Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
118 results
CVE-2025-12163 preview

CVE-2025-12163

GitHubsnailsploit/cve-2025-12163

CVE-2025-12163: Stored Cross-Site Scripting in Omnipress WordPress Plugin

educationpapers-researchvulnerability-analysis+2
3 months ago
CVE-2025-55998 preview

CVE-2025-55998

GitHubocmenog/cve-2025-55998
educationpapers-researchvulnerability-analysis+2
11 months ago
CVE-2023-24203-and-CVE-2023-24204 preview

CVE-2023-24203-and-CVE-2023-24204

GitHubmomo1239/cve-2023-24203-and-cve-2023-24204
educationexploitationpapers-research+3
2 years ago
CVE-2025-67730 preview

CVE-2025-67730

GitHubdharan10/cve-2025-67730

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

educationpapers-researchvulnerability-analysis+2
7 months ago
CVE-2026-33910_SqlInjectionVulnerabilityOpenEMR8.0.0.2 preview

CVE-2026-33910_SqlInjectionVulnerabilityOpenEMR8.0.0.2

GitHubchrissub08/cve-2026-33910_sqlinjectionvulnerabilityopenemr8.0.0.2

CVE-2026-33910: SQL Injection Vulnerability in OpenEMR <8.0.0.3

educationexploitationpapers-research+3
4 months ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubthemehackers/cve-2025-54100

CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

educationexploitationpapers-research+3
318 months ago
React2Shell-Library preview

React2Shell-Library

GitHubwebsecuritylabs/react2shell-library

A curated list of resources regarding CVE-2025-55182, the critical Remote Code Execution (RCE) vulnerability in React Server Components known as…

curated-resourceseducationexploitation+6
77 months ago
CVE-2023-49438 preview

CVE-2023-49438

GitHubbrandon-t-elliott/cve-2023-49438

CVE-2023-49438 - Open Redirect Vulnerability in Flask-Security-Too

educationpapers-researchvulnerability-analysis+2
52 years ago
CVE-2026-35031 preview

CVE-2026-35031

GitHubkeraattin/cve-2026-35031

Critical path traversal to RCE vulnerability in Jellyfin Media Server (CVSS 9.9). Includes proof-of-concept exploit, technical analysis, and…

educationexploitationpapers-research+5
24 months ago
CVE-2025-56399 preview

CVE-2025-56399

GitHubtheethat-thamwasin/cve-2025-56399

An authenticated Remote Code Execution (RCE) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager…

educationexploitationpapers-research+3
39 months ago
CVE-2023-37597 preview

CVE-2023-37597

GitHubsahiloj/cve-2023-37597

Issabel-pbx v 4.0.0-6 contains a Cross-Site Request Forgery (CSRF) vulnerability in its user group management functionality.

educationexploitationpapers-research+3
16 months ago
Flowise-RCE-CVE-2025-59528 preview

Flowise-RCE-CVE-2025-59528

GitHubr3nsi15/flowise-rce-cve-2025-59528

Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the…

educationexploitationpapers-research+4
14 months ago
React2ShellPoC preview

React2ShellPoC

GitHubgit0xlai/react2shellpoc

This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It…

educationexploitationpapers-research+3
7 months ago
CVE-2020-8158 preview

CVE-2020-8158

GitHubopen-flaw/cve-2020-8158

This is a proof-of-concept demonstrating CVE-2020-8158, a critical prototype pollution vulnerability in TypeORM versions < 0.2.25.

code-analysiseducationexploitation+3
8 months ago
CVE-2026-0847 preview

CVE-2026-0847

GitHubhyperps/cve-2026-0847

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including…

educationexploitationpapers-research+3
4 months ago
MAL-003 preview

MAL-003

GitHubmbadanoiu/mal-003

MAL-003: Groovy Security Bypass and Stored XSS in Apache OfBiz

exploitationpapers-researchpenetration-testing+3
2 years ago
CVE-2525-25748-Cross-Site-Request-Forgery-CSRF-Vulnerability-in-HotelDruid-3.0.7 preview

CVE-2525-25748-Cross-Site-Request-Forgery-CSRF-Vulnerability-in-HotelDruid-3.0.7

GitHubhuyvo2910/cve-2525-25748-cross-site-request-forgery-csrf-vulnerability-in-hoteldruid-3.0.7

Cross-Site Request Forgery (CSRF) Vulnerability in HotelDruid 3.0.7 (CVE-2025-25748)

educationpapers-researchpenetration-testing+3
1 year ago
CVE-2025-26206 preview

CVE-2025-26206

GitHubxibhi/cve-2025-26206

A critical Cross-Site Request Forgery (CSRF) vulnerability in Sell Done Storefront v.1.0. Discovered by B. Sibhi

educationpapers-researchvulnerability-analysis+2
1 year ago
Previous1234567Next