Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
MacroShop preview

MacroShop

GitHubkhr0x40sh/macroshop

Collection of scripts to aid in delivering payloads via Office Macros. Most are python. See http://khr0x40sh.wordpress.com for details.

payload-developmentpayload-generationpenetration-testing+2
408
10 years ago
MouseJack preview

MouseJack

GitHubsecurityward/mousejack

All the details and steps needed to perform tactical mousejacking using Autojack

exploitationpayload-generationred-teaming+2
157 years ago
CVE-2024-34716 preview

CVE-2024-34716

GitHubaelmokhtar/cve-2024-34716

Proof-of-concept exploit for CVE-2024-34716, a PNG-driven XSS to RCE chain in PrestaShop 8.1.5, enabling remote code execution via crafted image…

code-analysisexploitationpayload-generation+3
161 year ago
sqlmap-ai preview

sqlmap-ai

GitHubatiilla/sqlmap-ai

This script automates SQL injection testing using SQLMap with AI-powered decision making.

payload-generationpenetration-testingvulnerability-scanners+3
4497 months ago
CVE-2022-46485 preview

CVE-2022-46485

GitHubnevasec/cve-2022-46485

An issue in Data Illusion Survey Software Solutions NGSurvey v2.4.28 and below allows attackers to cause a Denial of Service (DoS) via a crafted…

exploitationpayload-generationpenetration-testing+2
3 years ago
CVE-2024-24590-ClearML-RCE-Exploit preview

CVE-2024-24590-ClearML-RCE-Exploit

GitHubrippsec/cve-2024-24590-clearml-rce-exploit

CVE-2024-24590 – ClearML RCE via unsafe pickle artifact deserialization (0.17.0–1.14.2)

command-and-controleducationexploitation+6
65 months ago
CVE-2019-14745 preview

CVE-2019-14745

GitHubxooxo/cve-2019-14745

weaponized radare2 vulnerability found by @CaptnBanana and blenk92

binary-exploitationexploitationpayload-generation+3
26 years ago
prestashop-exploits preview

prestashop-exploits

GitHubambionics/prestashop-exploits

Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)

exploitationpayload-generationpenetration-testing+2
498 years ago
CVE-2023-23397_EXPLOIT preview

CVE-2023-23397_EXPLOIT

GitHubbillskico/cve-2023-23397_exploit

Generates meeting requests taking advantage of CVE-2023-23397. This requires the outlook thick client to send.

educationexploitationlateral-movement+3
73 years ago
cve-2021-29447_auto-script preview

cve-2021-29447_auto-script

GitHubdavids52/cve-2021-29447_auto-script

This repo describes about cve-2021-29447 and a small script for exploiting automatically

educationexploitationpayload-generation+3
9 months ago
watchTowr-vs-FortiWeb-CVE-2025-25257 preview

watchTowr-vs-FortiWeb-CVE-2025-25257

GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

Detection artifact generator for FortiWeb CVE-2025-25257, exploiting unauthenticated SQL injection to achieve remote code execution via hex-encoded…

exploitationpayload-generationpenetration-testing+3
1001 year ago
watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882 preview

watchTowr-vs-Oracle-E-Business-Suite-CVE-2025-61882

GitHubwatchtowrlabs/watchtowr-vs-oracle-e-business-suite-cve-2025-61882

Generates detection artifacts for Oracle E-Business Suite CVE-2025-61882 by serving a reverse shell payload to verify pre-auth RCE.

exploitationpayload-generationpenetration-testing+3
5511 months ago
CVE-2015-1397-Magento-Shoplift preview

CVE-2015-1397-Magento-Shoplift

GitHubwytchwulf/cve-2015-1397-magento-shoplift

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

ctfexploitationpayload-generation+3
2 years ago
CVE-2021-44228-log4Shell preview

CVE-2021-44228-log4Shell

GitHubkali-dass/cve-2021-44228-log4shell

Java-based proof-of-concept exploit for CVE-2021-44228 (Log4Shell) enabling remote command execution, OS information gathering, and arbitrary…

command-and-controlexploitationpayload-generation+3
14 years ago
craftcms-vcard-exploit preview

craftcms-vcard-exploit

GitLabwguest/craftcms-vcard-exploit

This repository has details on a vulnerability found with the "vCard" plugin for CraftCMS 3.

educationexploitationpayload-generation+3
16 years ago
CVE-2025-8088 preview

CVE-2025-8088

GitHubwalidpyh/cve-2025-8088

Proof-of-concept demonstrating Alternate Data Stream (ADS) payload delivery via crafted WinRAR archives for educational research and controlled lab…

binary-exploitationeducationexploitation+2
41 year ago
heyserial preview
Archived

heyserial

GitHubmandiant/heyserial

Programmatically create hunting rules for deserialization exploitation with multiple keywords, gadget chains, object types, encodings, and rule types

curated-resourceseducationexploitation+6
1423 years ago
JNDI-Exploit-1.2-log4shell preview

JNDI-Exploit-1.2-log4shell

GitHub34zy/jndi-exploit-1.2-log4shell

Details : CVE-2021-44228

command-and-controlexploitationpayload-generation+3
4 years ago
Previous12Next