Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
cve-2025-4664 preview

cve-2025-4664

GitHubamalmurali47/cve-2025-4664

PoC and Setup for CVE-2025-4664

educationexploitationinformation-gathering+3
41 year ago
CVE-2026-10290-SQLI preview

CVE-2026-10290-SQLI

GitHubxmyronn/cve-2026-10290-sqli

Proof-of-concept for unauthenticated SQL injection in Hotel and Tourism Reservation System 1.0, demonstrating database extraction via the tour…

database-securityeducationexploitation+3
4 months ago
CVE-2025-64458-Demo preview

CVE-2025-64458-Demo

GitHubch4n3-yoon/cve-2025-64458-demo

A PoC script for demonstrating CVE 2025-64458, found in Django, potential DoS in `HttpResponseRedirect`/`HttpResponsePermanentRedirect` on Windows.

educationexploitationpenetration-testing+2
11 months ago
CVE-2018-7600-Remote-Code-Execution preview

CVE-2018-7600-Remote-Code-Execution

GitHubrajaabdullahnasir/cve-2018-7600-remote-code-execution

This repository contains a completely original and self-developed Proof-of-Concept (PoC) for CVE-2018-7600, also known as Drupalgeddon 2 — a critical…

educationexploitationpayload-generation+3
1 year ago
CVE-2019-9978-Social-Warfare-WordPress-Plugin-RCE preview

CVE-2019-9978-Social-Warfare-WordPress-Plugin-RCE

GitHubhousma/cve-2019-9978-social-warfare-wordpress-plugin-rce

The `swp_debug` parameter in `admin-post.php` allows remote attackers to include external files containing malicious PHP code, which are evaluated on…

educationexploitationpayload-generation+5
1 year ago
CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE preview

CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50365_csrf_delete_category-phpgurukul-cve

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

ctfeducationexploitation+3
1 year ago
BSCP-EXAM-GUIDE-BY-N3OARI-2026 preview

BSCP-EXAM-GUIDE-BY-N3OARI-2026

GitHubn3oari/bscp-exam-guide-by-n3oari-2026

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

curated-resourceseducationlabs-practice+3
342 months ago
CVE-2021-35042 preview

CVE-2021-35042

GitHubyougina/cve-2021-35042

SQL injection via unsanitized QuerySet.order_by() input

educationlabs-practicepenetration-testing+2
135 years ago
CVE-2022-28346 preview

CVE-2022-28346

GitHubyougina/cve-2022-28346

SQL injection in QuerySet.annotate(), aggregate(), and extra()

educationlabs-practicepenetration-testing+2
24 years ago
CVE-2020-7471 preview

CVE-2020-7471

GitHubmrlihd/cve-2020-7471

Reproduce CVE-2020-7471

database-securityeducationexploitation+2
5 years ago
CVE-2024-22243 preview

CVE-2024-22243

GitHubseanpesce/cve-2024-22243

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

code-analysisctfeducation+4
131 year ago
kafka-keycloak-oauth preview

kafka-keycloak-oauth

GitHuboriolrius/kafka-keycloak-oauth

Apache Kafka 4.1.0 (KRaft) with Keycloak OAuth2 authentication using Strimzi - bypasses CVE-2025-27817 URL allowlist restriction

authenticationcloud-infrastructure-securityconfiguration-auditing+3
50 years ago
day04-nexus-4956 preview

day04-nexus-4956

GitHubamalpvatayam67/day04-nexus-4956

Nexus Repository 3 Path Traversal (CVE-2024-4956)

container-securityeducationexploitation+3
1 year ago
url-cheatsheet-data preview

url-cheatsheet-data

GitHubportswigger/url-cheatsheet-data

This is the data that powers the PortSwigger URL validation bypass cheat sheet.

curated-resourceseducationvulnerability-analysis+2
648 months ago
CVE-2022-46080 preview

CVE-2022-46080

GitHubgeniuszly/cve-2022-46080

it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port,…

educationexploitationpenetration-testing+3
82 years ago
CVE-2021-26832 preview

CVE-2021-26832

GitHubgal-nagli/cve-2021-26832

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…

educationpapers-researchvulnerability-analysis+2
55 years ago
SPY-MASKER preview

SPY-MASKER

GitHubanupam2808/spy-masker

It is a simple Python Script to hide phishing URL under a normal looking URL (google.com or facebook.com). It can be integrated into Phishing tools…

educationphishingphishing-tools+1
42 years ago
CVE-2026-2020-SSRF-via-URL-Parser-Differential preview

CVE-2026-2020-SSRF-via-URL-Parser-Differential

GitHubgeorge0papasotiriou/cve-2026-2020-ssrf-via-url-parser-differential

Demonstrates SSRF exploitation via URL parser differential between urllib.parse and requests, including vulnerable service and PoC exploit script.

educationexploitationpenetration-testing+3
2 months ago
Previous123456Next