Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
207 results
CVE-2025-50461 preview

CVE-2025-50461

GitHubanchor0221/cve-2025-50461

Technical Details and Exploit for CVE-2025-50461

binary-exploitationeducationexploitation+3
1 year ago
CVE-2024-43425-Poc preview

CVE-2024-43425-Poc

GitHubaninfosec/cve-2024-43425-poc

Proof-of-concept exploit for Moodle CVE-2024-43425, enabling authenticated RCE via crafted calculated questions. Automates login, token extraction,…

educationexploitationpayload-development+3
1 year ago
CVE-2022-22980 preview

CVE-2022-22980

GitHubeliasdekiniweek/cve-2022-22980

Exploitation de CVE-2022-22980

command-and-controlctfeducation+3
16 months ago
Erlang-OTP-SSH-CVE-2025-32433 preview

Erlang-OTP-SSH-CVE-2025-32433

GitHubbilalz5-github/erlang-otp-ssh-cve-2025-32433

CVE-2025-32433 – Erlang/OTP SSH vulnerability allowing pre-auth RCE

educationexploitationpenetration-testing+2
11 year ago
CVE-2025-68400 preview

CVE-2025-68400

GitHublukasz-rybak/cve-2025-68400

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

database-securityeducationexploitation+3
4 months ago
Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit preview

Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit

GitHub0x00phantom-hat/hoverfly-1.11.3-rce-cve-2025-54123-exploit

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

command-and-controleducationexploitation+6
13 months ago
bola-CVE-2023-27524 preview

bola-CVE-2023-27524

GitHubrachidafaf/bola-cve-2023-27524

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

api-security-testingauthentication-authorizationeducation+3
5 months ago
CVE-2026-44963 preview

CVE-2026-44963

GitHubsentinelxofficial/cve-2026-44963

Detection scripts, patch checker & hardening guide for CVE-2026-44963 (Veeam B&R RCE)

educationexploitationincident-response+4
42 months ago
CVE-2026-8793 preview

CVE-2026-8793

GitHubh4zaz/cve-2026-8793

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

authenticationeducationexploitation+4
24 days ago
CVE-2026-10104-POC preview

CVE-2026-10104-POC

GitHubravi-lk/cve-2026-10104-poc

Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated Stored Cross-Site Scripting Proof of Concept

educationexploitationpenetration-testing+3
22 months ago
CVE-2024-44902-env preview

CVE-2024-44902-env

GitHubkre80r/cve-2024-44902-env

Vulnerable ThinkPHP 8.0.4 test environment for CVE-2024-44902 nuclei template validation

educationexploitationlabs-practice+3
9 months ago
CVE-2024-0368 preview

CVE-2024-0368

GitHubrandomrobbiebf/cve-2024-0368

Hustle Plugin <= 7.8.3 contains hardcoded HubSpot API credentials in inc/providers/hubspot/hustle-hubspot-api.php

educationexploitationinformation-gathering+3
18 months ago
3007Project preview

3007Project

GitHubtimon-l/3007project

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

binary-analysiscode-analysiseducation+2
3 years ago
CVE-2026-23003-Cross-Chain-Bridge-Message-Forging-via-Missing-Origin-Chain-ID preview

CVE-2026-23003-Cross-Chain-Bridge-Message-Forging-via-Missing-Origin-Chain-ID

GitHubgeorge0papasotiriou/cve-2026-23003-cross-chain-bridge-message-forging-via-missing-origin-chain-id

Cross-chain bridge PoC for CVE-2026-23003: demonstrates message forging via missing origin chain ID using vulnerable Solidity contract and Python…

adversarial-attackeducationexploitation+1
1 month ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubez4rd1x1/cve-2026-8181

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

authentication-authorizationctfeducation+5
3 months ago
CVE-2023-27524-POC preview

CVE-2023-27524-POC

GitHubmaanvader/cve-2023-27524-poc

A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

authentication-authorizationeducationexploitation+3
3 years ago
CVE-2025-32433-PoC preview

CVE-2025-32433-PoC

GitHubniteeshpujari/cve-2025-32433-poc

Proof-of-concept exploit for CVE-2025-32433, enabling unauthenticated remote code execution in Erlang/OTP SSH. Includes Docker setup and reverse…

ctfeducationexploitation+3
71 year ago
CVE-2026-24418 preview

CVE-2026-24418

GitHubbridgeralderson/cve-2026-24418

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…

database-securityeducationexploitation+5
22 months ago
Previous123…12Next