Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
CVE-2023-28467 preview

CVE-2023-28467

GitHubahmetaltuntas/cve-2023-28467

Proof-of-concept for a persistent XSS vulnerability in MyBB 1.8.33 User CP, allowing authenticated users to inject HTML via the email field, with…

ctfeducationpenetration-testing+2
4
3 years ago
CVE-2023-37191 preview

CVE-2023-37191

GitHubsahiloj/cve-2023-37191

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel PBX version 4.0.0-6. This allows an authenticated attacker to inject arbitrary…

educationexploitationpenetration-testing+3
17 months ago
Below-Logger-Symlink-Attack_CVE-2025-27591 preview

Below-Logger-Symlink-Attack_CVE-2025-27591

GitHub0xdtc/below-logger-symlink-attack_cve-2025-27591

A Bash-based privilege escalation exploit targeting the `below` system performance monitoring tool. This refurbished exploit leverages a symlink…

binary-exploitationeducationexploitation+3
210 months ago
CVE-2025-63307 preview

CVE-2025-63307

GitHubtheethat-thamwasin/cve-2025-63307

An authenticated Stored Cross-site Scripting (XSS) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file…

educationexploitationpenetration-testing+3
110 months ago
Gitea-Git-Hooks-RCE-CVE-2020-14144- preview

Gitea-Git-Hooks-RCE-CVE-2020-14144-

GitHubmohnad-al-saif/gitea-git-hooks-rce-cve-2020-14144-

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

educationexploitationpayload-development+3
7 months ago
CVE-2025-27591-Below preview

CVE-2025-27591-Below

GitHubthekin-ctrl/cve-2025-27591-below

Proof-of-concept exploit for CVE-2025-27591, a local privilege escalation in the 'below' system monitor. Demonstrates symlink attack on log file to…

educationexploitationpenetration-testing+2
1 year ago
CVE-2025-56771 preview

CVE-2025-56771

GitHubrrespxwnss/cve-2025-56771

During analysis of the ecodotempo.com.br website, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…

educationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-56772 preview

CVE-2025-56772

GitHubrrespxwnss/cve-2025-56772

During the analysis of the website ecodotempo.com.br, a Stored Cross-Site Scripting (XSS) vulnerability was discovered. This vulnerability allows an…

educationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2024-51032 preview

CVE-2024-51032

GitHubshree-chandragiri/cve-2024-51032

A Cross-site Scripting (XSS) vulnerability in manage_recipient.php of Sourcecodester Toll Tax Management System 1.0 allows remote authenticated users…

educationpenetration-testingvulnerability-analysis+2
1 year ago
CmdLineSpoofer preview

CmdLineSpoofer

GitHubplackyhacker/cmdlinespoofer

How to spoof the command line when spawning a new process from C#.

command-and-controleducationexploitation+5
1114 years ago
proftpd-CVE-2026-42167-poc preview

proftpd-CVE-2026-42167-poc

GitHubzeropathai/proftpd-cve-2026-42167-poc

POCs to demonstrate CVE-2026-42167 in ProFTPD

authentication-authorizationdatabase-securityeducation+6
244 months ago
phpipam_1.4.4 preview

phpipam_1.4.4

GitHubhadrian3689/phpipam_1.4.4

Exploit script for CVE-2022-23046 SQL injection in phpIPAM 1.4.4. Allows authenticated admin users to extract database info, read files, and write to…

educationexploitationpenetration-testing+2
4 years ago
cve-2025-66398 preview

cve-2025-66398

GitHubjoshuavanderpoll/cve-2025-66398

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

command-and-controleducationexploitation+7
36 months ago
bitbucket-test preview

bitbucket-test

GitHubjohangabrielson/bitbucket-test

Investigating CVE-2022-36804

educationexploitationlabs-practice+3
5 months ago
CVE-2019-6690-python-gnupg-vulnerability preview

CVE-2019-6690-python-gnupg-vulnerability

GitHubstigtsp/cve-2019-6690-python-gnupg-vulnerability

Proof-of-concept exploit for CVE-2019-6690, demonstrating input validation bypass in python-gnupg symmetric encryption via newline injection in…

cryptographyctfeducation+3
17 years ago
CVE-2021-20717 preview

CVE-2021-20717

GitHubs-index/cve-2021-20717

CVE-2021-20717-EC-CUBE-XSS

educationexploitationpenetration-testing+3
15 years ago
CVE-2025-67730 preview

CVE-2025-67730

GitHubdharan10/cve-2025-67730

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

educationpapers-researchvulnerability-analysis+2
8 months ago
CVE-2025-12163 preview

CVE-2025-12163

GitHubsnailsploit/cve-2025-12163

CVE-2025-12163: Stored Cross-Site Scripting in Omnipress WordPress Plugin

educationpapers-researchvulnerability-analysis+2
4 months ago
Previous12Next