Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
mip22 preview

mip22

GitHubmakdosx/mip22

Advanced phishing framework with 83 pre-built cloned websites, manual site cloning, URL masking, and real-time credential capture with audio…

educationphishingphishing-tools+1
6934 years ago
CVE-2024-52301 preview

CVE-2024-52301

GitHubnyamort/cve-2024-52301

Proof-of-concept exploit for CVE-2024-52301 demonstrating environment manipulation in Laravel via injected URL parameters, with detailed code…

code-analysiseducationexploitation+3
211 year ago
CVE-2014-0472 preview

CVE-2014-0472

GitHubchristasa/cve-2014-0472

Dockerized proof-of-concept exploit for CVE-2014-0472, demonstrating Django reverse() code execution via crafted URL parameters in vulnerable views.

educationexploitationpenetration-testing+2
75 years ago
DrupalCVE-2018-7602 preview

DrupalCVE-2018-7602

GitHubcyberharsh/drupalcve-2018-7602

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

code-analysiseducationexploitation+3
16 years ago
CVE-2024-50340 preview

CVE-2024-50340

GitHubnyamort/cve-2024-50340

Proof-of-concept exploit for CVE-2024-50340 demonstrating Symfony ArgvInput environment variable injection via crafted URL query parameters, enabling…

code-analysiseducationexploitation+3
121 year ago
CVE-2023-24329-lab preview

CVE-2023-24329-lab

GitHubjithinodattu/cve-2023-24329-lab

Self-contained Docker lab demonstrating CVE-2023-24329, a Python urllib parser differential that bypasses URL scheme and host filters, with…

ctfeducationexploitation+4
5 months ago
CVE-2023-25157-checker preview

CVE-2023-25157-checker

GitHub7imbitz/cve-2023-25157-checker

A script, written in golang. POC for CVE-2023-25157

educationexploitationpenetration-testing+2
32 years ago
CVE-2023-30212 preview

CVE-2023-30212

GitHubaash035/cve-2023-30212

Docker-based vulnerable OURPHP lab for reproducing CVE-2023-30212, a reflected XSS vulnerability, with setup instructions and proof-of-concept…

container-securityeducationlabs-practice+2
3 years ago
CVE-2024-34361-Pi-Hole-SSRF-to-RCE preview

CVE-2024-34361-Pi-Hole-SSRF-to-RCE

GitHubt0x1cx/cve-2024-34361-pi-hole-ssrf-to-rce

This repository contains an exploit for CVE-2024-34361, a critical Pi-hole vulnerability (CVSS 8.6). It uses SSRF to achieve RCE by exploiting…

educationexploitationpenetration-testing+3
11 month ago
CVE-2026-40176 preview

CVE-2026-40176

GitHubikarolaborda/cve-2026-40176

Differential proof-of-concept for CVE-2026-40176, demonstrating OS command injection in Composer's Perforce driver via a malicious repository URL,…

command-and-controleducationexploitation+3
3 months ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubjoapath/cve-2021-42013

Proof-of-concept exploit for CVE-2021-42013, demonstrating path traversal and remote code execution on Apache 2.4.50 via double URL encoding bypass…

educationexploitationpayload-generation+3
3 months ago
CVE-2025-60656 preview

CVE-2025-60656

GitHubdotadrien/cve-2025-60656

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

educationpapers-researchvulnerability-analysis+2
8 months ago
CVE-2022-25581 preview

CVE-2022-25581

GitHubwooluo/cve-2022-25581

Python exploit script for CVE-2022-25581 (ClassCMS 2.4 arbitrary file download) that automates login, CSRF token extraction, malicious zip upload…

educationexploitationpayload-development+3
1 year ago
Follina_MSDT_CVE-2022-30190 preview

Follina_MSDT_CVE-2022-30190

GitHubmuhammad-ali007/follina_msdt_cve-2022-30190

Educational exploit for CVE-2022-30190 (Follina) demonstrating MSDT remote code execution via malicious Office documents, with detection and…

command-and-controldefensive-toolseducation+8
13 years ago
iGoat-Swift preview

iGoat-Swift

GitHubowasp/igoat-swift

OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS

ctfeducationios-security+6
4559 months ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1132 years ago
cve-2026-87902-wordpress-lfi-lab preview

cve-2026-87902-wordpress-lfi-lab

GitHubdinosn/cve-2026-87902-wordpress-lfi-lab

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional…

educationexploitationlabs-practice+7
1318 days ago
CVE-2020-8825 preview

CVE-2020-8825

GitHubhacky1997/cve-2020-8825

Proof-of-concept exploit for stored XSS vulnerability in VanillaForum 2.6.3, demonstrating arbitrary HTML/script injection via insufficient input…

educationpenetration-testingphishing-tools+2
34 years ago
Previous123456Next