Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2026-15667 preview

CVE-2026-15667

GitHubcflowsec/cve-2026-15667

Python proof-of-concept for CVE-2026-15667, an authenticated local file inclusion in the WordPress Eventin plugin via the event_layout REST field.

exploitationpenetration-testingvulnerability-analysis+3
1 day ago
cacti-cve-2023-39361 preview

cacti-cve-2023-39361

GitHubspartanx-alejandro/cacti-cve-2023-39361

Exploit for CVE-2023-39361 in Cacti, a network graphing solution, demonstrating SQL injection vulnerability for educational and security testing…

exploitationpenetration-testingvulnerability-analysis+2
12 days ago
CVE-2026-39902 preview

CVE-2026-39902

GitHubkx00007/cve-2026-39902

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

code-analysisexploitationpenetration-testing+2
17 days ago
CVE-2026-39808 preview

CVE-2026-39808

GitHuberror-inside/cve-2026-39808

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

command-and-controleducationexploitation+3
2 months ago
CVE-2023-33730 preview

CVE-2023-33730

GitHubsahiloj/cve-2023-33730

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

authentication-authorizationeducationexploitation+8
16 months ago
ReactOOPS-WriteUp preview

ReactOOPS-WriteUp

GitHubthestingr/reactoops-writeup

Hack The Box Writeup for Retired Challenge ReactOOPS - Complete solution and educational guide to CVE-2025-55182/CVE-2025-66478 (React2Shell RCE).…

code-analysisctfeducation+8
69 months ago
CVE-2025-30216-PoC preview

CVE-2025-30216-PoC

GitHuboliviaisntcringe/cve-2025-30216-poc

PoC

binary-exploitationembedded-systems-securityexploitation+3
1 year ago
Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks. preview

Simulating-and-preventing-Zerologon-CVE-2020-1472-vulnerability-attacks.

GitHubpakwansk/simulating-and-preventing-zerologon-cve-2020-1472-vulnerability-attacks.

Simulation of the Zerologon (CVE-2020-1472) vulnerability attack in Active Directory on Windows Server 2016 and the use of the Trend Micro Deep…

educationexploitationlabs-practice+2
1 year ago
CVE-2022-34169 preview

CVE-2022-34169

GitHubdisnaming/cve-2022-34169

A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025

ctfeducationexploitation+3
31 year ago
JOP_ROCKET preview

JOP_ROCKET

GitHubbw3ll/jop_rocket

This framework enables user to discover JOP gagdets and can automate building a complete JOP chain to bypass DEP. JOP ROCKET is the ultimate solution…

binary-exploitationeducationexploitation+4
1172 years ago
EPScalate preview

EPScalate

GitHub0xinfection/epscalate

Exploit for elevation of privilege vulnerability in QuickHeal's Seqrite EPS (CVE-2023-31497).

exploitationpenetration-testingpost-exploitation+2
192 years ago
CVE-2023-27470_Exercise preview

CVE-2023-27470_Exercise

GitHub3lp4tr0n/cve-2023-27470_exercise

Windows privilege escalation lab that recreates CVE-2023-27470's arbitrary file deletion bug, with vulnerable executable, source, solution, and a…

educationexploitationlabs-practice+2
103 years ago
CVE-2021-40905 preview

CVE-2021-40905

GitHubedgarloyola/cve-2021-40905

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

code-analysisexploitationpenetration-testing+2
3 years ago
CVE-2021-36563 preview

CVE-2021-36563

GitHubedgarloyola/cve-2021-36563

Proof-of-concept for stored and reflected XSS vulnerabilities in CheckMK Management Web Console versions 1.5.0 to 2.0.0p9, with detailed disclosure…

educationexploitationpenetration-testing+3
13 years ago
log4j-CVE-2021-44228-workaround preview

log4j-CVE-2021-44228-workaround

GitHubgrimch/log4j-cve-2021-44228-workaround

general purpose workaround for the log4j CVE-2021-44228 vulnerability

exploitationincident-responsemisconfiguration+2
4 years ago
log4j-docker-vaccine preview

log4j-docker-vaccine

GitHubjeffbryner/log4j-docker-vaccine

docker compose solution to run a vaccine environment for the log4j2 vulnerability CVE-2021-44228

container-securityeducationexploitation+3
24 years ago
westone-CVE-2021-37580-scanner preview

westone-CVE-2021-37580-scanner

GitHubosyanina/westone-cve-2021-37580-scanner

A vulnerability scanner that detects CVE-2021-37580 vulnerabilities.

api-securityauthenticationexploitation+2
4 years ago
pentesterlab-cve-2018-6574 preview

pentesterlab-cve-2018-6574

GitHubthejuan1112/pentesterlab-cve-2018-6574

solution

binary-exploitationeducationexploitation+3
5 years ago
Previous12Next