Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

NewestRelevanceMost popularRecently updated
146 results
follina preview

follina

GitHubnoxtal/follina

All about CVE-2022-30190, aka follina, that is a RCE vulnerability that affects Microsoft Support Diagnostic Tools (MSDT) on Office apps such as…

command-and-controlexploitationpayload-generation+3
214 years ago
mutillidae preview

mutillidae

GitHubwebpwnized/mutillidae

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

ctfeducationlabs-practice+3
1.5k1 month ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsinformation-gatheringpenetration-testing+4
4 days ago
threat-dragon preview

threat-dragon

GitHubowasp/threat-dragon

An open source threat modeling tool from OWASP

api-securitycloud-securitydefensive-tools+5
1.6k1 day ago
Rail-OT-Protector preview

Rail-OT-Protector

GitHubspinfosecurity/rail-ot-protector

Rail-OT-Protector (ROP) — free, open-source cybersecurity scanning tool for rail and transit OT/SCADA networks. PowerShell + Bash scanners for…

defensive-toolsinformation-gatheringnetwork-security+6
13 days ago
omigood preview

omigood

GitHubmarcosimioni/omigood

OMIGOD! OM I GOOD? A free scanner to detect VMs vulnerable to one of the "OMIGOD" vulnerabilities discovered by Wiz's threat research team,…

cloud-securityexploitationinformation-gathering+3
204 years ago
redis-poc preview

redis-poc

GitHubberabuddies/redis-poc

RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0, 8.8.1

binary-exploitationdatabase-securityexploitation+3
50127 days ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubaleewyy/cve-2025-49132

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

database-securityexploitationinformation-gathering+3
2 months ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubdwisiswant0/cve-2025-49844

Proof-of-concept exploit for Redis 8.2.1 Lua parser use-after-free, racing garbage collection via crafted loadstring calls to achieve remote code…

binary-exploitationdatabase-securityexploitation+2
6610 months ago
CVE-2024-48427 preview

CVE-2024-48427

GitHubvighneshnair7/cve-2024-48427
database-securityexploitationinformation-gathering+3
11 year ago
CanaryHunter preview

CanaryHunter

GitHubc0axx/canaryhunter

Canary Hunter aims to be a quick PowerShell script to check for Common Canaries in various formats generated for free on canarytokens.org

adversarial-attackcloud-infrastructure-securityconfiguration-auditing+4
1373 years ago
Quasar preview
Archived

Quasar

GitHubquasar/quasar

Remote Administration Tool for Windows

command-and-controlpenetration-testingpost-exploitation+2
9.9k2 years ago
codoforum preview

codoforum

GitHubprasanthc41m/codoforum

CVE-2020-5842 Stored XSS Vulnerability in Codoforum 4.8.3

educationexploitationinformation-gathering+3
13 years ago
DVAP preview

DVAP

GitHubsonuoffsec/dvap

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

ai-securityctfeducation+4
272 months ago
telegram_bbbot preview
Archived

telegram_bbbot

GitHubmaddevsio/telegram_bbbot

Telegram Bug Bounty Bot

crawlerinformation-gatheringosint+3
329 years ago
CVE-2024-10924-Wordpress-Docker preview

CVE-2024-10924-Wordpress-Docker

GitHubtrackflaw/cve-2024-10924-wordpress-docker

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

authenticationexploitationlabs-practice+3
31 year ago
CrackAVFee preview

CrackAVFee

GitHubbyt3n33dl3/crackavfee

it's a CVE-2022-3368 (Patched), but feel free to use it for check any outdated software or reseach

binary-exploitationeducationexploitation+2
72 years ago
CVE-2023-38571-a-macOS-TCC-bypass-in-Music-and-TV preview

CVE-2023-38571-a-macOS-TCC-bypass-in-Music-and-TV

GitHubgergelykalman/cve-2023-38571-a-macos-tcc-bypass-in-music-and-tv

Exploit for CVE-2023-38571

exploitationpenetration-testingprivilege-escalation+2
132 years ago
Previous12…9Next