Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
CVE-2019-0708-EXP-Windows preview

CVE-2019-0708-EXP-Windows

GitHubcbwang505/cve-2019-0708-exp-windows

CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell

exploitationpayload-generationpenetration-testing+3
317
6 years ago
TrustJack preview

TrustJack

GitHubjfmaes/trustjack

Yet another PoC for https://www.wietzebeukema.nl/blog/hijacking-dlls-in-windows

exploitationpersistence-mechanismspost-exploitation+2
1436 years ago
Redis-RCE preview

Redis-RCE

GitHubjas502n/redis-rce

remote code execute for redis4 and redis5

database-securityexploitationpayload-development+2
1027 years ago
CVE-2020-1938-Tomact-file_include-file_read preview

CVE-2020-1938-Tomact-file_include-file_read

GitHubsv3nbeast/cve-2020-1938-tomact-file_include-file_read

Tomcat的文件包含及文件读取漏洞利用POC

exploitationinformation-gatheringpenetration-testing+2
566 years ago
CVE-2024-50379 preview

CVE-2024-50379

GitHubsleepingbag945/cve-2024-50379

tomcat CVE-2024-50379/CVE-2024-56337 条件竞争文件上传exp

exploitationpayload-generationpenetration-testing+3
841 year ago
CVE-2023-28432 preview

CVE-2023-28432

GitHubmzzdtot/cve-2023-28432

MinIO敏感信息泄露漏洞批量扫描poc&exp

cloud-securityexploitationinformation-gathering+3
373 years ago
CVE-2025-0108-PoC preview

CVE-2025-0108-PoC

GitHubisee857/cve-2025-0108-poc

Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)

authentication-authorizationexploitationids-ips-evasion+3
321 year ago
spring-core-rce preview

spring-core-rce

GitHubk3rwin/spring-core-rce

spring框架RCE漏洞 CVE-2022-22965

exploitationpayload-generationpenetration-testing+3
274 years ago
FollinaExtractor preview

FollinaExtractor

GitHubmalwaretech/follinaextractor

Extract payload URLs from Follina (CVE-2022-30190) docx and rtf files

exploitationinformation-gatheringmalware-analysis+2
314 years ago
k8s-CVE-2021-43557-poc preview

k8s-CVE-2021-43557-poc

GitHubxvnpw/k8s-cve-2021-43557-poc

PoC for CVE-2021-43557

api-securitycloud-securitycontainer-security+3
234 years ago
CVE-2023-29923 preview

CVE-2023-29923

GitHub1820112015/cve-2023-29923

CVE-2023-29922 Batch detection script

exploitationinformation-gatheringpenetration-testing+2
153 years ago
cve-2019-5736-poc preview

cve-2019-5736-poc

GitHubagppp/cve-2019-5736-poc

getshell test

container-escapecontainer-securityexploitation+2
77 years ago
CVE-2022-22947 preview

CVE-2022-22947

GitHubmrknow001/cve-2022-22947

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

command-and-controlexploitationpayload-generation+3
74 years ago
CVE-2022-24990-POC preview

CVE-2022-24990-POC

GitHubvveakee/cve-2022-24990-poc

仅仅是poc,并不是exp

exploitationpenetration-testingvulnerability-analysis+2
44 years ago
CVE-2020-13937 preview

CVE-2020-13937

GitHubyaunsky/cve-2020-13937

Apache Kylin API未授权访问漏洞;CVE-2020-13937;Apache Kylin漏洞

exploitationinformation-gatheringreconnaissance+2
95 years ago
cve-2022-29464 preview

cve-2022-29464

GitHublidong-io/cve-2022-29464

cve-2022-29464 批量脚本

exploitationpenetration-testingreconnaissance+2
54 years ago
py-CVE-2021-41773 preview

py-CVE-2021-41773

GitHubaqiao-jashell/py-cve-2021-41773

python编写的apache路径穿越poc&exp

educationexploitationinformation-gathering+3
73 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubli8u99/cve-2022-26134

Python-based exploit for Atlassian Confluence remote code execution (CVE-2022-26134) with single-target and batch URL verification capabilities.

exploitationpenetration-testingreconnaissance+2
44 years ago
Previous123456Next