Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
CVE-2026-85706 preview

CVE-2026-85706

GitHubmhtsec/cve-2026-85706

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

data-exfiltrationexploitationinformation-gathering+5
12
14 days ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubun9nplayer/cve-2024-24919

This repository contains a proof-of-concept (PoC) exploit for CVE-2024-24919, a critical vulnerability discovered in Check Point SVN. The…

exploitationinformation-gatheringpenetration-testing+2
162 years ago
PowerMeta preview

PowerMeta

GitHubdafthack/powermeta

PowerMeta searches for publicly available files hosted on various websites for a particular domain by using specially crafted Google, and Bing…

information-gatheringosintreconnaissance
5841 year ago
CVE-2025-43919-POC preview

CVE-2025-43919-POC

GitHubcybersecplayground/cve-2025-43919-poc

A new vulnerability has been discovered in GNU Mailman 2.1.39, bundled with cPanel/WHM, allowing unauthenticated remote attackers to read arbitrary…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubandrelia-hacks/cve-2024-3400

Proof-of-concept exploit for CVE-2024-3400, a command injection in Palo Alto GlobalProtect. Scans targets, triggers RCE, and retrieves configuration…

command-and-controlexploitationpenetration-testing+3
2 years ago
CVE-2021-41773-Apache-RCE preview

CVE-2021-41773-Apache-RCE

GitHubpwn3z/cve-2021-41773-apache-rce

A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path traversal attack to map URLs to…

exploitationpenetration-testingreconnaissance+2
4 years ago
CVE-2020-29666 preview

CVE-2020-29666

GitHubjet-pentest/cve-2020-29666

Proof-of-concept for CVE-2020-29666: directory listing vulnerability in Lan ATMService M3 ATM Monitoring System 6.1.0 that exposes log files…

information-gatheringmisconfigurationreconnaissance+2
5 years ago
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.7k1 day ago
jsubfinder preview

jsubfinder

GitHubthreatunknown/jsubfinder

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

information-gatheringosintreconnaissance+3
2841 year ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubsh4den/cve-2026-21858

Proof of Concept: CVE-2026-21858 is vulnerability on n8n where unauthenticated remote attackers can access sensitive files.

exploitationinformation-gatheringpenetration-testing+3
32 months ago
CVE-2006-3392 preview

CVE-2006-3392

GitHubbrosck/cve-2006-3392

Python exploit for CVE-2006-3392, a path traversal in Webmin/Usermin allowing arbitrary file read, demonstrated by retrieving /etc/shadow.

exploitationinformation-gatheringpenetration-testing+3
31 year ago
Poc_CVE-2025-68645 preview

Poc_CVE-2025-68645

GitHubharisaidhin/poc_cve-2025-68645

Zimbra Path Traversal (CVE-2025-68645) - Unauthenticated file read vulnerability in Zimbra Collaboration Suite

exploitationinformation-gatheringpenetration-testing+3
14 months ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubrubbxalc/cve-2025-24071

Generates a ZIP file exploiting CVE-2025-24071 to capture netNTLMv2 credentials from Windows Explorer via malicious .library-ms files, intended for…

educationexploitationinformation-gathering+3
11 year ago
CVE-2025-34171 preview

CVE-2025-34171

GitHubeyodav/cve-2025-34171

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

exploitationinformation-gatheringmisconfiguration+3
8 months ago
CVE-2026-56718 preview

CVE-2026-56718

GitHubhellkkid/cve-2026-56718

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

embedded-systems-securityexploitationiot-security+3
22 days ago
CVE-2025-11371 preview

CVE-2025-11371

GitHubrxerium/cve-2025-11371

Detection for CVE-2025-11371

information-gatheringpenetration-testingreconnaissance+2
611 months ago
Digital-Privacy preview
Archived

Digital-Privacy

GitHubffffffff0x/digital-privacy

Information Protection & OSINT resources | 一个关于数字隐私搜集、保护、清理集一体的方案,外加开源信息收集(OSINT)对抗

curated-resourcesdns-analysiseducation+8
4.9k3 years ago
Previous123Next