Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
261 results
cve-2025-66723 preview

cve-2025-66723

GitHubaudiopump/cve-2025-66723

CVE-2025-66723: inMusic Brands Engine DJ >=3.0.0 through <4.3.4 exposes local and network files to external parties

data-exfiltrationexploitationinformation-gathering+3
8 months ago
CVE-2021-44228-docker-example preview

CVE-2021-44228-docker-example

GitHubdicanio/cve-2021-44228-docker-example

Docker-based demonstration of CVE-2021-44228 (Log4Shell) exploitation, featuring a vulnerable Java server, malicious LDAP server, and data…

data-exfiltrationeducationexploitation+3
14 years ago
Mysql-Readfile preview

Mysql-Readfile

GitHubal1ex/mysql-readfile

Mysql-Readfile

database-securitydata-exfiltrationexploitation+3
14 years ago
CVE-2025-65321 preview

CVE-2025-65321

GitHubsmarttfoxx/cve-2025-65321

Language Sloth Sloth Bot 1.0 is vulnerable to Directory Traversal in the gif() and png() functions. The functions build file paths using unsanitized…

data-exfiltrationexploitationinformation-gathering+2
210 months ago
CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read preview

CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read

GitHubgeorge0papasotiriou/cve-2026-21015-php-filter-chain-arbitrary-file-read

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

data-exfiltrationexploitationinformation-gathering+4
2 months ago
flar3ad preview

flar3ad

GitHubdaemoncibsec/flar3ad

POC of CVE-2026-51031 for arbitrary local file read

data-exfiltrationexploitationpenetration-testing+2
1 month ago
CVE-2020-16938 preview

CVE-2020-16938

GitHubioncodes/cve-2020-16938

Bypassing NTFS permissions to read any files as unprivileged user.

data-exfiltrationexploitationforensics+2
1945 years ago
CVE-2021-31800-Impacket-SMB-Server-Arbitrary-file-read-write preview

CVE-2021-31800-Impacket-SMB-Server-Arbitrary-file-read-write

GitHubp0dalirius/cve-2021-31800-impacket-smb-server-arbitrary-file-read-write

A path traversal in smbserver.py allows an attacker to read/write arbitrary files on the server.

data-exfiltrationexploitationpenetration-testing+2
113 years ago
CVE-2023-22047-Oracle-PeopleSoft-LFI preview

CVE-2023-22047-Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047-oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

data-exfiltrationexploitationinformation-gathering+3
1 month ago
CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open preview

CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open

GitHubgeorge0papasotiriou/cve-2026-11111-toctou-in-file-permission-check-before-open

Educational CVE PoC for a TOCTOU file-permission race in Flask; uses symlink replacement during the check-open window to disclose sensitive files.

data-exfiltrationeducationexploitation+4
2 months ago
CVE-2020-27603-bbb-libreoffice-poc preview

CVE-2020-27603-bbb-libreoffice-poc

GitHubhannob/cve-2020-27603-bbb-libreoffice-poc

Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button

data-exfiltrationexploitationpenetration-testing+2
31 year ago
MAL-014 preview

MAL-014

GitHubmbadanoiu/mal-014

MAL-014: Authenticated Arbitrary File Read in VMware vCenter Server

data-exfiltrationexploitationpenetration-testing+2
1 year ago
CVE-2024-40422 preview

CVE-2024-40422

GitHubalpernae/cve-2024-40422

Python implementation/PoC for CVE-2024-40422. Exploits a critical directory traversal vulnerability in Devika v1's /api/get-browser-snapshot endpoint…

data-exfiltrationexploitationpenetration-testing+2
2 months ago
CVE-2022-47522-PoC preview

CVE-2022-47522-PoC

GitHubtoffeenutt/cve-2022-47522-poc

Proof-of-concept exploit for CVE-2022-47522 demonstrating Wi-Fi frame interception via deauthentication attack and MAC address spoofing to capture…

exploitationpacket-sniffing-analysispenetration-testing+3
1 year ago
PPLBlade preview

PPLBlade

GitHubtastypepperoni/pplblade

Bypasses PPL protection to dump LSASS process memory, obfuscates dump files with XOR, and exfiltrates them remotely via RAW or SMB without writing to…

data-exfiltrationexploitationmemory-forensics+2
6023 years ago
CVE-2025-12137 preview

CVE-2025-12137

GitHubjfriedli/cve-2025-12137

Proof-of-concept exploit for CVE-2025-12137 demonstrating local file disclosure via a WordPress plugin's REST API importer endpoint. Includes…

data-exfiltrationexploitationinformation-gathering+3
6 months ago
CVE-2024-36991-Tool preview

CVE-2024-36991-Tool

GitHubthestingr/cve-2024-36991-tool

This binary POC automates the exploitation of CVE-2024-36991 by sending crafted curl requests to a vulnerable Splunk instance. It retrieves sensitive…

data-exfiltrationexploitationinformation-gathering+3
211 months ago
XSSFire preview

XSSFire

GitHubseifelsallamy/xssfire

A standalone Blind XSS Script.

data-exfiltrationexploitationinformation-gathering+3
471 year ago
Previous12…15Next