Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
141 results
vcenter_saml_login preview

vcenter_saml_login

GitHubhorizon3ai/vcenter_saml_login

A tool to extract the IdP cert from vCenter backups and log in as Administrator

authentication-authorizationcloud-infrastructure-securityexploitation+4
529
3 years ago
KasperMeow preview

KasperMeow

GitHubmein-0/kaspermeow

Proof-of-concept that exploits a Kaspersky driver vulnerability to leak kernel pointers and bypass KASLR on Windows, enabling kernel exploit chain…

binary-analysisexploitationreverse-engineering+1
141 month ago
DahuaLoginBypass preview

DahuaLoginBypass

GitHubbp2008/dahualoginbypass

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

authentication-authorizationexploitationiot-security+3
1993 months ago
xnuspy preview

xnuspy

GitHubjsherman212/xnuspy

an iOS kernel function hooking framework for checkra1n'able devices

binary-analysisdebuggersexploitation+1
6065 years ago
SenselessViolence preview

SenselessViolence

GitHubevergreencartoons/senselessviolence

CVE-2022-31814 Exploitation Toolkit.

command-and-controlexploitationlog-analysis+7
44 years ago
py-log4shellscanner preview

py-log4shellscanner

GitHubscheibling/py-log4shellscanner

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

dns-analysisexploitationfuzzing+3
4 years ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub00xcanelo/cve-2025-27591

🔥 Local Privilege Escalation Exploit for CVE-2025-27591 | Abuses world-writable log dir in Below to gain root via /etc/passwd injection

binary-exploitationeducationexploitation+3
21 year ago
CVE-2025-10951 preview

CVE-2025-10951

GitHub1amunvalid/cve-2025-10951

Proof-of-concept checker for CVE-2025-10951, an unauthenticated path traversal in ml-logger, validating arbitrary file read via /glob and /stream…

data-exfiltrationexploitationinformation-gathering+3
1 month ago
CVE-2026-58025 preview

CVE-2026-58025

GitHubshinthink/cve-2026-58025

CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8…

exploitationpayload-developmentpenetration-testing+2
52 months ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubahmetramazank/cve-2024-4577

Demonstrates exploitation of CVE-2024-4577, a PHP CGI RCE on Windows, including attack steps, reverse shell deployment, and ransomware simulation…

educationexploitationforensics+5
1 year ago
vRealizeLogInsightRCE preview

vRealizeLogInsightRCE

GitHubhorizon3ai/vrealizeloginsightrce

POC for RCE using vulnerabilities described in VMSA-2023-0001

exploitationpayload-generationpenetration-testing+2
1463 years ago
CVE-2025-0924-different preview

CVE-2025-0924-different

GitHubskrkcb2/cve-2025-0924-different

Technical analysis of CVE-2025-0924, a Stored XSS vulnerability in WP Activity Log plugin for WordPress. Includes root cause analysis, exploitation…

educationexploitationpapers-research+2
11 year ago
CVE-2025-27591-Below preview

CVE-2025-27591-Below

GitHubthekin-ctrl/cve-2025-27591-below

Proof-of-concept exploit for CVE-2025-27591, a local privilege escalation in the 'below' system monitor. Demonstrates symlink attack on log file to…

educationexploitationpenetration-testing+2
1 year ago
CVE-2021-3129 preview

CVE-2021-3129

GitHubjoshuavanderpoll/cve-2021-3129

Laravel RCE Exploit PoC - CVE-2021-3129 (user-friendly with automatic log path detection)

code-analysisexploitationpayload-generation+3
1584 months ago
CVE-2023-51214 preview

CVE-2023-51214

GitHubchandraprarikraj/cve-2023-51214

Proof-of-concept for CVE-2023-51214: a stored XSS vulnerability in a PHP-based activity log web application allowing remote code execution via…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2026-2636_PoC preview

CVE-2026-2636_PoC

GitHuboxfemale/cve-2026-2636_poc

Proof-of-concept for CVE-2026-2636, a Windows CLFS.sys vulnerability causing BSoD via ReadFile on CreateLogFile handle, enabling unprivileged denial…

exploitationexploit-frameworksvulnerability-analysis
157 months ago
CVE-2018-19276 preview

CVE-2018-19276

GitHubmpgn/cve-2018-19276

CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE

code-analysisexploitationpayload-development+3
167 years ago
ghostlock-pfem10 preview

ghostlock-pfem10

GitHubcxlfhx/ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

android-securitybinary-exploitationexploitation+7
29 days ago
Previous12…8Next