Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
117 results
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

data-exfiltrationexploitationinformation-gathering+3
22 days ago
SpringBreakPoC preview

SpringBreakPoC

GitHubfixyourface/springbreakpoc

PoC for SpringBreak (CVE-2017-8046)

exploitationpenetration-testingremote-access-tool+2
18 years ago
SiteCore-RCE-Detection preview

SiteCore-RCE-Detection

GitHubcrankyyash/sitecore-rce-detection

Python script to detect Sitecore Experience Platform pre-auth RCE (CVE-2021-42237) by probing vulnerable Report.ashx endpoints and analyzing HTTP…

exploitationpenetration-testingreconnaissance+2
3 years ago
CVE-2026-44578-PoC preview

CVE-2026-44578-PoC

GitHubtocong282/cve-2026-44578-poc

Proof-of-concept exploit for CVE-2026-44578, a Server-Side Request Forgery in Next.js WebSocket upgrade handler. Includes detection mode and…

cloud-securityexploitationpenetration-testing+3
3 months ago
CVE-2023-32117 preview

CVE-2023-32117

GitHubrandomrobbiebf/cve-2023-32117

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

api-security-testingexploitationinformation-gathering+3
63 years ago
CVE-2022-36804 preview

CVE-2022-36804

GitHubcoldfusionx/cve-2022-36804

Atlassian Bitbucket Server and Data Center - Command Injection Vulnerability (CVE-2022-36804)

command-and-controlexploitationinformation-gathering+3
73 years ago
CVE-2024-22243 preview

CVE-2024-22243

GitHubseanpesce/cve-2024-22243

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

code-analysisctfeducation+4
131 year ago
CVE-2023-25157 preview

CVE-2023-25157

GitHub0x2458bughunt/cve-2023-25157

Scans host lists for GeoServer endpoints vulnerable to CVE-2023-25157 SQL injection, verifies exposed paths with keyword checks, and logs confirmed…

exploitationinformation-gatheringreconnaissance+2
103 years ago
CVE-2026-47323 preview

CVE-2026-47323

GitHuboscerd/cve-2026-47323

Reproducer for CVE-2026-47323: Apache Camel CXF/Knative HeaderFilterStrategy missing inbound filtering, enabling Camel control-header injection (RCE…

educationexploitationpenetration-testing+3
1 month ago
CVE-2026-5029-Exploit preview

CVE-2026-5029-Exploit

GitHub0x00phantom-hat/cve-2026-5029-exploit

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

code-analysiseducationexploitation+3
1 month ago
Wireshark preview

Wireshark

GitHubkirkdjohnson/wireshark

Downloaded a packet capture (.pcapng) file from malware-traffic-analysis.net which was an example of an attempted attack against a webserver using…

command-and-controldigital-forensicseducation+9
32 years ago
CVE-2025-12720 preview

CVE-2025-12720

GitHubd0n601/cve-2025-12720

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

api-security-testingauthenticationexploitation+3
10 months ago
CVE-2025-55182-checker preview

CVE-2025-55182-checker

GitHubharness-security-labs/cve-2025-55182-checker

Multi-technique vulnerability detector for CVE-2025-55182 in React/Next.js applications. Tests gadget chains, RCE payloads, and WAF bypass variants…

exploitationpayload-developmentpenetration-testing+3
18 months ago
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

api-security-testingauthentication-authorizationcontainer-security+3
115 days ago
CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication preview

CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication

GitHubdylvie/cve-2026-30824-flowise-nvidia-nim-authentication

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

api-security-testingexploitationpenetration-testing+3
4 months ago
cve-2026-23550-poc preview

cve-2026-23550-poc

GitHubbaktistr/cve-2026-23550-poc

Bash-based proof-of-concept tester for CVE-2026-23550. Checks WordPress modular connector login endpoints for admin cookie issuance and verifies…

exploitationinformation-gatheringpenetration-testing+3
1 month ago
CVE-2026-48206 preview

CVE-2026-48206

GitHuboscerd/cve-2026-48206

Reproducer for CVE-2026-48206: Apache Camel camel-jira IssueKey (and other non-Camel-prefixed) header injection driving arbitrary JIRA issue…

api-security-testingeducationexploitation+3
1 month ago
CVE-2018-15133 preview

CVE-2018-15133

GitHubazharikun/cve-2018-15133

Exploit tool for CVE-2018-15133, a Laravel unserialize RCE, with multiprocessing support for scanning and exploiting vulnerable endpoints.

exploitationpayload-developmentpenetration-testing+2
35 years ago
Previous1234567Next