Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
CVE-2024-30270-PoC preview

CVE-2024-30270-PoC

GitHubalchemist3dot14/cve-2024-30270-poc

The script exploits Mailcow vulnerabilities via XSS and RCE, emphasizing the need for robust security measures and responsible usage to enhance web…

exploitationpayload-developmentpenetration-testing+3
4
2 years ago
CVE-2019-11043 preview

CVE-2019-11043

GitHubfairyming/cve-2019-11043

Proof-of-concept exploit for CVE-2019-11043, a PHP-FPM underflow vulnerability, built on the pocsuite framework for automated web application…

exploitationpayload-developmentpenetration-testing+2
16 years ago
cve-2025-64446-fortiweb-exploit preview

cve-2025-64446-fortiweb-exploit

GitHuban5i/cve-2025-64446-fortiweb-exploit

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

educationexploitationpayload-development+5
19 months ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5502 years ago
CVE-2022-36067-vm2-POC-webapp preview

CVE-2022-36067-vm2-POC-webapp

GitHub0x1nsomnia/cve-2022-36067-vm2-poc-webapp

Proof-of-concept web application demonstrating CVE-2022-36067, a vm2 sandbox escape, enabling remote code execution by uploading exploit code to a…

exploitationpayload-developmentpenetration-testing+2
23 years ago
CVE-2024-5246 preview

CVE-2024-5246

GitHubabdurahmon3236/cve-2024-5246

Proof-of-concept Python script demonstrating authenticated remote code execution in NETGEAR ProSAFE Network Management System via vulnerable Apache…

educationexploitationpayload-development+3
22 years ago
CVE-2018-14667 preview

CVE-2018-14667

GitHubzeroto01/cve-2018-14667

Proof-of-concept exploit for CVE-2018-14667 with a Windows calc payload, demonstrating remote code execution in a web application context.

educationexploitationpayload-development+3
27 years ago
PoC_CVE-2020-9484 preview

PoC_CVE-2020-9484

GitHubsavsch/poc_cve-2020-9484

PoC exploit for CVE-2020-9484, and a vulnerable web application for its demonstration

educationexploitationpayload-development+3
11 year ago
cve-2017-5123 preview

cve-2017-5123

GitHubnabilboudra/cve-2017-5123

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

binary-exploitationcommand-and-controleducation+5
9 months ago
CVE-2024-2054 preview

CVE-2024-2054

GitHubmadan301/cve-2024-2054

Proof-of-concept exploit for CVE-2024-2054, demonstrating insecure deserialization RCE in Artica-Proxy administrative web application. Includes…

educationexploitationpayload-development+3
2 years ago
CVE-2020-2555 preview

CVE-2020-2555

GitHuby4er/cve-2020-2555

Weblogic com.tangosol.util.extractor.ReflectionExtractor RCE

exploitationpayload-developmentvulnerability-analysis+1
1773 years ago
msdt-follina preview

msdt-follina

GitHubjohnhammond/msdt-follina

Generates a malicious Microsoft Word document exploiting the MS-MSDT 'Follina' vulnerability to execute arbitrary commands or stage payloads via an…

command-and-controlexploitationpayload-development+2
1.6k4 years ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9884 months ago
XSS-Payloads preview

XSS-Payloads

GitHuborwagodfather/xss-payloads
payload-developmentpenetration-testingvulnerability-analysis+2
1967 months ago
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

dynamic-code-analysiseducationencryption-decryption-tools+7
472 months ago
Spring-Kafka-POC-CVE-2023-34040 preview

Spring-Kafka-POC-CVE-2023-34040

GitHubcontrast-security-oss/spring-kafka-poc-cve-2023-34040

POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040

exploitationpayload-developmentvulnerability-analysis+1
454 months ago
foxpwn preview

foxpwn

GitHubsaelo/foxpwn

Exploit code for CVE-2016-9066

exploitationpayload-developmentvulnerability-analysis+1
449 years ago
fastjson-1.2.58-rce preview

fastjson-1.2.58-rce

GitHubjas502n/fastjson-1.2.58-rce

fastjson-1.2.58-rce with h2 database

exploitationpayload-developmentvulnerability-analysis+1
347 years ago
Previous12345Next