Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
112 results
CVE-2024-6460 preview

CVE-2024-6460

GitHubnxploited/cve-2024-6460

Grow by Tradedoubler < 2.0.22 - Unauthenticated LFI

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2017-8225-EXPLOIT preview

CVE-2017-8225-EXPLOIT

GitHubk3ystr0k3r/cve-2017-8225-exploit

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

exploitationinformation-gatheringiot-security+3
93 years ago
CVE-2026-36227 preview

CVE-2026-36227

GitHubnullbyte8080/cve-2026-36227

Benign proof-of-concept for CVE-2026-36227, a path traversal vulnerability in Easy Chat Server 3.1 user registration. Demonstrates unauthorized file…

educationexploitationlabs-practice+3
3 months ago
CVE-2025-46047 preview

CVE-2025-46047

GitHubj0ey17/cve-2025-46047

PoC for Silverpeas <= 6.4.2 Username Enumeration

educationexploitationinformation-gathering+3
21 year ago
Samba-CVE-2007-2447-Exploit preview

Samba-CVE-2007-2447-Exploit

GitHubshivamdey/samba-cve-2007-2447-exploit

Python exploit for CVE-2007-2447 in Samba, enabling remote command execution via crafted username. Delivers reverse shell to attacker. For authorized…

educationexploitationpayload-generation+3
2 years ago
CVE-2025-11833-PoC preview

CVE-2025-11833-PoC

GitHubbocgoinfosec/cve-2025-11833-poc

Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

educationexploitationpenetration-testing+2
10 months ago
Exploit-for-CVE-2025-2304 preview

Exploit-for-CVE-2025-2304

GitHubsparrowhawk1113/exploit-for-cve-2025-2304

Exploit for CVE-2025-2304

educationexploitationprivilege-escalation+2
7 months ago
Exploit-for-CVE-2024-46987 preview

Exploit-for-CVE-2024-46987

GitHubsparrowhawk1113/exploit-for-cve-2024-46987

Exploit for CVE-2024-46987

educationexploitationpenetration-testing+2
7 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubtiborscholtz/cve-2026-24061

Educational Docker lab demonstrating Telnet NEW-ENVIRON username injection (CVE-2026-24061) with a Python client and vulnerable server for isolated…

educationexploitationlabs-practice+2
7 months ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubdwisiswant0/cve-2020-9496

Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

educationexploitationpenetration-testing+2
36 years ago
exploit-CVE-2024-25723 preview

exploit-CVE-2024-25723

GitHubdavid-botelho-mariano/exploit-cve-2024-25723

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

educationexploitationpassword-attacks+3
42 years ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
CyberSec2026 preview

CyberSec2026

GitHubsanderschepers1993/cybersec2026

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

educationexploitationlabs-practice+3
4 months ago
confluence-rce-poc preview

confluence-rce-poc

GitHubwolf1892/confluence-rce-poc

Setting up POC for CVE-2021-26084

educationexploitationpenetration-testing+2
5 years ago
CVE-2026-42568 preview

CVE-2026-42568

GitHubex-cal1bur/cve-2026-42568

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

authenticationeducationexploitation+3
3 months ago
CVE-2020-25273 preview

CVE-2020-25273

GitHubjonathanrey87/cve-2020-25273

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

authenticationeducationexploitation+3
5 years ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubjenderal92/cve-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

authenticationeducationexploitation+3
3 months ago
CVE-2025-8088-Multi-Document preview

CVE-2025-8088-Multi-Document

GitHubpentestfunctions/cve-2025-8088-multi-document

Exploit systems using older WinRAR without knowing their username (unlike other projects)

binary-exploitationeducationexploitation+4
351 year ago
Previous1234567Next