Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
CVE-2020-13942-POC- preview

CVE-2020-13942-POC-

GitHubshifa123/cve-2020-13942-poc-

CVE-2020-13942 POC + Automation Script

exploitationreconnaissancesubdomain-enumeration+2
9
5 years ago
CICD-Goat-Vapt-Writeup preview

CICD-Goat-Vapt-Writeup

GitHubdheeraj-jayaswal/cicd-goat-vapt-writeup

Full VAPT writeup of OWASP CICD-Goat — 9 CTFd flags captured, 4 critical + 5 high findings (incl. CVE-2024-23897) mapped to the OWASP Top 10 CI/CD…

ctfdevsecopseducation+5
124 days ago
WG-CVE-2026-1555-Linux preview

WG-CVE-2026-1555-Linux

GitHubwillygailo/wg-cve-2026-1555-linux

Automated exploit toolkit for CVE-2026-1555, a critical unauthenticated file upload RCE in the WebStack WordPress theme. Features PyQt5 GUI,…

command-and-controleducationexploitation+6
2 months ago
Jquery-File-Tree-1.6.6-Path-Traversal preview

Jquery-File-Tree-1.6.6-Path-Traversal

GitHubnickguitar/jquery-file-tree-1.6.6-path-traversal

Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)

information-gatheringpenetration-testingreconnaissance+2
45 years ago
TwoMillion-Machine-Writeup preview

TwoMillion-Machine-Writeup

GitHubanxs3c/twomillion-machine-writeup

From deobfuscating code.js to root, CVE-2023-0386

ctfeducationexploitation+7
2 months ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k1 year ago
maps_scanner preview

maps_scanner

GitHubhackinglz/maps_scanner

MAPS cloud scanner and response parser for Microsoft Defender research.

api-security-testingdynamic-analysis-sandboxingfuzzing+6
946 months ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubverylazytech/cve-2024-23692

POC - Unauthenticated RCE Flaw in Rejetto HTTP File Server - CVE-2024-23692

exploitationpenetration-testingreconnaissance+3
481 year ago
CVE-2026-48282 preview

CVE-2026-48282

GitHubimbas007/cve-2026-48282

Proof-of-concept exploit for CVE-2026-48282, a critical path traversal in Adobe ColdFusion RDS enabling unauthenticated file read/write and RCE.…

exploitationinformation-gatheringpenetration-testing+3
241 month ago
CVE-2018-14847 preview

CVE-2018-14847

GitHubjas502n/cve-2018-14847

Proof-of-concept exploit for CVE-2018-14847 allowing arbitrary file read of plaintext passwords from MikroTik RouterOS WinBox service, with TCP/IP…

exploitationinformation-gatheringnetwork-security+3
307 years ago
CVE-2022-22954-PoC preview

CVE-2022-22954-PoC

GitHubtunelko/cve-2022-22954-poc

VMware Workspace ONE Access and Identity Manager RCE via SSTI - Test script for shodan, file or manual.

exploitationpenetration-testingreconnaissance+2
162 years ago
CVE-2026-58048-PoC-Exploit preview

CVE-2026-58048-PoC-Exploit

GitHubtc4dy/cve-2026-58048-poc-exploit

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…

database-securityexploitationincident-response+7
521 days ago
hook preview

hook

GitHubjbaines-r7/hook

Proof of Concept for WatchGuard Authenticated Arbitrary File Read (CVE-2022-31749)

exploitationpassword-crackingpenetration-testing+3
104 years ago
checker-CVE-2020-5902 preview

checker-CVE-2020-5902

GitHubmrcl0wnlab/checker-cve-2020-5902

Checker CVE-2020-5902: BIG-IP versions 15.0.0 through 15.1.0.3, 14.1.0 through 14.1.2.5, 13.1.0 through 13.1.3.3, 12.1.0 through 12.1.5.1, and 11.6.1…

exploitationreconnaissancevulnerability-scanners+1
56 years ago
VmWare-vCenter-vulnerability preview

VmWare-vCenter-vulnerability

GitHubvulnmachines/vmware-vcenter-vulnerability

Collection of Proof-of-Concept exploits for VMware vCenter vulnerabilities enabling RCE, SSRF, and arbitrary file read. Includes Shodan query for…

exploitationpenetration-testingreconnaissance+2
84 years ago
F5-BIG-IP-RCE-CVE-2022-1388 preview

F5-BIG-IP-RCE-CVE-2022-1388

GitHubangus-team/f5-big-ip-rce-cve-2022-1388

Multi-threaded Python scanner for CVE-2022-1388, an F5 BIG-IP remote code execution vulnerability. Supports single URL and batch file input, with…

command-and-controlexploitationpenetration-testing+3
54 years ago
CVE-2026-57827 preview

CVE-2026-57827

GitHubcandisexterior171/cve-2026-57827

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

exploitationpenetration-testingreconnaissance+2
8 days ago
CVE-2020-7799 preview

CVE-2020-7799

GitHubianxtianxt/cve-2020-7799

Batch detection and exploitation script for CVE-2020-7799. Reads URLs from a text file and runs Python-based exploit against each target.

exploitationpenetration-testingreconnaissance+2
36 years ago
Previous1…8910…13Next