Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
207 results
CVE-2026-33017 preview

CVE-2026-33017

GitHubeqstlab/cve-2026-33017

Langflow RCE

code-analysiseducationexploitation+3
1120 days ago
CVE-2025-45407 preview

CVE-2025-45407

GitHubyallasec/cve-2025-45407

CVE-2025-45407: Multiple XSS Vulnerabilities in DiscoveryNG v6.0.8 Hotfix 2 Discovered by: YallaSec Security Research Team CVE ID: CVE-2025-45407…

educationpapers-researchvulnerability-analysis+2
1 year ago
Flowise-CVE-2025-58434-PasswordReset preview

Flowise-CVE-2025-58434-PasswordReset

GitHubr3nsi15/flowise-cve-2025-58434-passwordreset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

authenticationeducationexploitation+3
14 months ago
CVE-2026-37750 preview

CVE-2026-37750

GitHubmenevarad007/cve-2026-37750

Reflected XSS proof-of-concept for School Management System 1.0, demonstrating unauthenticated JavaScript execution via the type parameter in…

educationexploitationvulnerability-analysis+2
4 months ago
CVE-2026-10104-POC preview

CVE-2026-10104-POC

GitHubravi-lk/cve-2026-10104-poc

Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated Stored Cross-Site Scripting Proof of Concept

educationexploitationpenetration-testing+3
22 months ago
CVE-2023-4911 preview

CVE-2023-4911

GitHubbaeseungwon1010/cve-2023-4911

CVE-2023-4911 (Looney Tunables) analysis report and Docker reproduction lab

binary-exploitationeducationexploitation+3
1 month ago
POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution preview

POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution

GitHubmakavellik/poc-cve-2025-24813-apache-tomcat-remote-code-execution

Este repositorio contiene un exploit automatizado desarrollado con fines educativos y de investigación en ciberseguridad, dirigido a demostrar una…

educationexploitationpayload-development+4
0 years ago
Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198- preview

Event-ID-193-Rule-Name-SOC231-Cisco-IOS-XE-Web-UI-ZeroDay-CVE-2023-20198-

GitHubahmedmansour93/event-id-193-rule-name-soc231-cisco-ios-xe-web-ui-zeroday-cve-2023-20198-

🚨 Just completed a detailed investigation for Event ID 193: "SOC231 - Cisco IOS XE Web UI ZeroDay (CVE-2023-20198)" via @LetsDefend.io. The attacker…

educationexploitationincident-response+3
1 year ago
CVE-2026-25769 preview

CVE-2026-25769

GitHub0xblackash/cve-2026-25769

CVE-2026-25769

educationexploitationincident-response+3
4 months ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
1 year ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubez4rd1x1/cve-2026-8181

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

authentication-authorizationctfeducation+5
3 months ago
cve-2026-7665 preview

cve-2026-7665

GitHubanirudhmakkar/cve-2026-7665

Proof-of-concept exploit for CVE-2026-7665, an unauthenticated information disclosure in Essential Addons for Elementor, allowing extraction of…

educationexploitationinformation-gathering+3
2 months ago
CVE-2023-6329 preview

CVE-2023-6329

GitHubitzvenom/cve-2023-6329

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

authenticationeducationexploitation+4
16 months ago
CVE-2025-65094 preview

CVE-2025-65094

GitHublukasz-rybak/cve-2025-65094

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

educationpapers-researchpenetration-testing+3
4 months ago
CVE-2026-5029-Exploit preview

CVE-2026-5029-Exploit

GitHub0x00phantom-hat/cve-2026-5029-exploit

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

code-analysiseducationexploitation+3
1 month ago
CVE-2025-66204 preview

CVE-2025-66204

GitHublukasz-rybak/cve-2025-66204

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

authenticationeducationpapers-research+3
4 months ago
gradle-static-analysis-plugin preview
Archived

gradle-static-analysis-plugin

GitHubnovoda/gradle-static-analysis-plugin

Easy setup of static analysis tools for Android and Java projects.

android-securitycode-analysisdevsecops+3
4034 years ago
CVE-2025-49113 preview

CVE-2025-49113

GitHub00xcanelo/cve-2025-49113

💥 Python Exploit for CVE-2025-49113 | Roundcube Webmail RCE via PHP Object Injection

educationexploitationpayload-development+3
81 year ago
Previous12…12Next