Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
ExchangeRelayX preview

ExchangeRelayX

GitHubquickbreach/exchangerelayx

An NTLM relay tool to the EWS endpoint for on-premise exchange servers. Provides an OWA for hackers.

authenticationemail-securityexploitation+7
305
8 years ago
BlueDucky preview

BlueDucky

GitHubsergeb250/blueducky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The…

bluetooth-securityexploitationpayload-generation+3
111 months ago
CVE-2023-50643 preview

CVE-2023-50643

GitHubgiovannipajeu1/cve-2023-50643

CVE-2023-50643

binary-exploitationexploitationpayload-generation+3
82 years ago
CVE-2024-23743 preview

CVE-2024-23743

GitHubgiovannipajeu1/cve-2024-23743
exploitationpayload-generationshellcode+2
12 years ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubpentestical/cve-2021-22204
exploitationpayload-generationremote-access-tool+2
35 years ago
CVE-2026-23744-PoC preview

CVE-2026-23744-PoC

GitHubboroeurnprach/cve-2026-23744-poc

CVE-2026-23744 - Versions 1.4.2 and earlier of MCPJam inspector are vulnerable to remote code execution (RCE). Because the tool listens on 0.0.0.0 by…

exploitationpayload-generationpenetration-testing+3
92 months ago
CVE-2021-3560 preview

CVE-2021-3560

GitHub0dayninja/cve-2021-3560

Polkit D-Bus Authentication Bypass Exploit

authentication-authorizationexploitationpayload-generation+3
95 years ago
CVE-2018-0114 preview

CVE-2018-0114

GitHuberemiel/cve-2018-0114

python2.7 script for JWT generation

authenticationencryption-decryption-toolsexploitation+3
25 years ago
OpenEMR_Vulnerabilities preview

OpenEMR_Vulnerabilities

GitHubemreovunc/openemr_vulnerabilities

OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious php codes.

exploitationpayload-generationpenetration-testing+2
145 years ago
Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter preview

Nuclei-Template-Exploit-F5-BIG-IP-iControl-REST-Auth-Bypass-RCE-Command-Parameter

GitHubmrcl0wnlab/nuclei-template-exploit-f5-big-ip-icontrol-rest-auth-bypass-rce-command-parameter

CVE-2022-1388 is an authentication bypass vulnerability in the REST component of BIG-IP’s iControl API that was assigned a CVSSv3 score of…

command-and-controlexploitationpayload-generation+3
64 years ago
CVE-2026-23744-MCPJAM-RCE-exploit preview

CVE-2026-23744-MCPJAM-RCE-exploit

GitHubdahalsamir/cve-2026-23744-mcpjam-rce-exploit

This Python proof-of-concept targets a vulnerable MCP (Model Context Protocol) service exposed by the target application. The vulnerability allows an…

exploitationpayload-generationpenetration-testing+2
2 months ago
CVE-2025-1015 preview

CVE-2025-1015

GitHubr3m0t3nu11/cve-2025-1015

an attacker to create and export an address book containing a malicious payload in a field. For example, in the “Other” field of the Instant…

exploitationpayload-generationphishing-tools+3
31 year ago
cve-2018-6574-exploit preview

cve-2018-6574-exploit

GitHubzerbaliy3v/cve-2018-6574-exploit

CVE-2018-6574 this vulnerability impacts Golang go get command and allows an attacker to gain code execution on a system by installing a malicious…

exploitationpayload-generationsupply-chain-security+2
2 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubshubhamkanhere307/cve-2024-21413

This script is the Proof of Concept (PoC) of the CVE-2024-21413, a significant security vulnerability discovered in the Microsoft Windows Outlook…

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2024-50986 preview

CVE-2024-50986

GitHubriftsandroses/cve-2024-50986

An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted DLL file (DLL Hijacking)

binary-exploitationexploitationpayload-generation+4
1 year ago
mbanyamer-Microsoft-PowerPoint-Use-After-Free-Remote-Code-Execution-RCE preview

mbanyamer-Microsoft-PowerPoint-Use-After-Free-Remote-Code-Execution-RCE

GitHubmbanyamer/mbanyamer-microsoft-powerpoint-use-after-free-remote-code-execution-rce

This repository contains a Proof of Concept (PoC) exploit for the **CVE-2025-47175** vulnerability found in Microsoft PowerPoint. The vulnerability…

binary-exploitationeducationexploitation+3
111 year ago
CVE-2023-41425-wonderCMS_RCE preview

CVE-2023-41425-wonderCMS_RCE

GitHubthefizzyfish/cve-2023-41425-wondercms_rce

CVE-2023-41425 - Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code via a…

educationexploitationpayload-generation+3
21 year ago
CVE-2023-44760_ConcreteCMS-Stored-XSS---TrackingCodes preview

CVE-2023-44760_ConcreteCMS-Stored-XSS---TrackingCodes

GitHubsromanhu/cve-2023-44760_concretecms-stored-xss---trackingcodes

Multiple Cross Site Scripting vulnerability in ConcreteCMS v.9.2.1 allows a local attacker to execute arbitrary code via a crafted script to the…

educationexploitationpayload-generation+3
2 years ago
Previous12345Next