Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
CVE-2022-29464-mass preview

CVE-2022-29464-mass

GitHubamit-pathak009/cve-2022-29464-mass

Mass exploit tool for CVE-2022-29464, a pre-auth RCE in WSO2 Carbon Server, with single-target and batch scanning via file input and search dorks.

exploitationinformation-gatheringreconnaissance+2
1
4 years ago
CVE-2021-42237-SiteCore-XP preview

CVE-2021-42237-SiteCore-XP

GitHubvesperp/cve-2021-42237-sitecore-xp

Automated exploit tool for CVE-2021-42237 targeting SiteCore XP. Reads target URLs from a file and leverages DNSLog for out-of-band detection.

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2024-31497-POC preview

CVE-2024-31497-POC

GitHubhugobond/cve-2024-31497-poc

Proof Of Concept that exploits PuTTy CVE-2024-31497.

cryptographyexploitationinformation-gathering+3
112 years ago
CVE-2025-45955 preview

CVE-2025-45955

GitHubsurendrapuppala7/cve-2025-45955

Proof-of-concept exploit for CVE-2025-45955 demonstrating Server-Side Request Forgery (SSRF) in DonWeb Ferozo hosting platform, enabling internal…

cloud-securityexploitationinformation-gathering+3
17 months ago
CVE-2025-24071-POC preview

CVE-2025-24071-POC

GitHubhyperchk/cve-2025-24071-poc

Proof-of-concept exploit for CVE-2025-24071, leveraging a crafted ZIP file to trigger SMB authentication relay and capture NTLM hashes via Impacket.

exploitationinformation-gatheringpenetration-testing+2
3 months ago
CVE-2018-7600-Drupal-RCE preview

CVE-2018-7600-Drupal-RCE

GitHubg0rx/cve-2018-7600-drupal-rce

PoC exploit collection for CVE-2018-7600 Drupal RCE with multiple scripts targeting Drupal 7 and 8, including mass exploitation variants.

exploitationpayload-generationpenetration-testing+3
1148 years ago
GONET-Scanner preview

GONET-Scanner

GitHubluijait/gonet-scanner

Golang network scanner with arp discovery and own parser

information-gatheringnetwork-mappingpenetration-testing+2
884 years ago
CVE-2023-22047 preview

CVE-2023-22047

GitHubtuo4n8/cve-2023-22047

Leveraging arbitrary file read to RCE on Oracle PeopleSoft

exploitationinformation-gatheringpenetration-testing+3
121 year ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
27 days ago
pbck-exploit preview

pbck-exploit

GitHubshinthink/pbck-exploit

📤 Mass exploitation framework for CVE-2026-56290 — Page Builder CK Joomla unauthenticated file upload to RCE

exploit-frameworkspayload-developmentpenetration-testing+4
31 month ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubmauricelambert/cve-2021-42013

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubmauricelambert/cve-2021-41773

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2021-26855 preview
Archived

CVE-2021-26855

GitHubhackerschoice/cve-2021-26855

Proof-of-concept exploit for CVE-2021-26855 (ProxyLogon SSRF) enabling file write via Exchange server vulnerability. Demonstrates the SSRF chain for…

exploitationpenetration-testingreconnaissance+2
605 years ago
Oracle-WebLogic-CVE-2022-21371 preview

Oracle-WebLogic-CVE-2022-21371

GitHubvulnmachines/oracle-weblogic-cve-2022-21371

Oracle WebLogic CVE-2022-21371

exploitationinformation-gatheringpenetration-testing+3
183 years ago
-CVE-2023-30845 preview

-CVE-2023-30845

GitHubhimori123/-cve-2023-30845

Explore CVE 2023-30845 automatically across multiple subdomains

exploitationreconnaissancesubdomain-enumeration+2
162 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubak1t4/cve-2024-3400

Global Protec Palo Alto File Write Exploit

educationexploitationreconnaissance+2
92 years ago
CVE-2006-2842 preview

CVE-2006-2842

GitHubkarthi-the-hacker/cve-2006-2842

CLI scanner for CVE-2006-2842 (PHP include() path truncation) vulnerability. Scans single or multiple URLs to detect this specific web application…

information-gatheringpenetration-testingreconnaissance+3
32 years ago
CrawlBox preview
Archived

CrawlBox

GitHubabaykan/crawlbox

Easy way to brute-force web directory.

crawlerinformation-gatheringpenetration-testing+3
1647 years ago
Previous1…456…13Next