Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
687 results
kamene preview

kamene

GitHubphaethon/kamene

Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3…

information-gatheringnetwork-mappingnetwork-security+3
872
5 years ago
CVE-2025-10952-ml-logger-AFR preview

CVE-2025-10952-ml-logger-AFR

GitHubkhashayarnzk/cve-2025-10952-ml-logger-afr

PoC for CVE-2025-10952 — ml-logger unauthenticated arbitrary file read. CVSS 5.3

exploitationinformation-gatheringpenetration-testing+2
2 days ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubmachiavelliii/cve-2024-23897

Unauthenticated arbitrary file read exploit for Jenkins CVE-2024-23897, with HTTPS and CSRF-crumb support to bypass hardened instances.

exploitationinformation-gatheringpenetration-testing+2
2 days ago
htb-labs-connected preview

htb-labs-connected

GitHubdiegorivas1/htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

ctfeducationexploitation+7
2 days ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
2 days ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
3 months ago
CVE-2026-26336-PoC preview

CVE-2026-26336-PoC

GitHubceaarab/cve-2026-26336-poc

Proof-of-concept exploit for CVE-2026-26336, an unauthenticated path traversal in Alfresco Share allowing arbitrary file read within the webapp and…

exploitationinformation-gatheringpenetration-testing+2
3 months ago
portscan-CVE-2026-41940 preview

portscan-CVE-2026-41940

GitHubamirrezamarzban/portscan-cve-2026-41940

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

information-gatheringnetwork-securitypenetration-testing+3
14 months ago
CVE-2021-43798-mass_scanner preview

CVE-2021-43798-mass_scanner

GitHubrodpwn/cve-2021-43798-mass_scanner

Mass scanner for Grafana CVE-2021-43798 unauthorized file read, supporting single targets, hostname lists, and IP ranges with PoC verification.

exploitationinformation-gatheringreconnaissance+2
54 years ago
CVE-2026-29909-MRCMS-vulnerability preview

CVE-2026-29909-MRCMS-vulnerability

GitHubqflksheep/cve-2026-29909-mrcms-vulnerability

Unauthenticated directory enumeration PoC for MRCMS V3.1.2, exploiting missing authentication in /admin/file/list.do to disclose server directory…

exploitationinformation-gatheringpenetration-testing+2
5 months ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubmauricelambert/cve-2021-42013

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubmauricelambert/cve-2021-41773

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2021-21311 preview

CVE-2021-21311

GitHubllhala/cve-2021-21311

Proof-of-concept for CVE-2021-21311, a server-side request forgery in Adminer before 4.7.9, demonstrating SSRF exploitation in PHP database…

exploitationinformation-gatheringpenetration-testing+2
84 years ago
CVE-2021-43798 preview

CVE-2021-43798

GitHublalkaltest/cve-2021-43798

Proof-of-concept exploit for Grafana arbitrary file reading vulnerability (CVE-2021-43798) affecting versions 8.0.0 to 8.3.0, demonstrating…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
CVE-2024-55457-PoC preview

CVE-2024-55457-PoC

GitHubh13nh04ng/cve-2024-55457-poc

Proof-of-concept exploit for CVE-2024-55457, a directory traversal in MasterSAM Star Gate v11 allowing unauthenticated arbitrary file download via…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2024-23897-Jenkins-4.441 preview

CVE-2024-23897-Jenkins-4.441

GitHubclassic130/cve-2024-23897-jenkins-4.441

Exploit for Jenkins arbitrary file leak (CVE-2024-23897) that reads files from the target server via a crafted request.

exploitationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2021-43798_exploit preview

CVE-2021-43798_exploit

GitHubaymenbouferroum/cve-2021-43798_exploit

Exploit for Grafana directory traversal (CVE-2021-43798) allowing local file read via crafted plugin path. Includes usage instructions and references.

exploitationinformation-gatheringpenetration-testing+2
14 years ago
CVE-2025-11371 preview

CVE-2025-11371

GitHubnetvanguard-cmd/cve-2025-11371

Proof-of-concept exploit for CVE-2025-11371, an unauthenticated Local File Inclusion in Gladinet CentreStack and TrioFox, enabling remote file…

educationexploitationinformation-gathering+3
110 months ago
Previous12…39Next