Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
339 results
CVE-2024-2667-Poc preview

CVE-2024-2667-Poc

GitHubnxploited/cve-2024-2667-poc

PoC exploit for CVE-2024-2667: automated arbitrary file upload and shell access via insufficient file validation in InstaWP Connect WordPress plugin…

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2023-26326_Buddyform_exploit preview

CVE-2023-26326_Buddyform_exploit

GitHubmesudmammad1/cve-2023-26326_buddyform_exploit

Python exploit for CVE-2023-26326 (WordPress BuddyForms) chained with CVE-2024-2961 to achieve unauthenticated remote code execution via php://filter…

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2024-25291 preview

CVE-2024-25291

GitHubeqstlab/cve-2024-25291

deskfiler 1.2.3 Open Redirect exploit

exploitationpayload-developmentpenetration-testing+3
2 years ago
chamilo-lms-unauthenticated-big-upload-rce-poc preview

chamilo-lms-unauthenticated-big-upload-rce-poc

GitHubm3m0o/chamilo-lms-unauthenticated-big-upload-rce-poc

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

exploitationpayload-developmentpenetration-testing+3
2 years ago
Codiad-CVE-2018-14009 preview

Codiad-CVE-2018-14009

GitHublolameroo/codiad-cve-2018-14009

Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689

exploitationpayload-developmentpenetration-testing+4
4 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubsymbolexe/cve-2023-23397

CVE-2023-23397: Remote Code Execution Vulnerability in Microsoft Outlook

exploitationpayload-developmentpenetration-testing+3
2 years ago
2022_PoC-MSDT-Follina-CVE-2022-30190 preview

2022_PoC-MSDT-Follina-CVE-2022-30190

GitHubimprovecybersecurityjaro/2022_poc-msdt-follina-cve-2022-30190

Proof of Concept zu MSDT-Follina - CVE-2022-30190. ÜBERPRÜFUNG DER WIRKSAMKEIT VON MICROSOFT DEFNEDER IN DER JEWEILS AKTUELLSTEN WINDOWS 10 VERSION.

exploitationpayload-developmentpenetration-testing+3
4 years ago
CVE-2023-46604-demo preview

CVE-2023-46604-demo

GitHubnitzanoligo/cve-2023-46604-demo
exploitationpayload-developmentpenetration-testing+3
1 year ago
cve-2022-30333_online_rar_extracor preview

cve-2022-30333_online_rar_extracor

GitHubparadox0909/cve-2022-30333_online_rar_extracor
exploitationpayload-developmentpenetration-testing+3
2 years ago
Ekko preview
Archived

Ekko

GitHubcracked5pider/ekko

Sleep Obfuscation

payload-developmentpost-exploitationred-teaming
8432 years ago
CVE-2024-37054 preview

CVE-2024-37054

GitHubbardlaudian/cve-2024-37054

Proof-of-concept that poisons MLflow registered models via the REST API, embedding a malicious pickle to trigger RCE when the model is loaded.

ai-securitydefensive-toolsexploitation+6
3 days ago
coactionbrittlemaidenhair51.github.io preview

coactionbrittlemaidenhair51.github.io

GitHubcoactionbrittlemaidenhair51/coactionbrittlemaidenhair51.github.io

Explore and validate CVE-2026-42978 PoC with an integrated AI security tool, multi-protocol terminal, and autonomous agent suite for Windows Push…

ai-securityexploitationpayload-development+4
5 days ago
CVE-2023-27163-AND-Mailtrail-v0.53 preview

CVE-2023-27163-AND-Mailtrail-v0.53

GitHubhhesenjan/cve-2023-27163-and-mailtrail-v0.53

Python exploit chaining CVE-2023-27163 SSRF in Requests Baskets with Mailtrail v0.53 to forward internal services and execute a reverse shell.

exploitationpayload-developmentpenetration-testing+3
23 years ago
venom-rs preview
Archived

venom-rs

GitHubmemn0ps/venom-rs

Rusty Injection - Shellcode Reflective DLL Injection (sRDI) in Rust (Codename: Venom)

payload-developmentpost-exploitationred-teaming+2
3682 years ago
CVE-2026-36239 preview
Archived

CVE-2026-36239

GitHubtazmidev/cve-2026-36239

CVE-2026-36239 | Authenticated RCE in PbootCMS ≤3.2.12

exploitationpayload-developmentpenetration-testing+3
24 months ago
Previous1…1819Next