Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23337 results
CVE-2024-12849-Poc preview

CVE-2024-12849-Poc

GitHubnxploited/cve-2024-12849-poc

Exploit for CVE-2024-12849, an arbitrary file read vulnerability in WordPress Error Log Viewer plugin. Downloads sensitive files via unauthenticated…

data-exfiltrationexploitationpenetration-testing+2
1 year ago
vcenter_saml_login preview

vcenter_saml_login

GitHubhorizon3ai/vcenter_saml_login

A tool to extract the IdP cert from vCenter backups and log in as Administrator

authentication-authorizationcloud-infrastructure-securityexploitation+4
5313 years ago
CVE-2026-62735 preview

CVE-2026-62735

GitHubnhh9905/cve-2026-62735

Proof-of-concept for CVE-2026-62735, an integer overflow in http.sys leading to heap overflow and SYSTEM shell. Includes crash log and stack trace…

binary-exploitationexploitationexploit-frameworks+1
3719 days ago
CVE-2024-23700 preview

CVE-2024-23700

GitHubcanyie/cve-2024-23700

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

android-securityexploitationmobile-app-pentesting+5
738 months ago
CVE-2020-16152 preview

CVE-2020-16152

GitHuberiknl/cve-2020-16152

Proof-of-concept exploit for CVE-2020-16152: LFI-to-RCE in Aerohive/Extreme Networks HiveOS via PHP string truncation and log poisoning, enabling…

binary-exploitationexploitationlateral-movement+3
116 years ago
ghostlock-pfem10 preview

ghostlock-pfem10

GitHubcxlfhx/ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

android-securitybinary-exploitationexploitation+7
13 days ago
CVE-2026-34344 preview

CVE-2026-34344

GitHubnhh9905/cve-2026-34344

PoC for CVE-2026-34344, a Windows afd.sys type confusion causing a kernel crash via AfdQueryProviderInfo. Provides trigger code, crash log, and…

binary-exploitationeducationexploitation+1
21 month ago
CVE-2026-5281 preview

CVE-2026-5281

GitHubjaf0rk/cve-2026-5281

Proof-of-concept exploit for CVE-2026-5281, a heap-use-after-free vulnerability in Chromium's Dawn WebGPU implementation, with ASAN log and build…

binary-exploitationdebuggersexploitation+3
2 months ago
CVE-2026-5027-Langflow preview

CVE-2026-5027-Langflow

GitHublayer-6/cve-2026-5027-langflow

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

command-and-controlexploitationpayload-development+8
3 months ago
CVE-2024-23700 preview

CVE-2024-23700

GitHubvinh0212/cve-2024-23700

PoC for CVE-2024-23700, Android slient privilege escalation allow to read/write contacts, SMS, calendar, call log and voicemail, make outgoing calls…

android-securityeducationexploitation+4
14 months ago
CVE-2026-25548 preview

CVE-2026-25548

GitHublagathos/cve-2026-25548

Detailed technical write-up and proof-of-concept for CVE-2026-25548, a critical RCE in InvoicePlane 1.7.0 via LFI and log poisoning, including attack…

educationexploitationpenetration-testing+3
16 months ago
CVE-2023-26469-Jorani preview

CVE-2023-26469-Jorani

GitHubkairo-one/cve-2023-26469-jorani

Proof-of-concept exploit for CVE-2023-26469 targeting Jorani 1.0.0. Combines path traversal and log injection to achieve remote code execution with…

educationexploitationpenetration-testing+3
19 months ago
AnySniff preview

AnySniff

GitHubmkultra6969/anysniff

AnySniff is a tool for monitoring TCP connections of processes like AnyDesk on Windows. It uses the CVE-2024-52940 vulnerability to track open…

exploitationinformation-gatheringnetwork-security+3
41 year ago
CVE-2021-33558. preview

CVE-2021-33558.

GitHubmdanzaruddin/cve-2021-33558.

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

exploitationinformation-gatheringmisconfiguration+2
35 years ago
CVE-2021-3129 preview

CVE-2021-3129

GitHubgiangdurian/cve-2021-3129

Python exploit script for Laravel Ignition CVE-2021-3129 RCE, using log poisoning and phar deserialization to execute commands on vulnerable web apps.

educationexploitationvulnerability-analysis+1
1 month ago
ams-failopen preview

ams-failopen

GitHubjgoyd/ams-failopen

Zero-day in AppleMediaServices: Bag fetch failure disables Mescal/Absinthe signing. Requests to Apple services proceed unsigned, exposing downgrade,…

dns-analysisexploitationpenetration-testing+3
31 year ago
cve-2026-43499 preview

cve-2026-43499

GitHubmiapatsune/cve-2026-43499

Kernel exploit for Redmi Pad Pro (dizi) / POCO Pad 5G with browser-based upload and execution interface, admin panel for log management, and…

android-securitybinary-exploitationexploitation+2
12 months ago
CVE-2024-43363 preview

CVE-2024-43363

GitHubp33d/cve-2024-43363

Python exploit script to test Cacti instances for CVE-2024-43363 RCE via log poisoning. Checks version, injects PHP payload into device names, and…

code-analysisexploitationpenetration-testing+2
41 year ago
Previous12…100Next