Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute preview

CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute

GitHubmbanyamer/cve-2026-25916-roundcube-webmail-dom-based-xss-exploit-via-svg-href-attribute

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

email-securityexploitationpayload-generation+3
3
7 months ago
CVE-2026-28289 preview

CVE-2026-28289

GitHub0xblackash/cve-2026-28289

CVE-2026-28289

email-securityexploitationpayload-development+3
16 months ago
CVE-2023-23397-POC preview

CVE-2023-23397-POC

GitHubp4x1s/cve-2023-23397-poc

CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。

email-securityexploitationpayload-generation+2
33 years ago
CVE-2025-30349 preview

CVE-2025-30349

GitHubnatasaka/cve-2025-30349

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

email-securityexploitationphishing-tools+2
21 year ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubth3hellion/cve-2024-21413

Python exploit for CVE-2024-21413, a Microsoft Outlook remote code execution vulnerability. Sends a crafted email via SMTP to trigger code execution…

email-securityexploitationpayload-generation+2
2 years ago
CVE-2023-23397-POC preview

CVE-2023-23397-POC

GitHubphaedrik/cve-2023-23397-poc

Two POCs I created for the CVE-2023-23397 Outlook NTLM vulnerability, to be used internally.

authenticationemail-securityexploitation+3
18 months ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtiepologian/cve-2023-23397

Proof of Concept for CVE-2023-23397 in Python

email-securityexploitationpayload-generation+3
253 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubdshabani96/cve-2024-21413

Proof-of-concept exploit for Microsoft Outlook RCE (CVE-2024-21413) with SMTP email delivery, malicious RTF attachment generation, and optional…

email-securityexploitationpayload-development+3
22 years ago
CVE-2023-51764-POC preview

CVE-2023-51764-POC

GitHubd4op/cve-2023-51764-poc

Python 3 proof-of-concept for CVE-2023-51764 SMTP smuggling vulnerability, enabling email spoofing via crafted SMTP sessions.

email-securityexploitationpayload-development+2
12 years ago
CVE-2021-34473-Exchange-ProxyShell preview

CVE-2021-34473-Exchange-ProxyShell

GitHubje6k/cve-2021-34473-exchange-proxyshell

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

email-securityexploitationpayload-generation+3
174 years ago
CVE-2023-23397-PoC preview

CVE-2023-23397-PoC

GitHubdjackreuter/cve-2023-23397-poc

C# PoC exploit for CVE-2023-23397 that sends malicious Outlook meeting invites with a UNC path trigger for NTLM credential theft.

email-securityexploitationpayload-generation+2
93 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtrackflaw/cve-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

email-securityexploitationpassword-attacks+3
1323 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubthemehackers/cve-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

email-securityexploitationpayload-generation+3
251 year ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubgrn-bogo/cve-2023-23397

Python script to create a message with the vulenrability properties set

email-securityexploitationpayload-generation+2
43 years ago
cve-2023-23397 preview

cve-2023-23397

GitHubbronzebee/cve-2023-23397

Python script for sending e-mails with CVE-2023-23397 payload using SMTP

email-securityexploitationpassword-attacks+3
143 years ago
BadOutlook preview

BadOutlook

GitHubaahmad097/badoutlook

Proof-of-concept C# tool that reads Outlook emails via COM interface, extracts base64-encoded shellcode from trigger subject lines, and executes…

command-and-controlemail-securityexploitation+3
1375 years ago