Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
cve-2025-66398 preview

cve-2025-66398

GitHubshowy-headteacher114/cve-2025-66398

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

exploitationpayload-developmentpenetration-testing+3
1
5 days ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
12 months ago
cve-2025-66398 preview

cve-2025-66398

GitHubjoshuavanderpoll/cve-2025-66398

CVE-2025-66398 — Signal K Server ≤ 2.18.0 RCE PoC

command-and-controleducationexploitation+7
36 months ago
jsPDF-Object-Injection preview

jsPDF-Object-Injection

GitHubabsholi7ly/jspdf-object-injection

CVE-2026-25755 A critical PDF Object Injection vulnerability in jsPDF allows attackers to inject arbitrary PDF objects through the addJS() function,…

exploitationpayload-developmentvulnerability-analysis+1
17 months ago
Gitea-Git-Hooks-RCE-CVE-2020-14144- preview

Gitea-Git-Hooks-RCE-CVE-2020-14144-

GitHubmohnad-al-saif/gitea-git-hooks-rce-cve-2020-14144-

Gitea versions 1.1.0 → 1.12.5 allow authenticated users with "May create git hooks" permission to inject arbitrary shell commands into post-receive…

educationexploitationpayload-development+3
7 months ago
CVE-2025-53770-Exploit preview

CVE-2025-53770-Exploit

GitHubsoltanali0/cve-2025-53770-exploit

SharePoint WebPart Injection Exploit Tool

educationexploitationpayload-development+4
31310 months ago
CVE-2025-53547-POC preview

CVE-2025-53547-POC

GitHubdvkunion/cve-2025-53547-poc

CVE-2025-53547 one of poc code

command-and-controlexploitationpayload-development+2
91 year ago
CVE-2023-6000-POC preview

CVE-2023-6000-POC

GitHubronf98/cve-2023-6000-poc

This vulnerability displays an XSS flaw in a WordPress popup plugin, allowing attackers to inject malicious JavaScript through a stored XSS

exploitationpayload-developmentpenetration-testing+3
11 year ago
CVE-2025-1094 preview

CVE-2025-1094

GitHubaninfosec/cve-2025-1094

It is an input sanitization flaw caused by an encoding mismatch, allowing crafted input to bypass filters. If a server is vulnerable, an attacker can…

database-securityeducationexploitation+5
11 year ago
IconJector preview

IconJector

GitHubd419h/iconjector

Inject DLLs into the explorer process using icons

adversarial-attackexploitationpayload-development+3
4141 year ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
CVE-2025-25706 preview

CVE-2025-25706

GitHubcotherm/cve-2025-25706

Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality,…

command-and-controlexploitationpayload-development+3
1 year ago
CVE-2024-53407 preview

CVE-2024-53407

GitHubsyfi/cve-2024-53407

CVE-2024-53407

binary-exploitationcommand-and-controlexploitation+2
1 year ago
process-inject-kit preview

process-inject-kit

GitHubrasta-mouse/process-inject-kit

Port of Cobalt Strike's Process Inject Kit

adversarial-attackexploit-frameworkspayload-development+2
1931 year ago
threadfire preview

threadfire

GitHubjosh0xa/threadfire

PoC Thread Execution Hijacking for Win32 Code Injection

payload-developmentpenetration-testingred-teaming+1
1742 years ago
-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server preview

-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server

GitHubr00t7oo2jm/-cve-2024-21683-rce-in-confluence-data-center-and-server

This vulnerability allows an unauthenticated attacker to remotely execute arbitrary code on a vulnerable Confluence server. The vulnerability exists…

exploitationpayload-developmentpenetration-testing+3
22 years ago
CVE-2023-43352-CMSmadesimple-SSTI--Content preview

CVE-2023-43352-CMSmadesimple-SSTI--Content

GitHubsromanhu/cve-2023-43352-cmsmadesimple-ssti--content

SSTI vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to use native template syntax to inject a malicious payload into a template,…

exploitationpayload-developmentpenetration-testing+3
3 years ago
Debinject preview
Archived

Debinject

GitHubundeadsec/debinject

Inject malicious code into *.debs

educationexploitationmalware-analysis+3
2944 years ago
Previous12Next