Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
183 results
CVE-2020-25078 preview

CVE-2020-25078

GitHubchinayozz/cve-2020-25078

Batch exploit script for CVE-2020-25078 targeting D-Link DCS series cameras to extract account credentials via information disclosure vulnerability.

exploitationinformation-gatheringiot-security+3
4 years ago
DVRFaultNET preview
Archived

DVRFaultNET

GitHubst0pl/dvrfaultnet

.NET console application that exploits CVE-2018-9995 vulnerability

exploitationinformation-gatheringiot-security+3
11 year ago
WinboxPoC preview
Archived

WinboxPoC

GitHubbasucert/winboxpoc

Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)

exploitationinformation-gatheringnetwork-security+3
5195 years ago
CVE-2026-63030 preview

CVE-2026-63030

GitHub4minx/cve-2026-63030

CVE-2026-63030 (wp2shell) POC.

exploitationpassword-attackspenetration-testing+2
92 months ago
gitlab-exploit preview

gitlab-exploit

GitHubhackeremmen/gitlab-exploit

Exploit for GitLab CVE-2023-7028: password reset bypass via dual email verification, allowing unauthorized account takeover. Includes affected…

authenticationexploitationpassword-attacks+3
12 years ago
CVE-2023-33243 preview

CVE-2023-33243

GitHubredteampentesting/cve-2023-33243

PoC for login with password hash in STARFACE

authenticationexploitationpassword-attacks+3
13 years ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
13 years ago
JWT-Bruteforcer preview

JWT-Bruteforcer

GitHubrealbatuhan/jwt-bruteforcer

Jwt Bruteforcer with CVE-2018-1000531 Test

authenticationexploitationpassword-attacks+2
11 year ago
CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below preview

CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37755---hardcoded-admin-credential-in-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

authenticationexploitationmisconfiguration+3
3 years ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubxaitax/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Microsoft-Outlook-Remote-Code-Execution-Vulnerability

email-securityexploitationinformation-gathering+5
7752 years ago
keepass-password-dumper preview

keepass-password-dumper

GitHubvdohney/keepass-password-dumper

Original PoC for CVE-2023-32784

digital-forensicsexploitationforensics+3
6513 years ago
kaboom preview

kaboom

GitHubleviathan36/kaboom

A tool to automate penetration tests

exploit-frameworksinformation-gatheringpassword-attacks+4
3826 years ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubvozec/cve-2023-7028

This repository presents a proof-of-concept of CVE-2023-7028

exploitationpassword-attackspenetration-testing+3
2452 years ago
aad-sso-enum-brute-spray preview

aad-sso-enum-brute-spray

GitHubtreebuilder/aad-sso-enum-brute-spray

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

authentication-authorizationcloud-securityinformation-gathering+3
1934 years ago
CVE-2025-24071-msfvenom preview

CVE-2025-24071-msfvenom

GitHubfolks-iwd/cve-2025-24071-msfvenom

Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms

exploitationexploit-frameworkspassword-attacks+2
251 year ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalucard0x1/cve-2024-28000

LiteSpeed Cache Privilege Escalation PoC

educationexploitationpassword-attacks+4
232 years ago
bw-dump preview

bw-dump

GitHubmarkuta/bw-dump

A proof-of-concept for (CVE-2023-38840) that extracts plaintext master passwords from a locked Bitwarden vault.

digital-forensicsexploitationforensics+4
422 years ago
solrradar preview

solrradar

GitHubshinthink/solrradar

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

command-and-controlexploitationinformation-gathering+7
52 months ago
Previous1…456…11Next