Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
78 results
CVE-2020-9496 preview

CVE-2020-9496

GitHubs4dbrd/cve-2020-9496

Exploit script for Apache OFBiz CVE-2020-9496 unsafe deserialization vulnerability, enabling remote code execution via crafted XML-RPC requests with…

exploitationpayload-developmentremote-access-tool+2
4
5 years ago
Wing-FTP-Server-7.4.4-RCE-Authenticated preview

Wing-FTP-Server-7.4.4-RCE-Authenticated

GitHubnouvexr/wing-ftp-server-7.4.4-rce-authenticated

Wing FTP Server provides an administrative Lua scripting console accessible via its web interface. Authenticated administrators are able to execute…

exploitationpayload-developmentpenetration-testing+3
21 year ago
Windows_LPE_AFD_CVE-2023-21768 preview

Windows_LPE_AFD_CVE-2023-21768

GitHubchompie1337/windows_lpe_afd_cve-2023-21768

Local privilege escalation exploit for CVE-2023-21768 targeting Windows AFD driver. Elevates arbitrary process to SYSTEM using I/O Ring read/write…

binary-exploitationexploitationpayload-development+3
5063 years ago
Windows_MSKSSRV_LPE_CVE-2023-36802 preview

Windows_MSKSSRV_LPE_CVE-2023-36802

GitHubchompie1337/windows_mskssrv_lpe_cve-2023-36802

Local privilege escalation exploit for CVE-2023-36802 targeting Windows kernel streaming service (MSKSSRV) on Windows 11 22H2, using I/O Ring…

binary-exploitationexploitationexploit-frameworks+3
1642 years ago
PiX-C2 preview

PiX-C2

GitHubrobertdavis1/pix-c2

Ping Exfiltration Command and Control (PiX-C2)

command-and-controlnetwork-securitypacket-sniffing-analysis+3
3111 years ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubjelasin/cve-2026-42945

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX's rewrite module enabling unauthenticated remote code execution via…

binary-exploitationexploitationpayload-development+3
44 months ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
17 days ago
CVE-2025-47812 preview

CVE-2025-47812

GitHub0xgh057r3c0n/cve-2025-47812

Wing FTP Server RCE via Lua Injection

exploitationpayload-developmentpenetration-testing+3
31 year ago
CVE-2025-47812-Wing-FTP-Server-7.4.3-Unauthenticated-RCE-PoC preview

CVE-2025-47812-Wing-FTP-Server-7.4.3-Unauthenticated-RCE-PoC

GitHubestebanzarate/cve-2025-47812-wing-ftp-server-7.4.3-unauthenticated-rce-poc

Proof-of-concept exploit for CVE-2025-47812: unauthenticated remote code execution in Wing FTP Server <= 7.4.3 via NULL byte injection in the…

exploitationpayload-developmentpenetration-testing+3
27 months ago
WingFTP-CVE-2025-47812-illdeed preview

WingFTP-CVE-2025-47812-illdeed

GitHubill-deed/wingftp-cve-2025-47812-illdeed

Remote Command Execution exploit for Wing FTP Server (CVE-2025-47812)

exploitationpayload-developmentpenetration-testing+3
1 year ago
CVE-2025-25705 preview

CVE-2025-25705

GitHubcotherm/cve-2025-25705

Proof-of-concept exploit for authenticated remote code execution via command injection in ProApps Enterprise Appliance ping functionality, with…

command-and-controlexploitationpayload-development+5
1 year ago
CVE-2025-25706 preview

CVE-2025-25706

GitHubcotherm/cve-2025-25706

Detailed CVE-2025-25706 proof-of-concept demonstrating authenticated remote code execution via command injection in ProApps ping functionality,…

command-and-controlexploitationpayload-development+3
1 year ago
ad-autopwn preview

ad-autopwn

GitHubjonaslejon/ad-autopwn

Automated Active Directory attack chain from zero-auth to Domain Admin. Chains 25+ techniques including Kerberoast, AD CS ESC1-16, Shadow…

command-and-controlexploitationlateral-movement+7
2073 days ago
MalleableC2Profiles preview

MalleableC2Profiles

GitHubbluscreenofjeff/malleablec2profiles

Malleable C2 profiles for Cobalt Strike

command-and-controlexploit-frameworksnetwork-security+3
779 years ago
DigiDuck-Framework preview

DigiDuck-Framework

GitHubm4cs/digiduck-framework

Framework for Digiduck Development Boards running ATTiny85 processors and micronucleus bootloader!

embedded-systems-securityhardware-securitypayload-development+2
337 years ago
CVE-2019-12949 preview

CVE-2019-12949

GitHubtarantula-team/cve-2019-12949

CVE-2019-12949

command-and-controlexploitationpayload-development+3
257 years ago
DsArk64 preview

DsArk64

GitHubgmh5225/dsark64

BYOVD proof-of-concept abusing the WHQL-signed DsArk64.sys driver for ring-0 process termination and kernel read/write via encrypted IOCTLs and…

binary-exploitationdefensive-toolsexploitation+6
125 months ago
CVE-2026-1281-Ivanti-EPMM-RCE preview

CVE-2026-1281-Ivanti-EPMM-RCE

GitHubmehdiledeaut/cve-2026-1281-ivanti-epmm-rce

Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion

exploitationpayload-developmentpenetration-testing+3
67 months ago
Previous12345Next