Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
229 results
CVE-2026-12227 preview

CVE-2026-12227

GitHubmurrez/cve-2026-12227

Python 3 PoC and scanner for CVE-2026-12227, an unauthenticated local file inclusion in WordPress Visual Composer Website Builder via the…

exploitationinformation-gatheringpenetration-testing+5
1 day ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubthemehackers/cve-2025-24071

Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)

educationexploitationinformation-gathering+2
341 year ago
PutScanner preview

PutScanner

GitHubx00byte/putscanner

A tool that identifies writable web directories in Apache Tomcat via HTTP PUT method [CVE-2025-24813]

exploitationinformation-gatheringpenetration-testing+3
91 year ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubth-secforge/cve-2025-24071

Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

exploitationinformation-gatheringpassword-attacks+2
31 year ago
CVE-2026-65694-PoC preview

CVE-2026-65694-PoC

GitHubabdugafforov-bobur/cve-2026-65694-poc

PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

educationexploitationinformation-gathering+3
12 months ago
CVE-2024-31497-POC preview

CVE-2024-31497-POC

GitHubhugobond/cve-2024-31497-poc

Proof Of Concept that exploits PuTTy CVE-2024-31497.

cryptographyexploitationinformation-gathering+3
112 years ago
CVE-2025-24071-PoC preview

CVE-2025-24071-PoC

GitHublooky243/cve-2025-24071-poc

CVE-2025-24071 Proof Of Concept

data-exfiltrationexploitationinformation-gathering+3
31 year ago
CVE-2020-3452-PoC preview

CVE-2020-3452-PoC

GitHubxdev05/cve-2020-3452-poc

Automates downloading and running an Nmap NSE script to scan hosts for CVE-2020-3452 vulnerability, using a list of target hosts.

exploitationpenetration-testingreconnaissance+3
26 years ago
PowerSploit preview
Archived

PowerSploit

GitHubpowershellmafia/powersploit

PowerSploit - A PowerShell Post-Exploitation Framework

lateral-movementpayload-generationpenetration-testing+5
13.1k6 years ago
Gxss preview
Archived

Gxss

GitHubkathanp19/gxss

A tool to check a bunch of URLs that contain reflecting params.

information-gatheringpenetration-testingreconnaissance+2
6012 years ago
lulzbuster preview

lulzbuster

GitHubnoptrix/lulzbuster

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

fuzzinginformation-gatheringpenetration-testing+3
1412 months ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubverylazytech/cve-2024-23692

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

exploitationpenetration-testingreconnaissance+3
491 year ago
CVE-2022-24716 preview

CVE-2022-24716

GitHub0x0jackal/cve-2022-24716

Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10

exploitationinformation-gatheringpenetration-testing+3
33 years ago
CVE-2024-36837 preview

CVE-2024-36837

GitHublhc321-source/cve-2024-36837

Proof-of-concept exploit for CVE-2024-36837, an unauthenticated arbitrary file read vulnerability in Zhilianyun SRM2.0. Includes batch scanning and…

exploitationinformation-gatheringpenetration-testing+3
21 year ago
WG-CVE-2026-1555-Linux preview

WG-CVE-2026-1555-Linux

GitHubwillygailo/wg-cve-2026-1555-linux

Automated exploit toolkit for CVE-2026-1555, a critical unauthenticated file upload RCE in the WebStack WordPress theme. Features PyQt5 GUI,…

command-and-controleducationexploitation+6
3 months ago
Poc_CVE-2025-68645 preview

Poc_CVE-2025-68645

GitHubharisaidhin/poc_cve-2025-68645

Zimbra Path Traversal (CVE-2025-68645) - Unauthenticated file read vulnerability in Zimbra Collaboration Suite

exploitationinformation-gatheringpenetration-testing+3
14 months ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubth-secforge/cve-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2025-68645 preview

CVE-2025-68645

GitHubcrow5-oss/cve-2025-68645

Proof-of-Concept scanner for CVE-2025-68645, detecting Local File Inclusion (LFI) in Zimbra Collaboration Suite via the /h/printcalendar endpoint…

exploitationinformation-gatheringpenetration-testing+3
7 months ago
Previous123…13Next