Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
103 results
Debinject preview
Archived

Debinject

GitHubundeadsec/debinject

Inject malicious code into *.debs

educationexploitationmalware-analysis+3
294
4 years ago
cve-2024-4367-poc preview

cve-2024-4367-poc

GitHubanomalousvectors/cve-2024-4367-poc

POC for PDF JS' CVE-2024-4367 vuln

exploitationpayload-generationvulnerability-analysis+1
21 year ago
CVE-2023-48034 preview

CVE-2023-48034

GitHubaprkr/cve-2023-48034

Weak encryption in Acer Wireless Keyboard SK-9662 allows attacker in physical proximity to both decrypt wireless keystrokes and inject wireless…

bluetooth-securitycryptographyembedded-systems-security+6
12 years ago
CVE-2025-53770-Exploit preview

CVE-2025-53770-Exploit

GitHubsoltanali0/cve-2025-53770-exploit

SharePoint WebPart Injection Exploit Tool

educationexploitationpayload-development+4
31310 months ago
CVE-2023-36163 preview

CVE-2023-36163

GitHubtrailer2/cve-2023-36163

Cross Site Scripting vulnerability in IP-DOT BuildaGate v.BuildaGate5 allows a remote attacker to execute arbitrary code via a crafted script to the…

exploitationinformation-gatheringpenetration-testing+2
23 years ago
CVE-2024-33209 preview

CVE-2024-33209

GitHubparagbagul111/cve-2024-33209

FlatPress 1.3. is vulnerable to Cross Site Scripting (XSS). An attacker can inject malicious JavaScript code into the "Add New Entry" section, which…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-60378 preview

CVE-2025-60378

GitHubajansha/cve-2025-60378

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

educationexploitationphishing+3
11 months ago
inject-assembly preview

inject-assembly

GitHubkyleavery/inject-assembly

Inject .NET assemblies into an existing process

exploitationpost-exploitationred-teaming+1
5094 years ago
CVE-2026-19501-poc preview

CVE-2026-19501-poc

GitHubtypedefabcd1234ntd/cve-2026-19501-poc

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

exploitationpayload-generationpenetration-testing+3
1 month ago
CVE-2023-48104 preview

CVE-2023-48104

GitHube1tex/cve-2023-48104

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

exploitationphishingvulnerability-analysis+2
2 years ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
OpenSSL-CCS-Inject-Test preview

OpenSSL-CCS-Inject-Test

GitHubtripwire/openssl-ccs-inject-test

This script is designed for detection of vulnerable servers (CVE-2014-0224.) in a wide range of configurations. It attempts to negotiate using each…

exploitationnetwork-securitypenetration-testing+2
3912 years ago
cve-2026-3854-test preview

cve-2026-3854-test

GitHubsimondankelmann/cve-2026-3854-test

Tests bypasses for CVE-2026-3854 patch, providing a proof-of-concept to validate security fixes.

exploitationpenetration-testingvulnerability-analysis+1
4 months ago
CVE-2023-44758_GDidees-CMS-Stored-XSS---Title preview

CVE-2023-44758_GDidees-CMS-Stored-XSS---Title

GitHubsromanhu/cve-2023-44758_gdidees-cms-stored-xss---title

GDidees CMS 3.9.2 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to…

exploitationpayload-generationpenetration-testing+3
3 years ago
CVE-2021-43650 preview

CVE-2021-43650

GitHubopenxp-research/cve-2021-43650

Webrun <= 3.6.0.42 SQLi

database-securityexploitationpenetration-testing+3
2 years ago
CVE-2022-2546 preview

CVE-2022-2546

GitHubopenxp-research/cve-2022-2546

All-in-One WP Migration < 7.63 - Unauthenticated Reflected XSS + CSRF

exploitationpenetration-testingphishing-tools+3
2 years ago
CVE-2026-25604-PoC preview

CVE-2026-25604-PoC

GitHubjohn-jung/cve-2026-25604-poc

A PoC for demonstrating CVE-2026-25604

authentication-authorizationcloud-securityeducation+4
5 months ago
dlinject preview

dlinject

GitHubdavidbuchanan314/dlinject

Inject a shared library (i.e. arbitrary code) into a live linux process, without ptrace

exploitationred-teamingshellcode
8291 year ago
Previous123456Next