Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
apfell preview

apfell

GitHubmythicagents/apfell

JavaScript for Automation (JXA) macOS agent

command-and-controlexploit-frameworkspayload-development+3
1052 months ago
CVE-2023-2033 preview

CVE-2023-2033

GitHubmistymntncop/cve-2023-2033

JavaScript exploit targeting CVE-2023-2033 for proof-of-concept testing and vulnerability validation in web applications.

exploitationpayload-developmentpenetration-testing+2
643 years ago
CVE-2022-29078 preview

CVE-2022-29078

GitHubl0n3m4n/cve-2022-29078

Serverside Template Injection (SSTI) RCE - THM challenge "whiterose"

ctfexploitationpayload-development+3
31 year ago
ditto preview

ditto

GitHubairbus-cert/ditto

Obfuscates PowerShell and JavaScript scripts using tree-sitter-based parsing with multiple configurable impostor profiles for stealth, size, and…

code-analysismalware-analysispayload-development+2
491 month ago
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
4817 days ago
CVE-2019-0752 preview

CVE-2019-0752

GitHubedxsh/cve-2019-0752

Proof-of-concept exploit for CVE-2019-0752 targeting Internet Explorer 11 on Windows 10 x64. Uses JavaScript DOM manipulation and special address…

exploitationpayload-developmentpenetration-testing+2
25 years ago
CVE-2022-30507-PoC preview

CVE-2022-30507-PoC

GitHubyosef0x01/cve-2022-30507-poc

PoC for Arbitrary Code Execution in Notable

exploitationpayload-developmentpenetration-testing+2
43 years ago
CVE-2026-27574-OneUptime-RCE preview

CVE-2026-27574-OneUptime-RCE

GitHubmbanyamer/cve-2026-27574-oneuptime-rce

Proof-of-concept exploit for CVE-2026-27574, a critical code injection in OneUptime enabling remote code execution and environment variable leakage.

exploitationpayload-developmentpenetration-testing+3
17 months ago
CVE-2024-28397-Js2Py-RCE preview

CVE-2024-28397-Js2Py-RCE

GitHubd3ltaformation/cve-2024-28397-js2py-rce

This repository contains a Proof of Concept (PoC) for CVE-2024-28397, a vulnerability in the js2py library allowing a sandbox escape to achieve…

educationexploitationpayload-development+4
1 year ago
Node.js-CVE-2017-5941 preview

Node.js-CVE-2017-5941

GitHubturnernator1/node.js-cve-2017-5941

Educational demo of Node.js insecure deserialization (CVE-2017-5941) with cookie-based payload injection and reverse shell exploitation for security…

educationexploitationpayload-development+3
7 months ago
CVE-2026-29053 preview

CVE-2026-29053

GitHubk3ystr0k3r/cve-2026-29053

Python PoC and version scanner for CVE-2026-29053, an authenticated RCE in Ghost CMS below 6.19.1 via malicious Handlebars theme templates.

exploitationpayload-developmentpenetration-testing+5
16 days ago
CVE-2023-6000-POC preview

CVE-2023-6000-POC

GitHubronf98/cve-2023-6000-poc

This vulnerability displays an XSS flaw in a WordPress popup plugin, allowing attackers to inject malicious JavaScript through a stored XSS

exploitationpayload-developmentpenetration-testing+3
11 year ago
singularity preview

singularity

GitHubnccgroup/singularity

A DNS rebinding attack framework.

dns-analysisexploitationinformation-gathering+6
1.3k2 months ago
CVE-2024-4367-PoC preview

CVE-2024-4367-PoC

GitHublourc0d3/cve-2024-4367-poc

CVE-2024-4367 & CVE-2024-34342 Proof of Concept

exploitationpayload-developmentpenetration-testing+2
2032 years ago
CVE-2023-22621-POC preview

CVE-2023-22621-POC

GitHubsofianeelhor/cve-2023-22621-poc

CVE-2023-22621: SSTI to RCE by Exploiting Email Templates affecting Strapi Versions <=4.5.5

exploitationpayload-developmentpenetration-testing+3
243 years ago
Wildfire preview

Wildfire

GitHubdefineid/wildfire

CVE-2026-39154, Stored XSS in CometChat JS SDK

api-securityexploitationpayload-development+4
1 month ago
poc-cve-2025-55182 preview

poc-cve-2025-55182

GitHubkoadt/poc-cve-2025-55182

This repository contains a POC of CVE-2025-55182, a critical (CVSS score 10.0) pre-authentication remote code execution vulnerability affecting React…

code-analysisctfdynamic-analysis-sandboxing+7
156 months ago