Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
183 results
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 months ago
py-network-scanner preview

py-network-scanner

GitHubanonymous121029034720384234234/py-network-scanner

Advanced network penetration testing toolkit with SSH vulnerability assessment, CVE-2018-15473 exploitation, stealth brute force capabilities, and…

educationexploitationids-ips-evasion+6
11 year ago
Windows-Explorer-CVE-2025-24071 preview

Windows-Explorer-CVE-2025-24071

GitHubcesarbtakeda/windows-explorer-cve-2025-24071

PoC exploit for CVE-2025-24071, a Windows File Explorer spoofing vulnerability that leaks NTLM hashes via malicious .library-ms files in RAR/ZIP…

educationexploitationinformation-gathering+2
11 year ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubfernandobortotti/cve-2024-24919

Automated exploit for CVE-2024-24919 with API-based vulnerable IP discovery and LFI brute-force using custom wordlists. Designed for educational…

educationexploitationinformation-gathering+3
12 years ago
CVE-2025-26326 preview

CVE-2025-26326

GitHubazurejoga/cve-2025-26326

Critical security vulnerability in NVDA remote connection add-ons.

exploitationinformation-gatheringpassword-attacks+3
11 year ago
Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets- preview

Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-

GitHubartemcyberlab/project-project-chimera-exploiting-a-modern-wordpress-xxe-to-pillage-secrets-

The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The…

educationexploitationinformation-gathering+8
11 year ago
winboxPOC preview

winboxPOC

GitHubtr33-he11/winboxpoc

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

exploitationinformation-gatheringnetwork-security+3
17 years ago
CVE-2025-63820 preview

CVE-2025-63820

GitHubxernary/cve-2025-63820

Proof-of-concept of vulnerability found in Totolink A720R router

embedded-systems-securityexploitationhardware-iot-security+3
10 months ago
CVE-2023-5359 preview

CVE-2023-5359

GitHubenzocipher/cve-2023-5359

CVE-2023-5359 scanner for W3 Total Cache cleartext storage vulnerability. Detects exposed credentials (API keys, OAuth tokens) in publicly accessible…

educationexploitationinformation-gathering+3
10 months ago
CVE-2025-21574-Exploit preview

CVE-2025-21574-Exploit

GitHubmdriaz009/cve-2025-21574-exploit

Black-box exploit for CVE-2025-21574 targeting MySQL servers. Automates credential brute-forcing, anonymous access attempts, and triggers server…

database-securityexploitationpassword-attacks+3
1 year ago
CVE-2020-15392 preview

CVE-2020-15392

GitHubinflixim4be/cve-2020-15392

Proof-of-concept exploit for user enumeration vulnerability in Supravizio BPM 10.1.2 via password recovery response differences, enabling brute force…

information-gatheringpassword-attackspenetration-testing+2
6 years ago
zerologon preview

zerologon

GitHubcarlos55ml/zerologon

Scripts to test and exploit the Zerologon vulnerability (CVE-2020-1472) in Active Directory, enabling password reset and hash dumping of domain…

exploitationlateral-movementpassword-attacks+3
4 years ago
ZerologonWithImpacket-CVE2020-1472 preview

ZerologonWithImpacket-CVE2020-1472

GitHubtuancui22/zerologonwithimpacket-cve2020-1472

A practical proof-of-concept for CVE-2020-1472 (Zerologon) using the Impacket library to exploit Netlogon vulnerability and perform unauthorized…

educationexploitationlateral-movement+5
1 year ago
smb preview

smb

GitHubhackingyseguridad/smb

Shell script collection for SMB protocol auditing, vulnerability detection (EternalBlue, SMBGhost), null session enumeration, credential brute-force,…

exploitationinformation-gatheringnetwork-security+5
8 months ago
CVE-2023-43154-PoC preview

CVE-2023-43154-PoC

GitHubally-petitt/cve-2023-43154-poc

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

authentication-authorizationexploitationpassword-attacks+3
3 years ago
CVE-2020-2969 preview

CVE-2020-2969

GitHubemad-almousa/cve-2020-2969

Proof-of-concept exploit for CVE-2020-2969 targeting unauthorized access to Oracle Database password hashes. Enables security researchers to test and…

database-securityexploitationpassword-attacks+2
2 years ago
CVE-2023-22074 preview

CVE-2023-22074

GitHubemad-almousa/cve-2023-22074

Proof-of-concept exploit for CVE-2023-22074, an Oracle Database Sharding component vulnerability enabling password hash exposure in versions 19c,…

database-securityexploitationinformation-gathering+2
2 years ago
Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232 preview

Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232

GitHubredfox-security/digisol-dg-gr1321-s-password-storage-in-plaintext-cve-2024-4232

Proof-of-concept demonstrating plaintext password storage vulnerability in Digisol DG-GR1321 routers, enabling credential exposure and unauthorized…

hardware-securityiot-securitymisconfiguration+3
2 years ago
Previous1…345…11Next