Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
297 results
CVE-2024-46278-teedy_1.11_account-takeover preview

CVE-2024-46278-teedy_1.11_account-takeover

GitHubayato-shitomi/cve-2024-46278-teedy_1.11_account-takeover

【Teedy 1.11】Account Takeover via XSS

exploitationpenetration-testingphishing-tools+3
1
1 year ago
CVE-2021-24884 preview

CVE-2021-24884

GitHubs1lkys/cve-2021-24884

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

exploitationpayload-developmentphishing-tools+3
14 years ago
CVE-2024-50677 preview

CVE-2024-50677

GitHubzumiyumi/cve-2024-50677

This repository presents a proof-of-concept of CVE-2024-50677

exploitationpenetration-testingphishing-tools+3
11 year ago
CVE-2020-0665 preview

CVE-2020-0665

GitHubgunzf0x/cve-2020-0665

Proof of Concept for CVE-2020-0665, a.k.a. SID Filter Bypass.

exploitationlateral-movementpenetration-testing+4
11 year ago
CVE-2023-23397-Report preview

CVE-2023-23397-Report

GitHubcyb3rmaddy/cve-2023-23397-report

An exploitation demo of Outlook Elevation of Privilege Vulnerability

authenticationexploitationlateral-movement+3
13 years ago
CVE-2023-40869 preview

CVE-2023-40869

GitHubminotauro2020/cve-2023-40869

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

exploitationpenetration-testingphishing-tools+3
13 years ago
CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration preview

CVE-2026-27579-CollabPlatform-Appwrite-CORS-Misconfiguration

GitHubmbanyamer/cve-2026-27579-collabplatform-appwrite-cors-misconfiguration

Exploit PoC for CVE-2026-27579, a CORS misconfiguration in Appwrite backend, demonstrating credentialed account data theft via malicious phishing…

exploitationphishing-toolsred-teaming+3
6 months ago
CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient preview

CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient

GitHubhagrid29/cve-2024-40586-windows-coerced-authentication-in-forticlient

Exploit for CVE-2024-40586: coerces Windows hosts to authenticate via a vulnerable FortiClient named pipe, enabling privilege escalation to SYSTEM or…

authenticationexploitationlateral-movement+4
11 year ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubj0eyv/cve-2023-23397

Proof-of-concept exploit for CVE-2023-23397, an Outlook/Exchange privilege escalation vulnerability that triggers NTLM credential theft via a…

email-securityexploitationpenetration-testing+2
13 years ago
CVE-2017-8464-EXP preview

CVE-2017-8464-EXP

GitHubxssfile/cve-2017-8464-exp

Exploit for CVE-2017-8464 LNK remote code execution vulnerability. Generates malicious .lnk files for USB-based payload delivery, supporting x86 and…

exploitationlateral-movementpayload-generation+3
18 years ago
CVE-2021-1675 preview

CVE-2021-1675

GitHubdll00p/cve-2021-1675

Proof-of-concept exploit for CVE-2021-1675 (PrintNightmare) targeting Windows Print Spooler. Uses msfvenom-generated malicious DLL delivered via SMB…

exploitationlateral-movementpayload-generation+4
11 year ago
cve-2026-45185-detection-script preview

cve-2026-45185-detection-script

GitHubmateraj2/cve-2026-45185-detection-script

These detection scripts are property of the SECPlayground Platform. Two safe detection scripts. Neither drives the close_notify-mid-BDAT trigger, so…

email-securityexploitationnetwork-security+3
4 months ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubstarscow/cve-2025-33073

PoC Exploit for the NTLM reflection SMB flaw.

exploitationlateral-movementpenetration-testing+3
1 year ago
CVE-2025-51863 preview

CVE-2025-51863

GitHubsecsys-fdu/cve-2025-51863

Proof-of-concept for a Self-XSS vulnerability in ChatGPTUtil, demonstrating cookie theft and account hijacking via crafted SVG payloads pasted into…

exploitationphishing-toolsvulnerability-analysis+2
1 year ago
CVE-2022-2546 preview

CVE-2022-2546

GitHubopenxp-research/cve-2022-2546

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

exploitationpenetration-testingphishing-tools+3
1 year ago
CVE-2023-0214 preview

CVE-2023-0214

GitHub0pts/cve-2023-0214

Secure Web Gateway 10.2.11 - Cross-Site Scripting (XSS)

exploitationpenetration-testingphishing-tools+3
7 months ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubgrupooruss/cve-2020-1472

PowerShell script to validate domain controllers against CVE-2020-1472 (Netlogon EoP) by checking installed hotfixes via WMI, outputting compliance…

exploitationlateral-movementpenetration-testing+2
5 years ago
zerologon preview

zerologon

GitHubcarlos55ml/zerologon

Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

exploitationlateral-movementpassword-attacks+3
4 years ago
Previous1…14151617Next