Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
183 results
CVE-2024-44812-PoC preview

CVE-2024-44812-PoC

GitHubb1u3st0rm/cve-2024-44812-poc

Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0

authentication-authorizationexploitationpassword-attacks+3
2 years ago
CVE-2024-28085 preview

CVE-2024-28085

GitHubskyler-ferrante/cve-2024-28085

WallEscape vulnerability in util-linux

exploitationpassword-attackspost-exploitation+3
552 years ago
Netgrave preview

Netgrave

GitHubxewdy444/netgrave

A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)

educationexploitationinformation-gathering+5
714 days ago
HashDump-BypassEDR preview

HashDump-BypassEDR

GitHubaabysszg/hashdump-bypassedr

Windows绕过EDR实现DumpHash

hash-analysisids-ips-evasionpassword-attacks+3
2631 month ago
ZeroLogon-PoC-DC-Pwn preview

ZeroLogon-PoC-DC-Pwn

GitHubmods20hh/zerologon-poc-dc-pwn

Zerologon (CVE-2020-1472) Proof-of-Concept application - Critical Active Directory vulnerability exploitation tool.

educationexploitationpapers-research+6
41 month ago
PoC-ubuntutouch-pin-privesc preview

PoC-ubuntutouch-pin-privesc

GitHubfilipkarc/poc-ubuntutouch-pin-privesc

CVE-2022-40297 - Proof of Concept: Privilege escalation in Ubuntu Touch 16.04 - by PIN Bruteforce

android-securityexploitationmobile-security+5
64 years ago
CVE-2025-14998 preview

CVE-2025-14998

GitHubktn1990/cve-2025-14998

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

authenticationexploitationpassword-attacks+3
28 months ago
TendaSpill preview

TendaSpill

GitHubshaheemirza/tendaspill

An exploitation tool to extract passwords using CVE-2015-5995.

educationexploitationpassword-attacks+3
107 years ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
1 month ago
CVE-2023-42820 preview

CVE-2023-42820

GitHubc1ph3rx13/cve-2023-42820

Exploit script for JumpServer password reset vulnerability CVE-2023-42820, with automatic verification code calculation and password modification.

exploitationpassword-attackspenetration-testing+2
572 years ago
CVE-2017-8295 preview

CVE-2017-8295

GitHubcyberheartmi9/cve-2017-8295

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

exploitationpassword-attackspenetration-testing+3
206 years ago
CVE-2024-28987-POC preview

CVE-2024-28987-POC

GitHubgh-ost00/cve-2024-28987-poc

Web Help Desk Hardcoded Credential Vulnerability (CVE-2024-28987)

authenticationexploitationmisconfiguration+3
122 years ago
POC-CVE-2014-0166 preview

POC-CVE-2014-0166

GitHubettack/poc-cve-2014-0166

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

exploitationpassword-attackspenetration-testing+2
512 years ago
openCRX-CVE-2020-7378 preview

openCRX-CVE-2020-7378

GitHubruthvikvegunta/opencrx-cve-2020-7378

Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script

authenticationexploitationpassword-attacks+3
55 years ago
redash-reset preview

redash-reset

GitHubrandomrobbiebf/redash-reset

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

exploitationpassword-attackspenetration-testing+2
54 years ago
CVE-2025-70829 preview

CVE-2025-70829

GitHubxiaoxiaoranxxx/cve-2025-70829

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

authenticationdatabase-securityexploitation+3
47 months ago
CVE-2024-28999 preview

CVE-2024-28999

GitHubhussainfathy/cve-2024-28999

Exploit for CVE-2024-28999 SolarWinds Platform Race Condition Vulnerability - login page

exploitationpassword-attackspenetration-testing+2
42 years ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubrajneeshkarya/cve-2023-3460

Exploit for the vulnerability of Ultimate Member Plugin.

exploitationpassword-attackspenetration-testing+2
12 years ago
Previous12…11Next