Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
263 results
CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053- preview

CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-

GitHubhf3cyber/cms-made-simple-2.2.9-unauthenticated-sql-injection-exploit-cve-2019-9053-

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…

exploitationinformation-gatheringpassword-cracking+3
1 year ago
CVE-2023-49546 preview

CVE-2023-49546

GitHubgeraldoalcantara/cve-2023-49546

Customer Support System 1.0 - SQL Injection Vulnerability in the "email" Parameter During "save_staff" Operation

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2019-11395 preview

CVE-2019-11395

GitHubcaioprince/cve-2019-11395

A exploit for the CVE-2019-11395 vulnerability in the MailCarrier 2.51 email application, enabling remote code execution.

binary-exploitationexploitationpayload-generation+3
2 years ago
CVE-2023-6444-POC preview

CVE-2023-6444-POC

GitHubwayne-ker/cve-2023-6444-poc

Proof of concept on Unauthenticated Administrator Email Disclosure CVE-2023-6444

exploitationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2024-0235-PoC preview

CVE-2024-0235-PoC

GitHubnxploited/cve-2024-0235-poc

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413 preview

Project-NTLM-Hash-Capture-and-Phishing-Email-Exploitation-for-CVE-2024-21413

GitHubartemcyberlab/project-ntlm-hash-capture-and-phishing-email-exploitation-for-cve-2024-21413

The project was created to demonstrate the use of various tools for capturing NTLM hashes from users on a network and for executing phishing attacks…

educationexploitationlabs-practice+5
1 year ago
CVE-2023-49973 preview

CVE-2023-49973

GitHubgeraldoalcantara/cve-2023-49973

Customer Support System 1.0 - Cross-Site Scripting (XSS) Vulnerability in "email" field/parameter on "customer_list" Page

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2024-25412 preview

CVE-2024-25412

GitHubparagbagul111/cve-2024-25412

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
Event-ID-263-Rule-Name-SOC287---Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919- preview

Event-ID-263-Rule-Name-SOC287---Arbitrary-File-Read-on-Checkpoint-Security-Gateway-CVE-2024-24919-

GitHubahmedmansour93/event-id-263-rule-name-soc287---arbitrary-file-read-on-checkpoint-security-gateway-cve-2024-24919-

🔍 Just wrapped up an incident report on a Phishing Alert (Event ID 257, SOC282). Enhancing my expertise in email threat detection and response! 🚨…

educationexploitationincident-response+2
1 year ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubwyatu/cve-2018-8581

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

email-securityexploitationlateral-movement+4
3317 years ago
CVE-2023-23397-PoC preview

CVE-2023-23397-PoC

GitHubdjackreuter/cve-2023-23397-poc
email-securityexploitationpayload-generation+2
93 years ago
CVE-2026-8080-DKIM-Signature-Verification-Bypass-Header-Canonicalization-Flaw- preview

CVE-2026-8080-DKIM-Signature-Verification-Bypass-Header-Canonicalization-Flaw-

GitHubgeorge0papasotiriou/cve-2026-8080-dkim-signature-verification-bypass-header-canonicalization-flaw-
cryptographyemail-securityexploitation+1
18 days ago
CVE-2021-26855-d preview

CVE-2021-26855-d

GitHubmr-xn/cve-2021-26855-d
email-securityexploitationinformation-gathering+3
65 years ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubqiantu88/cve-2018-8581

CVE-2018-8581

email-securityexploitationpenetration-testing+3
57 years ago
CVE-2025-51863 preview

CVE-2025-51863

GitHubsecsys-fdu/cve-2025-51863
exploitationphishing-toolsvulnerability-analysis+2
1 year ago
CVE-2024-37383-exploit preview

CVE-2024-37383-exploit

GitHubamirzargham/cve-2024-37383-exploit

Roundcube mail server exploit for CVE-2024-37383 (Stored XSS)

data-exfiltrationemail-securityexploitation+3
1 year ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubth3hellion/cve-2024-21413
email-securityexploitationpayload-generation+2
2 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubjacquesquail/cve-2023-23397
email-securityexploitationpenetration-testing+2
3 years ago
Previous1…567…15Next