Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
832 results
cve-2017-5123 preview

cve-2017-5123

GitHubnabilboudra/cve-2017-5123

Educational demonstration of CVE-2017-5123 kernel exploit, ICMP-based rootkit command-and-control, and OS command injection vulnerable web…

binary-exploitationcommand-and-controleducation+5
8 months ago
n8n-cve-2025-68613-thm preview

n8n-cve-2025-68613-thm

GitHubkhin-96/n8n-cve-2025-68613-thm

Educational walkthrough for exploiting CVE-2025-68613, a critical RCE in n8n workflow automation. Covers expression injection, sandbox escape,…

command-and-controleducationexploitation+6
18 months ago
CVE-2023-30258-Exploit-For-Magnus-Billing-System preview

CVE-2023-30258-Exploit-For-Magnus-Billing-System

GitHubabdullohqurbon0v/cve-2023-30258-exploit-for-magnus-billing-system

Exploit for Magnus Billing v7 that achieves root privileges by exploiting CVE-2023-30258, enabling unauthorized access and system compromise.

exploitationpenetration-testingprivilege-escalation+2
11 months ago
AutoPwn-Titanic.htb preview

AutoPwn-Titanic.htb

GitHubmaikneysm/autopwn-titanic.htb

This is an automated exploitation script for the Hack The Box machine *Titanic*. It extracts Gitea user hashes via LFI, assists in cracking them, and…

ctfexploitationinformation-gathering+5
1 year ago
CVE-2021-32099 preview

CVE-2021-32099

GitHubmagicrc/cve-2021-32099

PoC for CVE-2021-32099

educationexploitationpenetration-testing+3
1 year ago
CVE-2025-2907 preview

CVE-2025-2907

GitHubyucaerin/cve-2025-2907

Order Delivery Date Pro for WooCommerce < 12.3.1 - Unauthenticated Arbitrary Option Update

educationexploitationprivilege-escalation+2
1 year ago
CVE-2025-33053-POC preview

CVE-2025-33053-POC

GitHubcyberw1ng/cve-2025-33053-poc

POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on…

command-and-controleducationexploitation+7
8 months ago
Harmonic preview

Harmonic

GitLabrunik/harmonic

Suite for reverse shell handling geared toward working within the native shell

command-and-controlinformation-gatheringpayload-development+7
8 years ago
QuickBox-Pro-2.1.8-Authenticated-RCE preview

QuickBox-Pro-2.1.8-Authenticated-RCE

GitHubs1gh/quickbox-pro-2.1.8-authenticated-rce

Authenticated command injection exploit for QuickBox Pro v2.1.8, providing remote code execution as www-data and privilege escalation to root via…

exploitationpenetration-testingpost-exploitation+3
6 years ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubmatesz44/cve-2025-9074

CVE-2025-9074: Docker Desktop LPE via Docker Engine API wo/ AuthN in posix sh

container-escapeexploitationpenetration-testing+2
6 months ago
CVE-2025-49132_HTB_SEASON10 preview

CVE-2025-49132_HTB_SEASON10

GitHubnik123-py/cve-2025-49132_htb_season10

Exploit for CVE-2025-49132 targeting Pterodactyl Panel, combining path traversal with PEAR command injection for unauthenticated remote code…

ctfeducationexploitation+4
6 months ago
CVE-2019-6440 preview

CVE-2019-6440

GitHubhexnone/cve-2019-6440

Proof-of-concept exploit for CVE-2019-6440 achieving SYSTEM privilege escalation on Zemana antimalware via man-in-the-middle update interception and…

exploitationmalware-analysispenetration-testing+3
7 years ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubmrdottt/cve-2021-22911

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

exploitationpenetration-testingprivilege-escalation+3
3 years ago
CVE_2020_35848 preview

CVE_2020_35848

GitHubsabbu143s/cve_2020_35848

CVE-2020-35848 impacts Cockpit-CMS v1.7 due to unsafe handling of user inputs in authentication mechanisms, leading to remote code execution. This…

ctfeducationexploitation+6
1 year ago
CVE-2025-25968 preview

CVE-2025-25968

GitHubpadayali-jd/cve-2025-25968

Proof-of-concept exploit for CVE-2025-25968, an improper access control vulnerability in DDSN Interactive cm3 Acora CMS v10.1.1. Enables…

exploitationinformation-gatheringpenetration-testing+3
11 months ago
CVE-2019-14287-CVE-2014-6271 preview

CVE-2019-14287-CVE-2014-6271

GitHubsindayifu/cve-2019-14287-cve-2014-6271

Exploit code for CVE-2019-14287 and CVE-2014-6271, targeting sudo privilege escalation and Shellshock vulnerabilities.

command-and-controlexploitationpenetration-testing+3
6 years ago
CVE-2025-25369 preview

CVE-2025-25369

GitHublkasjkasj/cve-2025-25369

Documented XSS exploit for ZKBio CVSecurity v.6.4.1 with WAF bypass, enabling privilege escalation from Template Editor to administrator via crafted…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
fortinet-cve-2024-46671 preview

fortinet-cve-2024-46671

GitHubixec-lab/fortinet-cve-2024-46671

Automated exploit for an authenticated IDOR vulnerability in FortiWeb 7.4.3, enabling privilege escalation and account takeover via a logical bug.

exploitationpenetration-testingprivilege-escalation+3
1 year ago
Previous1…192021…47Next