Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3105 results
FUCKER preview

FUCKER

GitHubrazureink/fucker

Penetration testing framework with AI-driven decision engine

command-and-controlexploitationlateral-movement+7
1 month ago
mvn_pwn preview

mvn_pwn

GitHubmbadanoiu/mvn_pwn

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

educationexploitationpayload-development+3
2 months ago
CVE-2024-23745 preview

CVE-2024-23745

GitHublouiselalanne/cve-2024-23745

In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack.

binary-exploitationexploitationpayload-development+2
22 years ago
By-Poloss..-..CVE-2017-20251 preview

By-Poloss..-..CVE-2017-20251

GitHubpolosss/by-poloss..-..cve-2017-20251

Insert PHP Plugin PHP Code Injection

code-analysiseducationexploitation+4
12 months ago
WP-Bricks-Exploit-CVE-2024-25600 preview

WP-Bricks-Exploit-CVE-2024-25600

GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

command-and-controlexploitationinformation-gathering+7
11 month ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubpssec-io/cve-2026-48907

POC for CVE-2026-48907

educationexploitationlabs-practice+5
12 months ago
CVE-2026-54161 preview

CVE-2026-54161

GitHubja-errorpro/cve-2026-54161

upsmon: remote OS command injection (RCE) via attacker-controlled ups.alarm in NOTIFYCMD execution

command-and-controlexploitationpayload-development+3
12 months ago
selenium-node-takeover-kit preview

selenium-node-takeover-kit

GitHubjonstratton/selenium-node-takeover-kit

A collection of selenium tests that might aid it takeover of a selenium node

command-and-controldata-exfiltrationexploit-frameworks+6
28 months ago
gitlab-cve-2020-10977 preview

gitlab-cve-2020-10977

GitHubvandycknick/gitlab-cve-2020-10977

GitLab Arbitrary File Read Exploit

exploitationpayload-developmentpenetration-testing+3
25 years ago
Overflow-Demo-CVE-2017-11882 preview

Overflow-Demo-CVE-2017-11882

GitHubekgg/overflow-demo-cve-2017-11882

Simple Overflow demo, like CVE-2017-11882 exp

binary-exploitationeducationexploitation+2
26 years ago
CVE-2025-47812 preview

CVE-2025-47812

GitHub0xgh057r3c0n/cve-2025-47812

Wing FTP Server RCE via Lua Injection

exploitationpayload-developmentpenetration-testing+3
31 year ago
CVE-2025-24016 preview

CVE-2025-24016

GitHubglostarrx1/cve-2025-24016

CVE-2025-24016: RCE in Wazuh server! Remote Code Execution

exploitationpayload-developmentpenetration-testing+3
11 year ago
DexLoader preview

DexLoader

GitHubbend0us/dexloader

A demo Android project showcasing dynamic DEX loading using DexClassLoader, PathClassLoader, and in-memory execution. For educational purposes only.

android-securitybinary-exploitationdynamic-analysis-sandboxing+3
21 year ago
cve-2022-42889-text4shell preview

cve-2022-42889-text4shell

GitHubdimamend/cve-2022-42889-text4shell

Docker-based lab environment to reproduce and test CVE-2022-42889 (Text4Shell) remote code execution vulnerability in Apache Commons Text.

educationexploitationlabs-practice+3
11 days ago
CVE-2024-8353-PoC preview

CVE-2024-8353-PoC

GitHub0xb0mb3r/cve-2024-8353-poc

Proof-of-Concept for CVE-2024-5932 GiveWP PHP Object Injection

educationexploitationpayload-development+3
31 year ago
VTIGER-CRM-RCE-CVE-2026-23698 preview

VTIGER-CRM-RCE-CVE-2026-23698

GitHubjivasecurity/vtiger-crm-rce-cve-2026-23698

Vtiger CRM 8.3.0, 8.4.0 Module Import Authenticated RCE PoC

exploitationpayload-developmentpenetration-testing+3
1 month ago
CVE-2022-22965-Spring4Shell preview

CVE-2022-22965-Spring4Shell

GitHubkuri119/cve-2022-22965-spring4shell

Exploit for CVE-2022-22965 (Spring4Shell) enabling remote code execution on unpatched Spring Framework applications via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
2 months ago
engeman-web-language-combobox-sqli preview

engeman-web-language-combobox-sqli

GitHubm3m0o/engeman-web-language-combobox-sqli

Proof of concept for exploitation of the vulnerability described in CVE-2025-8220, which concerns the possibility of SQL Injection during the…

exploitationpayload-developmentpenetration-testing+2
310 months ago
Previous1…99100Next