Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
120 results
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubz3rodayhacks/cve-2026-63030-cve-2026-60137

Pre-auth RCE proof-of-concept chaining a WordPress REST batch API auth bypass with WP_Query SQL injection to dump hashes, add admin users, or plant a…

exploitationpayload-developmentpenetration-testing+6
2 months ago
cve-2022-31749 preview

cve-2022-31749

GitHubiveresk/cve-2022-31749

PoC checker for CVE-2022-31749 exploiting a parameter injection vulnerability in WatchGuard SSH interface to exfiltrate hashed user passwords via FTP.

authenticationdata-exfiltrationexploitation+3
14 years ago
CVE-2022-21392 preview

CVE-2022-21392

GitHubmbadanoiu/cve-2022-21392

CVE-2022-21392: Local Privilege Escalation via NMR SUID in Oracle Enterprise Manager

exploitationpenetration-testingprivilege-escalation+1
42 years ago
CVE-2016-5639 preview

CVE-2016-5639

GitHubxfox64x/cve-2016-5639

Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules

exploitationexploit-frameworksinformation-gathering+3
26 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubka7ana/cve-2023-23397

PowerShell proof-of-concept for CVE-2023-23397 that exploits Outlook's ReminderSoundFile property to intercept Net-NTLMv2 hashes via SMB or WebDAV…

authenticationexploitationpenetration-testing+3
403 years ago
CVE-2025-24054-PoC preview

CVE-2025-24054-PoC

GitHubsimantchaudhari/cve-2025-24054-poc

Proof-of-concept exploit for CVE-2025-24054, a Windows Library (.library-ms) NTLM hash disclosure vulnerability. Generates a malicious .library-ms…

educationexploitationinformation-gathering+3
5 months ago
Bad-Pdf preview

Bad-Pdf

GitHubdeepzec/bad-pdf

Steal Net-NTLM Hash using Bad-PDF

educationexploitationphishing-tools+1
1.2k11 months ago
CVE-2020-2969 preview

CVE-2020-2969

GitHubemad-almousa/cve-2020-2969

Proof-of-concept exploit for CVE-2020-2969 targeting unauthorized access to Oracle Database password hashes. Enables security researchers to test and…

database-securityexploitationpassword-attacks+2
2 years ago
CVE-2021-3831 preview

CVE-2021-3831

GitHubaratane/cve-2021-3831

Unauthenticated Sensitive Information Disclosure

educationexploitationinformation-gathering+2
1 year ago
CVE-2024-43451-POC preview

CVE-2024-43451-POC

GitHubronf98/cve-2024-43451-poc

CVE-2024-43451 is a Windows NTLM vulnerability that allows an attacker to force authentication and capture NTLM hashes by using malicious shortcuts.

exploitationmalware-analysispassword-cracking+3
151 year ago
CVE-2022-24637 preview

CVE-2022-24637

GitHubpflegusch/cve-2022-24637

Open Web Analytics 1.7.3 - Remote Code Execution

exploitationpayload-generationpenetration-testing+3
43 years ago
monikerlink-cve-2024-21413-writeup preview

monikerlink-cve-2024-21413-writeup

GitHubpczbuilds/monikerlink-cve-2024-21413-writeup

Writeup of TryHackMe's Moniker Link room, exploiting CVE-2024-21413 to bypass Outlook Protected View and capture NTLMv2 hashes via crafted Moniker…

ctfeducationexploitation+2
17 days ago
CVE-2026-40083 preview

CVE-2026-40083

GitHubhakaioffsec/cve-2026-40083

Proof-of-concept exploit for CVE-2026-40083, a SQL injection in Cacti managers.php allowing authenticated users to extract MySQL databases, user…

database-securityeducationexploitation+4
43 months ago
CVE-2024-24919 preview

CVE-2024-24919

GitHub0xyumeko/cve-2024-24919

Proof-of-concept exploit for CVE-2024-24919, a Check Point path traversal allowing arbitrary file read (e.g., /etc/shadow) via crafted HTTPS POST…

exploitationinformation-gatheringpenetration-testing+2
12 years ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

Demonstrates capturing NTLM hashes via Responder and executing phishing emails exploiting CVE-2024-21413 to compromise systems.

educationexploitationlabs-practice+5
1 year ago
internal-penetration-testing-project-using-Metasploit preview

internal-penetration-testing-project-using-Metasploit

GitHubabdullah50i/internal-penetration-testing-project-using-metasploit

Initialized & connected PostgreSQL to Metasploit. Reconnoitered 10.1.16.0/24 with Nmap and imported results. Enumerated hosts/services using SYN, SMB…

exploitationexploit-frameworksinformation-gathering+6
2 months ago
CVE-2019-9053-POC preview

CVE-2019-9053-POC

GitHubcaelumisme/cve-2019-9053-poc

Python 3 exploit for CVE-2019-9053, an unauthenticated time-based blind SQL injection in CMS Made Simple < 2.2.10, extracting admin credentials and…

educationexploitationpassword-cracking+3
11 months ago
AutoPwn-Titanic.htb preview

AutoPwn-Titanic.htb

GitHubmaikneysm/autopwn-titanic.htb

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

ctfexploitationinformation-gathering+5
1 year ago
Previous1234567Next