Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
CVE-2026-58480 preview

CVE-2026-58480

GitHubshinthink/cve-2026-58480

CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via…

exploitationpayload-generationpenetration-testing+3
3
1 month ago
CVE-2021-43798 preview

CVE-2021-43798

GitHublim-ahmin/cve-2021-43798

Proof-of-concept exploit for Grafana path traversal vulnerability (CVE-2021-43798) allowing unauthorized file read via directory traversal in plugin…

exploitationinformation-gatheringpenetration-testing+3
1 month ago
CVE-2026-4883 preview

CVE-2026-4883

GitHubxshadow-here/cve-2026-4883

Piotnet Forms Pro <= 2.1.40 - Unauthenticated Arbitrary File Upload → RCE

exploitationpayload-generationpenetration-testing+3
2 months ago
By-Poloss..-..CVE-2026-39938 preview

By-Poloss..-..CVE-2026-39938

GitHubpolosss/by-poloss..-..cve-2026-39938

Proof-of-concept exploit for CVE-2026-39938: unauthenticated local file inclusion in Cacti <= 1.2.30, enabling arbitrary file read and remote code…

exploitationinformation-gatheringpenetration-testing+3
2 months ago
CVE-2026-66066 preview

CVE-2026-66066

GitHubshinthink/cve-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

exploitationpenetration-testingreconnaissance+3
126 days ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

command-and-controlexploitationinformation-gathering+8
11 month ago
zimbramail-CVE-2025-68645-poc preview

zimbramail-CVE-2025-68645-poc

GitHubmaxmnml/zimbramail-cve-2025-68645-poc

CVE-2025-68645 - A Local File Inclusion (LFI) vulnerability in the Webmail Classic UI of Zimbra Collaboration

exploitationinformation-gatheringpenetration-testing+3
37 months ago
WP-Bricks-Exploit-CVE-2024-25600 preview

WP-Bricks-Exploit-CVE-2024-25600

GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

command-and-controlexploitationinformation-gathering+7
11 month ago
auto-cve-2022-44268.sh preview

auto-cve-2022-44268.sh

GitHubnarekkay/auto-cve-2022-44268.sh

Automating Exploitation of CVE-2022-44268 ImageMagick Arbitrary File Read

exploitationinformation-gatheringpenetration-testing+3
23 years ago
CVE-2024-36837 preview

CVE-2024-36837

GitHublhc321-source/cve-2024-36837

Proof-of-concept exploit for CVE-2024-36837, an unauthenticated arbitrary file read vulnerability in Zhilianyun SRM2.0. Includes batch scanning and…

exploitationinformation-gatheringpenetration-testing+3
21 year ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
4 months ago
CVE-2022-31793 preview

CVE-2022-31793

GitHubxpgdgit/cve-2022-31793

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

exploitationpenetration-testingreconnaissance+2
14 years ago
f5scan preview

f5scan

GitHubhalencarjunior/f5scan

CVE-2020-5902 scanner for F5 BIG-IP with Shodan host discovery, LFI file reading, and remote command execution capabilities.

exploitationinformation-gatheringreconnaissance+2
16 years ago
CVE-2019-11510-PulseVPN preview

CVE-2019-11510-PulseVPN

GitHubpwn3z/cve-2019-11510-pulsevpn

Exploit and detection scripts for CVE-2019-11510, enabling unauthenticated remote file reading on Pulse Secure VPN appliances, with IP scanning and…

exploitationinformation-gatheringreconnaissance+2
15 years ago
CVE-2020-17519 preview

CVE-2020-17519

GitHubqmf0c3uk/cve-2020-17519

Exploit for CVE-2020-17519 targeting Apache Flink directory traversal vulnerability. Enables unauthenticated remote file read for security testing…

exploitationpenetration-testingreconnaissance+2
15 years ago
FUXAPWN preview

FUXAPWN

GitHubhann1bl3l3ct3r/fuxapwn

POC exploit for CVE-2026-25895 FUXA Unauthenticated Path Traversal -> Arbitrary File Write -> RCE

exploitationinformation-gatheringlateral-movement+8
3 months ago
Vite-CVE-2025-30208-EXP preview

Vite-CVE-2025-30208-EXP

GitHublilil3333/vite-cve-2025-30208-exp

Python-based exploit for CVE-2025-30208 targeting Vite dev server arbitrary file read. Supports single-target detection, custom file paths, system…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
POC-CVE-2021-41773 preview

POC-CVE-2021-41773

GitHubkubota/poc-cve-2021-41773

Proof-of-concept exploit for Apache HTTP Server 2.4.49 path traversal (CVE-2021-41773) enabling file read and remote code execution via CGI.

exploitationpenetration-testingreconnaissance+2
14 years ago
Previous1…91011…13Next