Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
CVE-2024-42009-PoC preview

CVE-2024-42009-PoC

GitHubdanithehack3r/cve-2024-42009-poc

CVE-2024-42009 Proof of Concept

data-exfiltrationeducationemail-security+3
81 year ago
CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute preview

CVE-2026-25916-Roundcube-Webmail-DOM-based-XSS-Exploit-via-SVG-href-Attribute

GitHubmbanyamer/cve-2026-25916-roundcube-webmail-dom-based-xss-exploit-via-svg-href-attribute

Python exploit for Roundcube Webmail DOM-based XSS (CVE-2026-25916) via SVG href attributes, enabling session hijacking and data exfiltration through…

email-securityexploitationpayload-generation+3
38 months ago
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

data-exfiltrationemail-securityexploitation+6
1 month ago
CVE-2025-30349 preview

CVE-2025-30349

GitHubnatasaka/cve-2025-30349

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

email-securityexploitationphishing-tools+2
21 year ago
CVE-2024-37383-exploit preview

CVE-2024-37383-exploit

GitHubamirzargham/cve-2024-37383-exploit

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

data-exfiltrationemail-securityexploitation+3
1 year ago
Roundcube-CVE-2024-42008-and-CVE-2024-42010-POC preview

Roundcube-CVE-2024-42008-and-CVE-2024-42010-POC

GitHubvictoni/roundcube-cve-2024-42008-and-cve-2024-42010-poc

POC for Roundcube vulnerabilities CVE-2024-42008 and CVE-2024-42010

email-securityexploitationvulnerability-analysis+2
21 year ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubxaitax/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

email-securityexploitationinformation-gathering+5
7772 years ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubwyatu/cve-2018-8581

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

email-securityexploitationlateral-movement+4
3307 years ago
OutlookLeakTest preview

OutlookLeakTest

GitHubnccgroup/outlookleaktest

The Outlook HTML Leak Test Project

data-exfiltrationemail-securityinformation-gathering+5
1298 years ago
CVE-2020-16947 preview

CVE-2020-16947

GitHub0neb1n/cve-2020-16947

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

binary-exploitationemail-securityexploitation+3
1225 years ago
css-the-bomb-inside-your-inbox preview

css-the-bomb-inside-your-inbox

GitHubportswigger/css-the-bomb-inside-your-inbox

All the materials for Gareth Heyes' Black Hat talk: CSS: the bomb inside your inbox.

ai-securitycurated-resourcesdata-exfiltration+7
431 month ago
0dayex-checker preview

0dayex-checker

GitHubvncert-cc/0dayex-checker

Zeroday Microsoft Exchange Server checker (Virtual Patching checker)

email-securityvulnerability-scannersweb-vulnerability-scanners
694 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubthemehackers/cve-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

email-securityexploitationpayload-generation+3
251 year ago
CVE-2021-26855-PoC preview

CVE-2021-26855-PoC

GitHubsrvaccount/cve-2021-26855-poc

PoC exploit code for CVE-2021-26855

email-securityexploitationinformation-gathering+3
175 years ago
CVE-2021-33766-ProxyToken preview

CVE-2021-33766-ProxyToken

GitHubdemossl/cve-2021-33766-proxytoken

Proof-of-concept exploit for CVE-2021-33766 (ProxyToken) authentication bypass in Microsoft Exchange Server. Supports single and batch target…

email-securityexploitationpenetration-testing+2
105 years ago
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
62 days ago
OWASSRF preview

OWASSRF

GitHubcrowdstrike/owassrf
email-securityexploitationvulnerability-analysis+3
153 years ago
CVE-2021-34473-Exchange-ProxyShell preview

CVE-2021-34473-Exchange-ProxyShell

GitHubje6k/cve-2021-34473-exchange-proxyshell

对Exchange Proxyshell 做了二次修改,精确的拆分、实现辅助性安全测试。

email-securityexploitationpayload-generation+3
164 years ago
Previous123Next