Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
833 results
CVE-2017-14263 preview

CVE-2017-14263

GitHubzzz66686/cve-2017-14263

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

authenticationexploitationiot-security+3
5
8 years ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubarch1m3d/cve-2024-28000

PoC for the CVE-2024 Litespeed Cache Privilege Escalation

educationexploitationpenetration-testing+3
71 year ago
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
48 days ago
Codify-TJNULL-OSCP- preview

Codify-TJNULL-OSCP-

GitHubr3fr4kt/codify-tjnull-oscp-

Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege…

ctfeducationexploitation+5
24 days ago
CVE-2020-24028 preview

CVE-2020-24028

GitHubredteambrasil/cve-2020-24028

PoC for CVE-2020-24028: privilege escalation via authenticated permission bypass in ForLogic Qualiex, allowing user creation and password changes.

exploitationpenetration-testingprivilege-escalation+2
29 days ago
CVE-2025-8110-gogs-poc preview

CVE-2025-8110-gogs-poc

GitHubshirouuu/cve-2025-8110-gogs-poc

PoC for CVE-2025-8110 - Gogs arbitrary file write via symlink

educationexploitationpenetration-testing+3
51 month ago
CVE-2023-42791_CVE-2024-23666 preview

CVE-2023-42791_CVE-2024-23666

GitHubsynacktiv/cve-2023-42791_cve-2024-23666

Exploitations scripts for CVE-2023-42791 and CVE-2024-23666.

command-and-controlexploitationpenetration-testing+5
61 year ago
langflow-rce-exploit preview

langflow-rce-exploit

GitHub0-d3y/langflow-rce-exploit

Remote Code Execution Exploit for Langflow (CVE-2025-3248) - [ By S4Tech ]

command-and-controlexploitationpayload-development+8
71 year ago
react2shell-toolkit preview

react2shell-toolkit

GitHubolezhaku/react2shell-toolkit

Toolkit for CVE-2025-55182, also known as React2Shell.

cloud-securitydatabase-securityexploitation+8
42 months ago
CVE-2024-49328 preview

CVE-2024-49328

GitHubrandomrobbiebf/cve-2024-49328

WP REST API FNS <= 1.0.0 - Privilege Escalation

exploitationpenetration-testingprivilege-escalation+3
61 year ago
CVE-2026-19598-PoC preview

CVE-2026-19598-PoC

GitHubdeadexpl0it/cve-2026-19598-poc

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

exploitationpenetration-testingprivilege-escalation+3
7 days ago
copy-fail-checker preview

copy-fail-checker

GitHubsamanzamani/copy-fail-checker

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

cryptographyeducationexploitation+4
53 months ago
CVE-2025-81110-PoC preview

CVE-2025-81110-PoC

GitHubbridgeralderson/cve-2025-81110-poc

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

exploitationpayload-developmentpenetration-testing+4
44 months ago
CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open preview

CVE-2026-11111-TOCTOU-in-File-Permission-Check-Before-Open

GitHubgeorge0papasotiriou/cve-2026-11111-toctou-in-file-permission-check-before-open

Educational CVE PoC for a TOCTOU file-permission race in Flask; uses symlink replacement during the check-open window to disclose sensitive files.

data-exfiltrationeducationexploitation+4
24 days ago
e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout preview

e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

GitHubhunt-benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

database-securityeducationexploitation+4
121 days ago
CVE-2026-8732 preview

CVE-2026-8732

GitHubzycoder0day/cve-2026-8732

Automated 8-phase exploit for CVE-2026-8732, an unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0. Uses multiprocessing and asyncio to scan…

exploitationpenetration-testingprivilege-escalation+3
33 months ago
CVE-2026-13152 preview

CVE-2026-13152

GitHubminhhk68/cve-2026-13152

CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).

educationexploitationpenetration-testing+4
127 days ago
CVE-2026-66804 preview

CVE-2026-66804

GitHubcypherhippie/cve-2026-66804

Local Windows privilege escalation PoC for CVE-2026-66804: plants a COM DLL in a missing path to abuse Camera FrameServer and impersonate SYSTEM.

exploitationpenetration-testingpost-exploitation+1
19 days ago
Previous1…131415…47Next