Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
741 results
CVE-2009-0182 preview

CVE-2009-0182

GitHubnobodyatall648/cve-2009-0182

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

binary-exploitationeducationexploitation+3
5 years ago
CVE-2018-6905 preview

CVE-2018-6905

GitHubdnr6419/cve-2018-6905

Step-by-step reproduction environment for CVE-2018-6905, a stored XSS vulnerability in TYPO3 install.php, with Docker setup and payload execution…

educationexploitationpenetration-testing+2
5 years ago
Neton preview

Neton

GitHubaetsu/neton

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

educationinformation-gatheringmalware-analysis+1
1003 years ago
syncord preview

syncord

GitHubkrishsharma0413/syncord

Syncord is a CLI-based file synchronization and storage tool that uses Discord as an encrypted file storage.

cloud-securitydata-exfiltrationeducation+3
88 months ago
CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload preview

CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload

GitHubh4x0r-dz/cve-2025-64095---dnn-unauthenticated-arbitrary-file-upload

POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

educationexploitationpenetration-testing+2
1410 months ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubozcanpng/cve-2024-9264

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

command-and-controleducationexploitation+3
1 month ago
CVE-2025-66676 preview

CVE-2025-66676

GitHubcwjchoi01/cve-2025-66676

Proof-of-concept exploit for CVE-2025-66676 demonstrating arbitrary process termination via IOBit Unlocker kernel driver, with checksum bypass…

binary-exploitationeducationexploitation+2
36 months ago
CVE-2023-50164-HTB-strutted preview

CVE-2023-50164-HTB-strutted

GitHubmkirahmet/cve-2023-50164-htb-strutted

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use…

ctfeducationexploitation+3
11 months ago
CVE-2025-46157 preview

CVE-2025-46157

GitHubmorphine009/cve-2025-46157

Proof-of-concept exploit for CVE-2025-46157: Remote code execution via insecure file upload in Timetrax V1 Attendance module, with EfsPotato-based…

educationexploitationpayload-development+4
11 year ago
CVE-2017-1000117 preview

CVE-2017-1000117

GitHubsiling2017/cve-2017-1000117

Proof-of-concept exploit for CVE-2017-1000117 (Git SSH command injection) that writes command output to a web-accessible file. Part of VulApps…

educationexploitationlabs-practice+2
8 years ago
CVE-2024-10586-Poc preview

CVE-2024-10586-Poc

GitHubnxploited/cve-2024-10586-poc

Proof-of-concept exploit for CVE-2024-10586 targeting WordPress Debug Tool plugin. Automates arbitrary file upload leading to remote code execution…

educationexploitationpayload-generation+3
1 year ago
CVE-2025-8081-Elementor preview

CVE-2025-8081-Elementor

GitHublyesh4ck/cve-2025-8081-elementor

Proof-of-concept exploit for CVE-2025-8081, an arbitrary file read in Elementor WordPress plugin, allowing authenticated admins to read sensitive…

educationexploitationpenetration-testing+2
10 months ago
CVE-2008-2992 preview

CVE-2008-2992

GitHubjonas-holmberg/cve-2008-2992

Writeup och POC för CVE-2008-2992

educationexploitationlabs-practice+3
4 months ago
CVE-2020-29607 preview

CVE-2020-29607

GitHubalienfader/cve-2020-29607

Python exploit for CVE-2020-29607 that bypasses file upload restrictions in Pluck CMS to upload a PHP webshell, enabling remote command execution on…

educationexploitationpenetration-testing+2
1 year ago
CVE-2023-38831_Exploit preview

CVE-2023-38831_Exploit

GitHubvictoriousknight/cve-2023-38831_exploit

Python script that generates a malicious RAR file exploiting CVE-2023-38831 to execute a reverse shell payload, intended for educational and ethical…

binary-exploitationeducationexploitation+3
1 year ago
InfectPE preview

InfectPE

GitHubsecrary/infectpe

InfectPE - Inject custom code into PE file [This project is not maintained anymore]

binary-analysiseducationmalware-analysis+1
3249 years ago
CVE-2021-40444--CABless preview

CVE-2021-40444--CABless

GitHubedubr2020/cve-2021-40444--cabless

Modified code so that we don´t need to rely on CAB archives

educationexploitationpapers-research+2
1044 years ago
CVE-2022-2588 preview

CVE-2022-2588

GitHubbassamgraini/cve-2022-2588

Educational exploit for CVE-2022-2588, a Linux kernel race condition leading to privilege escalation. Includes Vagrant setup for a vulnerable machine…

binary-exploitationeducationexploitation+3
123 years ago
Previous1234…42Next