Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
834 results
CVE-2023-32749-PoC preview

CVE-2023-32749-PoC

GitHubalaeddine03/cve-2023-32749-poc

Exploit for CVE-2023-32749 affecting Pydio Cells 4.1.2 and earlier

educationexploitationpenetration-testing+3
1
4 months ago
CVE-2025-30772 preview

CVE-2025-30772

GitHubnxploited/cve-2025-30772

WordPress WPC Smart Upsell Funnel for WooCommerce plugin <= 3.0.4 - Arbitrary Option Update to Privilege Escalation vulnerability

educationexploitationpenetration-testing+3
11 year ago
Apache-couchdb-CVE-2017-12635 preview

Apache-couchdb-CVE-2017-12635

GitHubcyberharsh/apache-couchdb-cve-2017-12635

Docker-based reproduction environment for Apache CouchDB CVE-2017-12635 vertical privilege escalation via JSON parser inconsistency, enabling…

exploitationlabs-practicepenetration-testing+3
16 years ago
FUXAPWN preview

FUXAPWN

GitHubhann1bl3l3ct3r/fuxapwn

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

exploitationinformation-gatheringlateral-movement+8
3 months ago
CVE-2026-11551-PoC preview

CVE-2026-11551-PoC

GitHububaydev/cve-2026-11551-poc

Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

authenticationcode-analysisexploitation+5
2 months ago
CVE-2025-6254 preview

CVE-2025-6254

GitHubxxconi/cve-2025-6254

Python exploit for CVE-2025-6254 targeting unauthenticated privilege escalation in Doctreat Core <= 1.6.8. Supports single URL and multi-target…

exploitationpenetration-testingprivilege-escalation+2
2 months ago
CVE-2017-10271 preview

CVE-2017-10271

GitHubdungsocool/cve-2017-10271

Step-by-step lab guide for exploiting CVE-2017-10271 (WebLogic XMLDecoder deserialization RCE) with manual payload construction, blind RCE bypass,…

binary-exploitationdata-exfiltrationeducation+7
3 months ago
Full-Attack-Lifecycle-Simulation-on-Metasploitable preview

Full-Attack-Lifecycle-Simulation-on-Metasploitable

GitHubom4rsallam/full-attack-lifecycle-simulation-on-metasploitable

Full-cycle Pentest on Metasploitable (VMware/Kali). Scanned services (Apache Tomcat/8180), researched CVE-2002-0936 via Exploit-DB, and gained access…

educationexploitationlabs-practice+5
5 months ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubgurjotexpert/cve-2023-3460

Proof-of-concept exploit for CVE-2023-3460, a WordPress Ultimate Member privilege escalation vulnerability. Creates an admin account via crafted…

educationexploitationpenetration-testing+4
11 year ago
vaultize_CVE-2024-36079 preview

vaultize_CVE-2024-36079

GitHubdxrvs/vaultize_cve-2024-36079

Proof-of-concept exploit for CVE-2024-36079, demonstrating arbitrary file upload in Vaultize DRM v21.07.27 via path traversal, enabling SSH key…

exploitationpenetration-testingprivilege-escalation+3
12 years ago
Penetration-Testing-Walkthrough-Hacksudo-Thor preview

Penetration-Testing-Walkthrough-Hacksudo-Thor

GitHubheventafese/penetration-testing-walkthrough-hacksudo-thor

Black-box penetration test against HackSudo Thor : CVE-2014-6271 Shellshock RCE through Apache mod_cgi, chained with sudo misconfiguration and bash…

ctfeducationexploitation+8
3 months ago
CVE-2024-32371 preview

CVE-2024-32371

GitHubchucrutis/cve-2024-32371

Proof-of-concept for CVE-2024-32371: privilege escalation via type parameter manipulation in HSC Mailinspector, enabling regular users to gain…

exploitationpenetration-testingprivilege-escalation+2
12 years ago
CVE-2023-22515 preview

CVE-2023-22515

GitHubiveresk/cve-2023-22515

Shell-based exploit script for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center,…

exploitationpenetration-testingprivilege-escalation+3
12 years ago
CVE-2017-14105 preview

CVE-2017-14105

GitHubtheguly/cve-2017-14105

Detailed CVE-2017-14105 disclosure for Aerohive HiveManager Classic privilege escalation via malicious backup archive upload enabling JSP webshell…

code-analysisexploitationpenetration-testing+3
18 years ago
CVE-2023-6875 preview

CVE-2023-6875

GitHubhatlesswizard/cve-2023-6875

CVE-2023-6875 exploit written for Xakep.Ru

exploitationpassword-attackspayload-generation+3
12 years ago
CVE-2024-45337 preview

CVE-2024-45337

GitHubpeace-maker/cve-2024-45337

Proof of Concept for CVE-2024-45337 against Gitea and Forgejo

authenticationexploitationpenetration-testing+3
11 year ago
CVE-2024-46507 preview

CVE-2024-46507

GitHubsomchandra17/cve-2024-46507

build-script for CVE-2024-46507 and CVE-2024-46508

command-and-controleducationexploitation+6
11 year ago
CVE-2024-0507_CVE-2024-0200-github preview

CVE-2024-0507_CVE-2024-0200-github

GitHubconvisolabs/cve-2024-0507_cve-2024-0200-github

Exploits for GitHub Enterprise CVE-2024-0507 and CVE-2024-0200

exploitationpenetration-testingprivilege-escalation+2
11 year ago
Previous1…171819…47Next