Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
558 results
CVE-2025-29557 preview

CVE-2025-29557

GitHub0xsu3ks/cve-2025-29557

Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…

api-securityeducationexploitation+3
1 year ago
CVE-2025-4664 preview

CVE-2025-4664

GitHubspeinador/cve-2025-4664

Educational demo of CVE-2025-4664, a Chrome Loader vulnerability enabling cross-origin data leakage via referrer-policy manipulation. Includes a…

educationexploitationinformation-gathering+3
1 year ago
CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH preview

CVE-2024-6387-Race-Condition-in-Signal-Handling-for-OpenSSH

GitHubs1d6point7bugcrowd/cve-2024-6387-race-condition-in-signal-handling-for-openssh

Technical analysis and proof-of-concept for CVE-2024-6387, a race condition in OpenSSH signal handling enabling unauthenticated remote code execution…

binary-exploitationeducationexploitation+3
2 years ago
CVE-2023-34598 preview

CVE-2023-34598

GitHubzer0f8th/cve-2023-34598

Gibbon v25.0.0 is vulnerable to a Local File Inclusion (LFI)

educationexploitationinformation-gathering+3
1 year ago
CVE-2022-34961 preview

CVE-2022-34961

GitHubbypazs/cve-2022-34961

OpenTeknik LLC OSSN OPEN SOURCE SOCIAL NETWORK v6.3 LTS was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Users…

educationexploitationinformation-gathering+3
4 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubmrp4nda1337/cve-2023-23752

simple program for joomla scanner CVE-2023-23752 with target list

educationexploitationinformation-gathering+3
3 years ago
CVE-2021-41773h preview

CVE-2021-41773h

GitHubmightysai1997/cve-2021-41773h

PoC and exploit for Apache HTTP Server 2.4.49 path traversal vulnerability (CVE-2021-41773) with Docker setup, curl-based exploitation commands, and…

educationexploitationinformation-gathering+3
7 months ago
aziot-cctv-cve-2025-50777 preview

aziot-cctv-cve-2025-50777

GitHubveereshgadige/aziot-cctv-cve-2025-50777

CVE-2025-50777: Root Access and Plaintext Credential Exposure in AZIOT Smart CCTV

educationembedded-systems-securityexploitation+8
1 year ago
CVE-2019-20085 preview

CVE-2019-20085

GitHubz3r0space/cve-2019-20085

A repository used for Hackthebox ServMon Machine

educationexploitationinformation-gathering+3
1 year ago
CVE-2025-3419 preview

CVE-2025-3419

GitHubyucaerin/cve-2025-3419

The Eventin plugin (<= 4.0.26) for WordPress contains an unauthenticated arbitrary file read vulnerability

educationexploitationinformation-gathering+3
1 year ago
CVE-2025-1661 preview

CVE-2025-1661

GitHubmuhammadwaseem29/cve-2025-1661

HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)

educationexploitationinformation-gathering+3
1 year ago
cachet_2.4.0-dev preview

cachet_2.4.0-dev

GitHubhadrian3689/cachet_2.4.0-dev

Python exploit script for CVE-2021-39174 Cachet information disclosure and remote code execution via Twig Server-Side Template Injection, with…

educationexploitationinformation-gathering+3
3 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubifconfig-me/cve-2024-23897

Proof-of-concept exploit for Jenkins arbitrary file leak vulnerability (CVE-2024-23897). Enables unauthorized file disclosure for security testing…

educationexploitationinformation-gathering+2
2 years ago
CVE-2025-29602 preview

CVE-2025-29602

GitHubharish0x/cve-2025-29602

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in FlatPress CMS 1.3.1, demonstrating payload injection and impact including…

educationexploitationinformation-gathering+3
1 year ago
EXP-CVE-2017-75 preview

EXP-CVE-2017-75

GitHubcalebfin/exp-cve-2017-75

CVE-2017-7529- Check and EXPLOIT

educationexploitationinformation-gathering+3
2 years ago
CVE-2023-23752_Joomla preview

CVE-2023-23752_Joomla

GitHubhadrian3689/cve-2023-23752_joomla

Proof-of-concept exploit for CVE-2023-23752 targeting unauthenticated information disclosure in Joomla! versions 4.0.0 to 4.2.7. Includes a Python…

educationexploitationinformation-gathering+3
2 years ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubviardant/cve-2021-29447

CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8

ctfexploitationinformation-gathering+3
3 years ago
CVE-2025-31125 preview

CVE-2025-31125

GitHub0xgh057r3c0n/cve-2025-31125

Vite WASM Import Path Traversal 🛡️

educationexploitationinformation-gathering+3
1 year ago
Previous1…28293031Next