Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
217 results
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
CVE-2024-27198-SOC-Lab preview

CVE-2024-27198-SOC-Lab

GitHubptd200110/cve-2024-27198-soc-lab

SOC detection and incident response lab simulating CVE-2024-27198 authentication bypass in JetBrains TeamCity. Includes ELK SIEM, Suricata IDS, Sigma…

educationexploitationids-ips-evasion+7
22 months ago
snuffleupagus preview

snuffleupagus

GitLabjvoisin/snuffleupagus

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest! https://snuffleupagus.rtfd.io

code-analysisids-ips-evasionmisconfiguration+3
16 days ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsentinelxofficial/cve-2025-55182

Pre-authentication RCE exploit for CVE-2025-55182 (React2Shell) targeting React Server Components. Features scanning, OAST verification, WAF bypass,…

exploitationids-ips-evasionpayload-development+5
12 months ago
web-application-firewall- preview

web-application-firewall-

GitHubnithylesh/web-application-firewall-

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

educationexploitationids-ips-evasion+5
32 years ago
CVE-2025-5777-CitrixBleed preview

CVE-2025-5777-CitrixBleed

GitHubrickgeex/cve-2025-5777-citrixbleed

CitrixBleed-2 (CVE-2025-5777) – proof-of-concept exploit for NetScaler ADC/Gateway “memory bleed”

exploitationids-ips-evasioninformation-gathering+3
11 year ago
CVE-2023-27100 preview

CVE-2023-27100

GitHubdaroknet/cve-2023-27100

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via X-Forwarded-For header manipulation and anti-CSRF token reuse.

authenticationexploitationids-ips-evasion+3
23 years ago
next-attack preview

next-attack

GitHubnicknisi/next-attack

A demo of the CVE-2025-29927 vulnerability for a NebraskaJS lightning talk

educationids-ips-evasionmisconfiguration+2
21 year ago
CVE-2022-30190-Follina-Lab preview

CVE-2022-30190-Follina-Lab

GitHubu1tr0nex/cve-2022-30190-follina-lab

Full exploit chain lab and Suricata IDS detection for CVE-2022-30190 (Follina) - MSDT RCE

command-and-controleducationexploitation+7
3 months ago
CVE-2022-28986 preview

CVE-2022-28986

GitHubflaviupopescu/cve-2022-28986

A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationeducationids-ips-evasion+3
24 years ago
CVE-2026-21876 preview

CVE-2026-21876

GitHubdaytriftnewgen/cve-2026-21876

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

ids-ips-evasionpenetration-testingvulnerability-analysis+3
2 months ago
PHP-REVERSE-SHELL preview

PHP-REVERSE-SHELL

GitLabs_r_e_e_r_a_j/php-reverse-shell

This is a powerful and stealthy PHP reverse shell designed for ethical hacking and penetration testing. It establishes a reliable and quiet…

command-and-controleducationids-ips-evasion+6
111 months ago
Typecho-Multiple-Vulnerabilities preview

Typecho-Multiple-Vulnerabilities

GitHubcyberaz0r/typecho-multiple-vulnerabilities

Exploits for Typecho CVE-2024-35538, CVE-2024-35539 and CVE-2024-35540

exploitationids-ips-evasionpenetration-testing+3
12 years ago
CrushFTP-AS2-Bypass-Research-CVE-2025-54309 preview

CrushFTP-AS2-Bypass-Research-CVE-2025-54309

GitHubsmileyface101/crushftp-as2-bypass-research-cve-2025-54309

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

authenticationdefensive-toolseducation+6
8 months ago
CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit preview

CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit

GitHubsimoesctt/ctt-serverless-rce-v1.0---convergent-time-theory-enhanced-mcp-exploit

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

ai-securitycloud-securitycommand-and-control+8
7 months ago
CVE-2020-1938 preview

CVE-2020-1938

GitHubstreghstreek/cve-2020-1938

Detection rules for CVE-2020-1938 (Ghostcat) vulnerability in Apache Tomcat AJP connector, with Suricata and Bro signatures for network-based…

exploitationids-ips-evasionintrusion-detection+2
15 years ago
cve-2022-27438 preview

cve-2022-27438

GitHubgar-re/cve-2022-27438

Proof-of-concept exploit for CVE-2022-27438, demonstrating remote code execution via spoofed update server in Advanced Installer 19.3. Includes DNS…

dns-analysisexploitationids-ips-evasion+3
3 years ago
CVE-2023-27100 preview

CVE-2023-27100

GitHubfabdotnet/cve-2023-27100

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via crafted X-Forwarded-For headers and anti-CSRF tokens to evade sshguard…

authenticationexploitationids-ips-evasion+3
2 years ago
Previous1…567…13Next