Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1106 results
CVE-2025-48384-poc preview

CVE-2025-48384-poc

GitHubjacobholtz/cve-2025-48384-poc

PoC for CVE-2025-48384

educationexploitationpapers-research+3
1 year ago
cfengine-CVE_2015_0235 preview

cfengine-CVE_2015_0235

GitHubnickanderson/cfengine-cve_2015_0235

gethostbyname*() buffer overflow exploit in glibc - CVE-2015-0235 https://community.qualys.com/blogs/laws-of-vulnerabilities/2015/01/27/the-ghost-vuln…

binary-exploitationexploitationpayload-development+3
111 years ago
CVE-2021-44228-Apache-Log4j-Rce preview

CVE-2021-44228-Apache-Log4j-Rce

GitHubkannthu/cve-2021-44228-apache-log4j-rce

Proof-of-concept exploit for CVE-2021-44228 (Log4Shell) with JNDI injection payloads, WAF bypass techniques, and passive scanning integration for…

exploitationpayload-developmentpenetration-testing+3
4 years ago
CVE-2014-6271-Shellshock- preview

CVE-2014-6271-Shellshock-

GitHubdrhaitham/cve-2014-6271-shellshock-

A complete, modern demonstration lab for CVE-2014-6271 (Shellshock), including architecture, exploitation steps, Burp Suite usage, reverse shells,…

command-and-controlctfeducation+8
9 months ago
roundcube-cve-2025-49113-lab preview

roundcube-cve-2025-49113-lab

GitHubankitpandey383/roundcube-cve-2025-49113-lab

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

code-analysisctfeducation+7
9 months ago
CVE-2023-50965 preview

CVE-2023-50965

GitHubdavigsantana/cve-2023-50965

STACK BUFFER OVERFLOW EXPLOIT RESULTING IN REMOTE CODE EXECUTION

binary-exploitationeducationexploitation+3
5 months ago
Ashwesker-CVE-2025-60021 preview

Ashwesker-CVE-2025-60021

GitHubmefhika120/ashwesker-cve-2025-60021

CVE-2025-60021

command-and-controleducationexploitation+5
7 months ago
CVE-2022-1329 preview

CVE-2022-1329

GitHubdexit/cve-2022-1329

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

code-analysisexploitationpayload-development+3
3 years ago
CVE-2025-53694-to-CVE-2025-53691 preview

CVE-2025-53694-to-CVE-2025-53691

GitHubblueisbeautiful/cve-2025-53694-to-cve-2025-53691

From Information Disclosure to RCE in Sitecore Experience Platform (XP)

educationexploitationpayload-development+3
1 year ago
cve-2026-33937 preview

cve-2026-33937

GitHubdinhvaren/cve-2026-33937

Proof-of-concept exploit for CVE-2026-33937, a Handlebars AST injection vulnerability leading to remote code execution in Node.js. Demonstrates…

code-analysisexploitationpayload-development+2
4 months ago
CVE-2023-4220 preview

CVE-2023-4220

GitHubvanishedpeople/cve-2023-4220

CVE-2023-4220 PoC Chamilo RCE

educationexploitationpayload-development+3
1 year ago
CVE-2023-32571-POC preview

CVE-2023-32571-POC

GitHubvert16x/cve-2023-32571-poc

Proof-of-concept exploit for CVE-2023-32571 demonstrating Dynamic Linq injection to achieve remote code execution, with a Docker-based lab…

code-analysiseducationexploitation+4
2 years ago
CVE-2024-9264-Fixed preview

CVE-2024-9264-Fixed

GitHubexerrdev/cve-2024-9264-fixed

Fixed proof-of-concept exploit for CVE-2024-9264, a critical Grafana RCE via DuckDB SQL expressions. Executes reverse shell using corrected shellfs…

educationexploitationpayload-development+3
1 year ago
CVE-2025-55182-Scanner preview

CVE-2025-55182-Scanner

GitHubf0xyx/cve-2025-55182-scanner

Security scanner for CVE-2025-55182 - Critical RCE vulnerability in React Server Components

exploitationpayload-developmentpenetration-testing+3
9 months ago
CVE-2024-22515-File-Upload-Vulnerability preview

CVE-2024-22515-File-Upload-Vulnerability

GitHuborange-418/cve-2024-22515-file-upload-vulnerability

Proof-of-concept exploit for CVE-2024-22515, demonstrating arbitrary file upload and remote code execution in Agent DVR 5.1.6.0 via unverified sound…

exploitationpayload-developmentpenetration-testing+2
2 years ago
-CVE-2024-31211 preview

-CVE-2024-31211

GitHubabdurahmon3236/-cve-2024-31211

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

code-analysisexploit-frameworkspayload-development+3
2 years ago
Spring-Boot-Tomcat-CVE-2025-24813 preview

Spring-Boot-Tomcat-CVE-2025-24813

GitHubn0n-zer0/spring-boot-tomcat-cve-2025-24813

POC for CVE-2025-24813 using Spring-Boot

dynamic-analysis-sandboxingexploitationpayload-development+3
1 year ago
cve-2024-32002-submodule-rce preview

cve-2024-32002-submodule-rce

GitHubjakob-pennington/cve-2024-32002-submodule-rce

Proof-of-concept demonstrating CVE-2024-32002 remote code execution via malicious Git submodule hook, targeting Windows and macOS systems.

command-and-controlexploitationpayload-development+3
2 years ago
Previous1…565758…62Next