Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
qyvora-toha3ee preview

qyvora-toha3ee

GitHubqyvora/qyvora-toha3ee

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

exploitationnetwork-securityosint+9
4
2 days ago
SdoKeyCrypt-sys-local-privilege-elevation preview

SdoKeyCrypt-sys-local-privilege-elevation

GitHubhypersine/sdokeycrypt-sys-local-privilege-elevation

CVE-2019-9729. Transferred from https://github.com/DoubleLabyrinth/SdoKeyCrypt-sys-local-privilege-elevation

binary-exploitationexploitationprivilege-escalation+2
847 years ago
audit-xss-cve-2020-7934 preview

audit-xss-cve-2020-7934

GitHubgiardinas-dev/audit-xss-cve-2020-7934

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

ctfeducationexploitation+3
4 years ago
pegasus-neo preview

pegasus-neo

GitHubsobri3195/pegasus-neo

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

exploitationforensicsosint+9
1287 months ago
CVE-2024-57175 preview

CVE-2024-57175

GitHubajmal101/cve-2024-57175

Stored XSS proof-of-concept for PHPGURUKUL Online Birth Certificate System v1.0, demonstrating authenticated JavaScript injection via profile name…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
vuln-chm-hijack preview

vuln-chm-hijack

GitHubyasinyilmaz/vuln-chm-hijack

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

educationexploitationlabs-practice+3
77 years ago
reaver-wps-fork-t6x preview

reaver-wps-fork-t6x

GitHubt6x/reaver-wps-fork-t6x

Brute-force attack tool against WPS registrar PINs to recover WPA/WPA2 passphrases, supporting online brute force and offline Pixie Dust attacks on…

exploitationpassword-attackswi-fi-auditing+1
2.0k11 months ago
CVE-2021-42666 preview

CVE-2021-42666

GitHub0xdeku/cve-2021-42666

CVE-2021-42666 - SQL Injection vulnerability in the Engineers online portal system.

database-securityexploitationinformation-gathering+3
4 years ago
shellcide preview

shellcide

GitHubzer0x64/shellcide

Shellcode IDE

binary-analysisdebuggerseducation+6
154 months ago
tricorne preview

tricorne

GitHubcrussella0129/tricorne

a Fedora remix focused on pentesting and purple hat tooling

defensive-toolsexploitationforensics+8
55 months ago
CVE-2026-77276-PoC preview

CVE-2026-77276-PoC

GitHubmorzan6/cve-2026-77276-poc

CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online

exploitationpenetration-testingred-teaming+2
1 month ago
ds3-nrssr-rce preview

ds3-nrssr-rce

GitHubtremwil/ds3-nrssr-rce

Documentation and proof of concept code for CVE-2022-24125 and CVE-2022-24126.

binary-exploitationeducationexploitation+8
1694 years ago
CVE-2021-42667 preview

CVE-2021-42667

GitHub0xdeku/cve-2021-42667

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

database-securityexploitationinformation-gathering+3
24 years ago
exploitation-course preview

exploitation-course

GitHubashemery/exploitation-course

Offensive Software Exploitation Course

binary-exploitationeducationexploitation+7
2.5k3 years ago
C2-Pwn preview

C2-Pwn

GitHublukebob-zz/c2-pwn

Uses Shodan API to pull down C2 servers to run known exploits on them.

command-and-controlexploitationosint+3
198 years ago
CVE-2024-27115-Exploit preview

CVE-2024-27115-Exploit

GitHubtheexploiters/cve-2024-27115-exploit

Exploit For SOPlanning 1.52.01 (Simple Online Planning Tool) - Remote Code Execution (RCE) (Authenticated)

exploitationpayload-developmentpenetration-testing+2
51 year ago
CVE-2024-50970 preview

CVE-2024-50970

GitHubakhlak2511/cve-2024-50970

Proof-of-concept demonstrating time-based SQL injection in Itsourcecode Online Furniture Shopping Project 1.0 via the id parameter in orderview1.php,…

database-securityeducationexploitation+3
1 year ago
CVE-2025-51970 preview

CVE-2025-51970

GitHubm4xiq/cve-2025-51970

SQL Injection in Online Shopping System Advanced (CVE-2025-51970)

database-securityexploitationinformation-gathering+3
1 year ago
Previous123456Next