Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
CVE-2026-11112-XXE-via-SVG-Image-Upload preview

CVE-2026-11112-XXE-via-SVG-Image-Upload

GitHubgeorge0papasotiriou/cve-2026-11112-xxe-via-svg-image-upload

Demonstrates XXE via SVG upload with a vulnerable Flask/lxml parser and an exploit script for arbitrary file read, SSRF, and denial-of-service…

exploitationpayload-generationpenetration-testing+3
1 month ago
Zena-CVE-2021-45026 preview

Zena-CVE-2021-45026

GitHubjetp1ane/zena-cve-2021-45026

Proof-of-concept exploit for CVE-2021-45026 targeting Rocket Software Zena. Chains stored XSS to remote code execution via REST API task injection on…

command-and-controlexploitationpayload-generation+3
45 months ago
vBulletin_Routestring-RCE preview

vBulletin_Routestring-RCE

GitHubludy-dev/vbulletin_routestring-rce

PoC exploit for CVE-2019-16759 enabling remote code execution on vBulletin 5.0.0–5.6.2 via malicious POST request due to input validation flaw.

exploitationpayload-generationpenetration-testing+2
15 years ago
Log4jUnifi preview

Log4jUnifi

GitHubpuzzlepeaches/log4junifi

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

exploitationpayload-generationpenetration-testing+3
1692 years ago
Deathnote preview

Deathnote

GitHubmalwareman007/deathnote

Proof of Concept of CVE-2022-30190

command-and-controlexploitationpayload-generation+3
383 years ago
CVE-2026-23744-MCPJAM-RCE-exploit preview

CVE-2026-23744-MCPJAM-RCE-exploit

GitHubdahalsamir/cve-2026-23744-mcpjam-rce-exploit

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an…

exploitationpayload-generationpenetration-testing+2
3 months ago
CVE-2023-27163-AND-Mailtrail-v0.53 preview

CVE-2023-27163-AND-Mailtrail-v0.53

GitHubhusenjandev/cve-2023-27163-and-mailtrail-v0.53

Requests Baskets (CVE-2023-27163) and Mailtrail v0.53

exploitationpayload-generationpenetration-testing+3
23 years ago
CVE-2023-26039 preview

CVE-2023-26039

GitHubungabunga-ctf/cve-2023-26039

CVE-2023-26039 - ZoneMinder. Any authenticated user can construct an api command to execute any shell command as the web user.

command-and-controlexploitationpayload-generation+3
1 month ago
CVE-2021-45428-Defacer preview

CVE-2021-45428-Defacer

GitHubprojectforsix/cve-2021-45428-defacer

Python-based exploit for CVE-2021-45428, targeting a specific web application vulnerability for penetration testing and security assessment.

exploitationpayload-generationpenetration-testing+2
2 years ago
CVE-2021-44228_dockernize preview

CVE-2021-44228_dockernize

GitHubqw3rtyou/cve-2021-44228_dockernize

Dockerized lab environment for safely practicing CVE-2021-44228 (Log4Shell) exploitation. Includes attacker LDAP server and vulnerable Java…

educationexploitationlabs-practice+3
11 year ago
cve-2021-3164 preview

cve-2021-3164

GitHubrmccarth/cve-2021-3164

Church Rota version 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permission in order to…

exploitationpayload-generationpenetration-testing+2
25 years ago
CVE-2021-21315-POC preview

CVE-2021-21315-POC

GitHubxmohamed0/cve-2021-21315-poc

Proof-of-concept exploit for CVE-2021-21315, demonstrating remote code execution in a web application framework. Intended for security testing and…

exploitationpayload-generationpenetration-testing+2
4 years ago
CVE-2018-16156-Exploit preview

CVE-2018-16156-Exploit

GitHubsecurifera/cve-2018-16156-exploit

Exploit for CVE-2018-16156 targeting a remote code execution vulnerability in a web application, providing a proof-of-concept payload for security…

exploitationpayload-generationpenetration-testing+2
17 years ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHubpimps/cve-2017-1000486

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

exploitationpayload-generationpenetration-testing+3
952 years ago
CVE-2015-9235_JWT_key_confusion preview

CVE-2015-9235_JWT_key_confusion

GitHubnxvh1337/cve-2015-9235_jwt_key_confusion

automate CVE-2015-9235 exploitation

educationexploitationpayload-generation+3
32 years ago
CVE-2018-19246 preview

CVE-2018-19246

GitHubneowans/cve-2018-19246

Proof-of-concept exploit for CVE-2018-19246 with Docker-based deployment and Pocsuite integration for automated web application vulnerability testing.

exploitationpayload-generationpenetration-testing+2
14 years ago
CVE-2021-31630 preview

CVE-2021-31630

GitHubjunnythemarksman/cve-2021-31630

Modified proof-of-concept exploit for CVE-2021-31630 targeting a web application vulnerability with reverse shell payload generation and remote code…

exploitationpayload-generationpenetration-testing+3
2 years ago
Log4j preview

Log4j

GitHubisuruwa/log4j

Scanner and proof-of-concept exploit for Log4j RCE (CVE-2021-44228). Creates a vulnerable application and runs the exploit with a netcat listener.

exploitationpayload-generationpenetration-testing+2
64 years ago
Previous123Next