Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
cve-2023-23397-purple-team preview

cve-2023-23397-purple-team

GitHubpraneethnaidu1910-cmd/cve-2023-23397-purple-team

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

educationemail-securityexploitation+3
7 days ago
CVE-2025-56218 preview

CVE-2025-56218

GitHubsaykino/cve-2025-56218

Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing…

curated-resourceseducationphishing+2
10 months ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF + Open Email Relay in Chamilo LMS via install.ajax.php — CVSS 7.5

exploitationphishingreconnaissance+2
4 months ago
CVE-2025-40778 preview

CVE-2025-40778

GitHubnehkark/cve-2025-40778

Proof-of-concept demonstrating DNS cache poisoning via additional record injection in BIND 9, with tools to validate and exploit CVE-2025-40778 for…

dns-analysiseducationexploitation+3
510 months ago
Ashwesker-CVE-2026-21509 preview

Ashwesker-CVE-2026-21509

GitHubkimstars/ashwesker-cve-2026-21509

Proof-of-concept exploit for Microsoft Office security feature bypass (CVE-2026-21509). Generates malicious DOCX files with embedded OLE objects to…

exploitationmalware-analysispayload-generation+3
117 months ago
CVE-2025-60378 preview

CVE-2025-60378

GitHubajansha/cve-2025-60378

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

educationexploitationphishing+3
10 months ago
CVE-2025-55903 preview

CVE-2025-55903

GitHubajansha/cve-2025-55903

Proof of concept for CVE-2025-55903, a stored HTML injection in PerfexCRM allowing authenticated users to inject malicious HTML into invoices and…

exploitationphishingvulnerability-analysis+2
10 months ago
CVE-2026-33149-PoC preview

CVE-2026-33149-PoC

GitHubfilipegaudard/cve-2026-33149-poc

Proof-of-concept exploit for CVE-2026-33149, a Host header injection in Tandoor Recipes that enables invite link poisoning and cache poisoning.…

exploitationpenetration-testingphishing+3
5 months ago
PoC-CVE-2026-20841 preview

PoC-CVE-2026-20841

GitHubelenichristopoulou/poc-cve-2026-20841

Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad remote code execution vulnerability, using a crafted .md file and social engineering…

exploitationphishingsocial-engineering+1
6 months ago
CVE-2023-48104 preview

CVE-2023-48104

GitHube1tex/cve-2023-48104

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

exploitationphishingvulnerability-analysis+2
2 years ago
detections preview

detections

GitHubdelivr-to/detections

A home for detection content developed by the delivr.to team

email-securityintrusion-detectionmalware-analysis+2
751 year ago
CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form preview

CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form

GitHubgeorge0papasotiriou/cve-2026-11113-smtp-header-injection-in-contact-form

Proof-of-concept exploit for CVE-2026-11113, demonstrating SMTP header injection in a Flask contact form via unsanitized email input; includes…

educationemail-securityexploitation+4
1 month ago
tryhackme-monikerlink-writeup preview

tryhackme-monikerlink-writeup

GitHubomarmahmoud1024/tryhackme-monikerlink-writeup

TryHackMe Moniker Link (CVE-2024-21413) walkthrough: Outlook Protected View bypass leading to NTLMv2 hash capture via a crafted moniker link.

ctfeducationexploitation+4
29 days ago
CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Moniker-Link-Vulnerability

GitHubh4cknain/cve-2024-21413-microsoft-outlook-moniker-link-vulnerability

Lab write-up analyzing CVE-2024-21413 Outlook Moniker Link exploitation, NetNTLMv2 credential leakage via SMB, detection with YARA/Wireshark, and…

educationemail-securityexploitation+6
29 days ago
CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval- preview

CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval-

GitHubgeorge0papasotiriou/cve-2026-22005-oauth-2.0-device-code-phishing-short-interval-

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

authentication-authorizationeducationexploitation+4
1 month ago
CVE-2026-20841 preview

CVE-2026-20841

GitHubtangent65536/cve-2026-20841

PoC for the "Windows Notepad RCE"

exploitationpayload-generationphishing
26 months ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubmseymend/cve-2024-21413

CVE-2024-21413 Açığını Kullanarak Giriş Bilgilerini Alma

email-securityexploitationinformation-gathering+2
2 years ago
Estudo-de-Caso-CVE-2024-21413 preview

Estudo-de-Caso-CVE-2024-21413

GitHubpedro-lucas-melo/estudo-de-caso-cve-2024-21413

Um estudo de caso do CVE-2024-21413. Usado como parâmetro a sala do TryHackMe Moniker Link (CVE-2024-21413). Feito edições com claude code no exploit.

ctfeducationemail-security+6
5 months ago
Previous1234567Next