Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
EasySpider preview

EasySpider

GitHubnaibowang/easyspider

A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别名:ServiceWrapper面向Web应用的智能化服务封装系统。

crawlereducationscripting-automation+1
44.5k
11 days ago
p3-loader preview

p3-loader

GitHuborange-cyberdefense/p3-loader

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

binary-exploitationdefensive-toolseducation+8
2121 month ago
CVE-2022-0778 preview

CVE-2022-0778

GitHubdrago-96/cve-2022-0778

Proof-of-concept exploit for CVE-2022-0778, demonstrating an infinite loop in OpenSSL's BN_mod_sqrt via a crafted X.509 certificate with non-prime…

binary-analysiscryptographyeducation+3
1814 years ago
CVE-2023-50164-Apache-Struts-RCE preview

CVE-2023-50164-Apache-Struts-RCE

GitHubjakabakos/cve-2023-50164-apache-struts-rce

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload…

educationexploitationpayload-development+3
8610 months ago
CVE-2024-52301 preview

CVE-2024-52301

GitHubnyamort/cve-2024-52301

Proof-of-concept exploit for CVE-2024-52301 demonstrating environment manipulation in Laravel via injected URL parameters, with detailed code…

code-analysiseducationexploitation+3
211 year ago
CVE-2024-50340 preview

CVE-2024-50340

GitHubnyamort/cve-2024-50340

Proof-of-concept exploit for CVE-2024-50340 demonstrating Symfony ArgvInput environment variable injection via crafted URL query parameters, enabling…

code-analysiseducationexploitation+3
121 year ago
CVE-2014-0472 preview

CVE-2014-0472

GitHubchristasa/cve-2014-0472

Dockerized proof-of-concept exploit for CVE-2014-0472, demonstrating Django reverse() code execution via crafted URL parameters in vulnerable views.

educationexploitationpenetration-testing+2
75 years ago
CVE-2026-63766_exploit preview

CVE-2026-63766_exploit

GitHub0xdak/cve-2026-63766_exploit

Unauthenticated OS command injection exploit for GPT-SoVITS Gradio web UI. Delivers RCE via unsanitized path parameters in audio-processing helpers,…

command-and-controleducationexploitation+3
1 month ago
NSEC3-Encloser-Attack preview

NSEC3-Encloser-Attack

GitHubgoethe-universitat-cybersecurity/nsec3-encloser-attack

This project generates DNS zonefiles with custom NSEC3 parameters to reproduce and evaluate the attacks in CVE-2023-50868.

dns-analysisdns-fuzzingeducation+3
62 years ago
CVE-2026-50229 preview

CVE-2026-50229

GitHubzero-trace7/cve-2026-50229

Automated XSS scanner and proof-of-concept exploit for CVE-2026-50229 in Apache Tomcat examples. Detects and exploits reflected cross-site scripting…

educationexploitationpenetration-testing+3
1 month ago
CVE-2023-34836 preview

CVE-2023-34836

GitHubsahiloj/cve-2023-34836

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

educationpapers-researchpenetration-testing+2
16 months ago
CVE-2025-20384 preview

CVE-2025-20384

GitHubaxselll/cve-2025-20384

Proof-of-concept demonstrating log injection and poisoning in Splunk via crafted URL parameters, highlighting OWASP log injection risks.

educationexploitationlog-analysis+3
8 months ago
CVE-2018-1273 preview

CVE-2018-1273

GitHubhdgokani/cve-2018-1273

PoC for CVE-2018-1273: Spring Data Commons property binder RCE via crafted request parameters against REST endpoints. Includes vulnerable and fixed…

educationexploitationpenetration-testing+2
8 years ago
CVE-2016-10033 preview

CVE-2016-10033

GitHubalexander47777/cve-2016-10033

Proof-of-concept exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer, demonstrating injection of additional sendmail…

educationexploitationpayload-generation+3
1 year ago
CVE-2023-34537---XSS-reflected--found-in-HotelDruid-3.0.5 preview

CVE-2023-34537---XSS-reflected--found-in-HotelDruid-3.0.5

GitHubleekenghwa/cve-2023-34537---xss-reflected--found-in-hoteldruid-3.0.5

Proof-of-concept demonstrating reflected XSS vulnerabilities in HotelDruid v3.0.5, with step-by-step exploitation guide for authenticated users…

educationpenetration-testingvulnerability-analysis+2
2 years ago
cve-2020-0601-Perl preview

cve-2020-0601-Perl

GitHubthimelp/cve-2020-0601-perl

Perl version of recently published scripts to build ECC certificates with specific parameters re CVE-2020-0601

cryptographyeducationexploitation+2
6 years ago
CVE-2024-29375 preview

CVE-2024-29375

GitHubismailcemunver/cve-2024-29375

Proof-of-concept for CSV injection in Addactis IBNRS 3.10.3.107, demonstrating Excel formula injection leading to OS command execution via crafted…

educationexploitationpayload-generation+2
2 years ago
CVE-2019-0232_tomcat_cgi_exploit preview

CVE-2019-0232_tomcat_cgi_exploit

GitHubx3m1sec/cve-2019-0232_tomcat_cgi_exploit

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

educationexploitationpayload-generation+3
1 year ago
Previous123Next