Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
51 results
Bad-Pdf preview

Bad-Pdf

GitHubdeepzec/bad-pdf

Steal Net-NTLM Hash using Bad-PDF

educationexploitationphishing-tools+1
1.2k10 months ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubka7ana/cve-2023-23397

Simple PoC in PowerShell for CVE-2023-23397

authenticationexploitationpenetration-testing+3
403 years ago
CVE-2023-33977 preview

CVE-2023-33977

GitHubmnqazi/cve-2023-33977

Read more at Medium

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
PoC-CVE-2022-30190 preview

PoC-CVE-2022-30190

GitHubjmousqueton/poc-cve-2022-30190

POC CVE-2022-30190 : CVE 0-day MS Offic RCE aka msdt follina

command-and-controlexploitationlateral-movement+4
1574 years ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubduy-31/cve-2024-21413

Microsoft Outlook Information Disclosure Vulnerability (leak password hash) - Expect Script POC

educationemail-securityexploitation+3
1572 years ago
CVE-2022-44666 preview

CVE-2022-44666

GitHubj00sean/cve-2022-44666

Write-up for another forgotten Windows vulnerability (0day): Microsoft Windows Contacts (VCF/Contact/LDAP) syslink control href attribute escape,…

exploitationpayload-developmentphishing-tools+2
1543 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubtrackflaw/cve-2023-23397

Simple PoC of the CVE-2023-23397 vulnerability with the payload sent by email.

email-securityexploitationpassword-attacks+3
1323 years ago
CVE-2025-2783 preview

CVE-2025-2783

GitHubalchemist3dot14/cve-2025-2783

Simulated PoC for CVE-2025-2783 — a sandbox escape vulnerability in Chrome's Mojo IPC. Includes phishing delivery, memory fuzzing, IPC simulation,…

binary-exploitationeducationexploitation+8
331 year ago
CVE-2024-21413 preview

CVE-2024-21413

GitHubthemehackers/cve-2024-21413

CVE-2024-21413 | Microsoft Outlook Remote Code Execution Vulnerability PoC

email-securityexploitationpayload-generation+3
251 year ago
Microsoft-Edge-Information-Disclosure preview

Microsoft-Edge-Information-Disclosure

GitHubabsholi7ly/microsoft-edge-information-disclosure

CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

data-exfiltrationexploitationinformation-gathering+3
172 years ago
evil-winrar preview

evil-winrar

GitHubyoumulijiang/evil-winrar

evil-winrar,CVE-2023-38831漏洞利用和社会工程学攻击框架 (evil-winrar, CVE-2023-38831 Vulnerability Exploitation and Social Engineering Attack Framework)

exploitationpayload-generationphishing-tools+3
102 years ago
CVE-2026-13156 preview

CVE-2026-13156

GitHubminhhk68/cve-2026-13156

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

educationexploitationpapers-research+3
19 days ago
CVE-2021-28079 preview

CVE-2021-28079

GitHubg33xter/cve-2021-28079

POC Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the ElectronJS Framework. An…

command-and-controlexploitationpayload-development+3
44 years ago
CVE-2025-6218-WinRAR-RCE-POC preview

CVE-2025-6218-WinRAR-RCE-POC

GitHubchrxstxqn/cve-2025-6218-winrar-rce-poc

Comprehensive analysis and proof-of-concept for CVE-2025-6218 - WinRAR path traversal RCE vulnerability affecting versions 7.11 and earlier

binary-exploitationeducationexploitation+6
28 months ago
CVE-2025-30349 preview

CVE-2025-30349

GitHubnatasaka/cve-2025-30349

Horde IMP (through 6.2.27) vulnerability – obfuscation via HTML encoding – XSS payload

email-securityexploitationphishing-tools+2
21 year ago
CVE-2019-1218 preview

CVE-2019-1218

GitHubd0gukank/cve-2019-1218

Outlook iOS Spoofing Vulnerability

exploitationios-securitymobile-security+3
16 years ago
CVE-2023-40869 preview

CVE-2023-40869

GitHubminotauro2020/cve-2023-40869

Cross Site Scripting vulnerability in mooSocial mooSocial Software v.3.1.6 allows a remote attacker to execute arbitrary code via a crafted script to…

exploitationpenetration-testingphishing-tools+3
12 years ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubbhanunamikaze/cve-2024-42009

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

data-exfiltrationeducationexploitation+5
11 year ago
Previous123Next