Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
111 results
CVE-2020-1938 preview

CVE-2020-1938

GitHubdacade/cve-2020-1938

Exploit for CVE-2020-1938 (Ghostcat) enabling file read and remote command execution on vulnerable Apache Tomcat servers via the AJP connector.

exploitationpayload-generationpenetration-testing+2
9
6 years ago
ICG-AutoExploiterBoT preview

ICG-AutoExploiterBoT

GitHubio1337/icg-autoexploiterbot

Automated exploitation tool targeting CMS vulnerabilities in Joomla, WordPress, Drupal, PrestaShop, and OsCommerce with built-in brute-force and…

exploitationpenetration-testingvulnerability-scanners+1
128 years ago
cve-2022-22947 preview

cve-2022-22947

GitHubtwseptian/cve-2022-22947

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

command-and-controlexploitationpayload-generation+3
114 years ago
CVE-2022-39066 preview

CVE-2022-39066

GitHubv0lp3/cve-2022-39066

Proof of concept of the SQL injection vulnerability affecting the ZTE MF286R router.

embedded-systems-securityexploitationiot-security+3
113 years ago
CVE-2026-36130 preview

CVE-2026-36130

GitHubcwjchoi01/cve-2026-36130

Proof-of-concept demonstrating a vulnerability that disables Microsoft Defender (MsMpEng.exe) by locking a folder and rebooting, with screenshots…

defensive-toolsexploitationincident-response+2
24 days ago
CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN preview

CVE-2026-0073-Android-ADBD-bypass-POC_zh_CN

GitHubctn-qvo/cve-2026-0073-android-adbd-bypass-poc_zh_cn

CVE-2026-0073-Android-ADBD-bypass-POC汉化版

android-securitybinary-exploitationeducation+3
33 months ago
moodle-login-csrf preview

moodle-login-csrf

GitHubdanielthatcher/moodle-login-csrf

Scripts for exploiting MSA-18-0020 (CVE-2018-16854) and MSA-19-0004 (CVE-2019-3847)

educationexploitationpenetration-testing+2
77 years ago
CVE-2026-0073 preview

CVE-2026-0073

GitHub0xblackash/cve-2026-0073

CVE-2026-0073

android-securityauthenticationexploitation+3
54 months ago
CVE-2022-39197-fix_patch preview

CVE-2022-39197-fix_patch

GitHub4nth0ny1130/cve-2022-39197-fix_patch

CVE-2022-39197 bug fix patch

exploitationids-ips-evasionpenetration-testing+2
73 years ago
CVE-2023-42791_CVE-2024-23666 preview

CVE-2023-42791_CVE-2024-23666

GitHubsynacktiv/cve-2023-42791_cve-2024-23666

Exploitations scripts for CVE-2023-42791 and CVE-2024-23666.

command-and-controlexploitationpenetration-testing+5
61 year ago
libxml2-exploit preview

libxml2-exploit

GitHubbrahmstaedt/libxml2-exploit

An example exploit for CVE-2017-7376

binary-exploitationexploitationfuzzing+2
36 years ago
CVE-2019-12180 preview

CVE-2019-12180

GitHub0x-nope/cve-2019-12180

Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.

code-analysisexploitationpayload-development+3
46 years ago
CVE-2025-4404-POC preview

CVE-2025-4404-POC

GitHubim10n/cve-2025-4404-poc

POC for CVE-2025-4404

authenticationexploitationpenetration-testing+2
71 year ago
CVE-2026-74586 preview

CVE-2026-74586

GitHubtarpeg007/cve-2026-74586

Unprivileged proof-of-concept for CVE-2026-74586, a Linux kernel SCTP ASCONF use-after-free. Provides a raw-packet trigger, reliability metrics, and…

binary-exploitationexploitationexploit-frameworks+1
116 days ago
CVE-2025-22828 preview

CVE-2025-22828

GitHubstolichnayer/cve-2025-22828

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

cloud-securityexploitationinformation-gathering+2
41 year ago
CVE-2026-54415-PoC preview

CVE-2026-54415-PoC

GitHubabdugafforov-bobur/cve-2026-54415-poc

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

authenticationctfeducation+4
22 months ago
CVE-2021-40346 preview

CVE-2021-40346

GitHubjmg0929/cve-2021-40346

PoC exploit for CVE-2021-40346: HAProxy integer overflow enabling HTTP request smuggling and ACL bypass. Includes analysis, reproduction steps, and…

educationexploitationpenetration-testing+3
2 months ago
CVE-2024-9061 preview

CVE-2024-9061

GitHubrandomrobbiebf/cve-2024-9061

WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via…

exploitationpenetration-testingvulnerability-analysis+2
31 year ago
Previous1234567Next