Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
387 results
PoC-CVE-2025-24071 preview

PoC-CVE-2025-24071

GitHubdaemon-404/poc-cve-2025-24071

Python PoC for CVE-2025-24071 that crafts a .library-ms file to coerce Windows Explorer into leaking NetNTLMv2 hashes over SMB for capture and…

ctfexploitationlabs-practice+5
4 days ago
ip-camera-research preview

ip-camera-research

GitHubamiraliuks/ip-camera-research

Security research on a consumer IP camera built on the Fullhan FH8626V100 SoC (model AJL30PG0803).

embedded-systems-securityexploitationexploit-frameworks+6
11 month ago
burpFakeIP preview

burpFakeIP

GitHubthekingofduck/burpfakeip

Burp Suite extension for spoofing IP addresses in HTTP requests, enabling testing of server-side IP restrictions and bypassing IP-based access…

ids-ips-evasionimpersonation-toolspenetration-testing+2
1.7k3 years ago
honeypot-auditor preview

honeypot-auditor

GitHubmziqudhd92/honeypot-auditor

Does This Look Like An Honeypot? (DTLLAH) Multi-protocol CLI that fingerprints whether a target IP behaves like a low-interaction honeypot — Shodan…

defensive-toolsinformation-gatheringnetwork-security+3
92 days ago
portscan-CVE-2026-41940 preview

portscan-CVE-2026-41940

GitHubamirrezamarzban/portscan-cve-2026-41940

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

information-gatheringnetwork-securitypenetration-testing+3
14 months ago
CVE-2025-57457 preview

CVE-2025-57457

GitHubrestdone/cve-2025-57457

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

command-and-controlexploitationpenetration-testing+2
11 months ago
CVE-2026-33752 preview

CVE-2026-33752

GitHubredyank/cve-2026-33752

Demonstrates a redirect-based SSRF vulnerability in curl_cffi allowing internal network access, with PoC code and analysis of TLS impersonation…

exploitationinformation-gatheringpenetration-testing+2
5 months ago
CVE-2025-55616 preview

CVE-2025-55616

GitHublivepwn/cve-2025-55616

Exploit for CVE-2025-55616, a local RCE in Zsh via history expression, achieving arbitrary code execution with user privileges.

binary-exploitationexploitationpenetration-testing+2
211 months ago
tapo-c260-rce preview

tapo-c260-rce

GitHubl0lsec/tapo-c260-rce

PoC exploit chain for TP-Link Tapo C260 camera — CVE-2026-0651/0652/0653. Research by @spaceraccoon.

command-and-controlembedded-systems-securityexploitation+7
26 months ago
CVE-2026-6274 preview

CVE-2026-6274

GitHubbugresearch/cve-2026-6274

Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static…

authenticationexploitationpenetration-testing+2
4 months ago
CVE-2021-44521 preview

CVE-2021-44521

GitHubwoodenklaas/cve-2021-44521

Automated proof-of-concept exploit for CVE-2021-44521, enabling remote code execution on Apache Cassandra via user-defined functions. Executes…

exploitationpenetration-testingremote-access-trojan+2
104 years ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubkondordevsecuritycorp/cve-2026-34197

Exploit for Apache ActiveMQ RCE via Jolokia API (CVE-2026-34197) with command output capture, mass scanning, and auto-exploitation.

exploitationlabs-practicepayload-generation+4
25 months ago
Tell-Me-Root preview

Tell-Me-Root

GitHubparameciumzhang/tell-me-root

Batch scanner for CVE-2026-24061 Telnet authentication bypass, with port liveness checks and automated payload attempts for authorized penetration…

authenticationexploitationnetwork-security+2
217 months ago
CVE-2021-29441 preview

CVE-2021-29441

GitHubbysinks/cve-2021-29441

Exploit for CVE-2021-29441 in Alibaba Nacos, enabling unauthorized addition of user accounts by sending crafted requests to the target IP.

authenticationexploitationpenetration-testing+2
24 years ago
DataEase_Postgresql_JDBC_Bypass-CVE-2025-49002 preview

DataEase_Postgresql_JDBC_Bypass-CVE-2025-49002

GitHubfeng-huang-0520/dataease_postgresql_jdbc_bypass-cve-2025-49002

Proof-of-concept exploit for CVE-2025-49002, a remote code execution vulnerability in DataEase via PostgreSQL JDBC bypass, including a crafted HTTP…

exploitationpenetration-testingred-teaming+2
111 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubbrainbob/cve-2026-24061

Python-based exploit for CVE-2026-24061, targeting a network service with customizable port and debug mode for security testing.

exploitationnetwork-securitypenetration-testing+2
7 months ago
CVE-2023-48022 preview

CVE-2023-48022

GitHub0x656565/cve-2023-48022

Exploit for CVE-2023-48022, adapted from Bishop Fox research. Configure IP, port, and payload to execute against vulnerable Ray instances.

exploitationpayload-developmentpenetration-testing+2
22 years ago
RunPE preview

RunPE

GitHubnettitude/runpe

C# Reflective loader for unmanaged binaries.

adversarial-attackimpersonation-toolspayload-development+6
4473 years ago
Previous12…22Next