Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
179 results
Vulnerable-Docker-Engine preview

Vulnerable-Docker-Engine

GitHubsne-m23-sn/vulnerable-docker-engine

This exploit offers an in-depth look at the CVE-2021-41091 security vulnerability and provides a step-by-step guide on how to utilize the exploit…

container-securityeducationexploitation+3
2
2 years ago
CVE-2010-1240 preview

CVE-2010-1240

GitHubasepsaepdin/cve-2010-1240

Educational proof-of-concept demonstrating how to embed a Meterpreter backdoor into a PDF file exploiting CVE-2010-1240, with step-by-step Metasploit…

exploit-frameworkspayload-developmentpenetration-testing+3
12 years ago
CVE-2026-32136_exploit preview

CVE-2026-32136_exploit

GitHub0xdak/cve-2026-32136_exploit

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

authentication-authorizationeducationexploitation+4
4 months ago
vsftpd-2.3.4---Backdoor-Command-Execution preview

vsftpd-2.3.4---Backdoor-Command-Execution

GitHubtshaq17/vsftpd-2.3.4---backdoor-command-execution

vsftpd 2.3.4 (CVE-2011-2523) a critical vulnerability that leads to Reverse Root Shell. In this repo I will do a PoC how to exploit it step by step,…

educationexploitationpayload-generation+3
7 months ago
Bypass-File-Upload-on-Koken-CMS preview

Bypass-File-Upload-on-Koken-CMS

GitHubv1n1v131r4/bypass-file-upload-on-koken-cms

This repo explain how to bypass File Upload Restrictions on Koken CMS

educationpenetration-testingvulnerability-analysis+1
16 years ago
CVE-2021-4773 preview

CVE-2021-4773

GitHubalexs18/cve-2021-4773

Step-by-step tutorial demonstrating how to set up a vulnerable Apache 2.4.49 environment and exploit CVE-2021-41773 path traversal using Kali Linux…

educationexploitationlabs-practice+3
10 months ago
log4j-CVE-2021-44228-test preview

log4j-CVE-2021-44228-test

GitHubkossatzd/log4j-cve-2021-44228-test

demo project to highlight how to execute the log4j (CVE-2021-44228) vulnerability

educationexploitationpayload-generation+3
4 years ago
CVE-2024-44541 preview

CVE-2024-44541

GitHubpointedsec/cve-2024-44541

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

educationexploitationpassword-cracking+3
1 year ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
39 days ago
CVE-2019-18634-writeup preview

CVE-2019-18634-writeup

GitHubdevteam6rabbit/cve-2019-18634-writeup

analysis of the sudo buffer overflow affect sudo version <1.8.26 and how to use GCC to compile publicly availible exploits

binary-exploitationctfeducation+4
7 months ago
CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE preview

CVE-2026-1281-CVE-2026-1340-Ivanti-EPMM-RCE

GitHubyunfeige18/cve-2026-1281-cve-2026-1340-ivanti-epmm-rce

A simple demo application that shows how to reproduce the Ivanti EPMM pre-auth RCE vulnerability (CVE-2026-1281 / CVE-2026-1340) for educational and…

educationexploitationpenetration-testing+2
36 months ago
pentestproxy preview
Archived

pentestproxy

GitHubshiva108/pentestproxy

Scripts for: How to Build a Covert Pentesting Infrastructure Almost Free

command-and-controldns-analysisids-ips-evasion+4
227 months ago
CSRF-to-RCE-on-Backdrop-CMS preview

CSRF-to-RCE-on-Backdrop-CMS

GitHubv1n1v131r4/csrf-to-rce-on-backdrop-cms

Proof-of-concept exploit for CSRF to RCE in Backdrop CMS 1.20 (CVE-2021-45268) using malicious plugin upload.

exploitationpenetration-testingred-teaming+3
84 years ago
CVE-2024-46377 preview

CVE-2024-46377

GitHubvidura2/cve-2024-46377

Python PoC script exploiting an arbitrary file upload vulnerability in Best House Rental Management System 1.0 to upload a PHP web shell and execute…

exploitationpayload-generationpenetration-testing+2
21 year ago
CVE-2022-0847-Exploit-Implementation preview

CVE-2022-0847-Exploit-Implementation

GitHubjoeymeech/cve-2022-0847-exploit-implementation

Using CVE-2022-0847, "Dirty Pipe Exploit", to pop a reverse bash shell for arbitrary code execution on a foreign machine.

binary-exploitationexploitationpayload-development+3
13 years ago
CVE-2022-32199 preview

CVE-2022-32199

GitHubtoxich4/cve-2022-32199

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

exploitationpenetration-testingred-teaming+2
13 years ago
CVE-2018-20250 preview

CVE-2018-20250

GitHubaeolustf/cve-2018-20250

Generates malicious RAR archives automatically to exploit CVE-2018-20250 and achieve code execution via WinRAR ACE path traversal.

exploitationpayload-generationpenetration-testing+2
7 years ago
CVE-2018-20250 preview

CVE-2018-20250

GitHublikekabin/cve-2018-20250

Python exploit script for CVE-2018-20250 that generates a malicious RAR archive to achieve code execution via WinRAR's ACE file extraction…

exploitationpayload-generationpenetration-testing+2
7 years ago
Previous123…10Next