-2026-54316-lab

GitHubinertfluid/cve-2026-54316-lab

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

ctfdata-exfiltrationeducation+5
12 months ago
POC-CVE-2025-24104-Py preview

POC-CVE-2025-24104-Py

GitHubmissaels235/poc-cve-2025-24104-py

Proof-of-concept Python script demonstrating iOS file exfiltration via malicious symlink in device backup restoration, targeting the…

data-exfiltrationeducationexploitation+4
31 year ago
Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment preview

Exploiting-CVE-2021-44228-Log4Shell-in-a-Banking-Environment

GitHubtadash10/exploiting-cve-2021-44228-log4shell-in-a-banking-environment

Objective: Demonstrate the exploitation of the Log4Shell vulnerability (CVE-2021-44228) within a simulated banking application environment.

command-and-controldata-exfiltrationeducation+8
32 years ago
CVE-2026-2828-WebGPU-Cross-Origin-Pixel-Stealing-via-Timing preview

CVE-2026-2828-WebGPU-Cross-Origin-Pixel-Stealing-via-Timing

GitHubgeorge0papasotiriou/cve-2026-2828-webgpu-cross-origin-pixel-stealing-via-timing

Browser PoC demonstrating CVE-2026-2828, a WebGPU timing side-channel that leaks cross-origin iframe pixel values by measuring GPU timestamp-query…

adversarial-attackdata-exfiltrationexploitation+3
11 month ago
CVE-2026-5061 preview

CVE-2026-5061

GitHub0xmrma/cve-2026-5061

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

code-analysisdata-exfiltrationeducation+2
11 month ago
CVE-2026-56782-Gorse-Auth-Bypass preview

CVE-2026-56782-Gorse-Auth-Bypass

GitHubbiitts/cve-2026-56782-gorse-auth-bypass

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

authenticationctfdata-exfiltration+6
12 months ago
CVE-2024-33901-ProofOfConcept preview

CVE-2024-33901-ProofOfConcept

GitHubgmikisilva/cve-2024-33901-proofofconcept

Short program that demonstrates the vulnerability CVE-2024-33901 in KeePassXC version 2.7.7

data-exfiltrationdigital-forensicsexploitation+3
21 year ago
CVE-2025-9223 preview

CVE-2025-9223

GitHubnetworkkiller/cve-2025-9223

POC CVE-2025-9223

command-and-controldata-exfiltrationeducation+4
210 months ago
Previous1…313233…35Next