Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
100 results
CitrixBleedCVE-2026-8452-2025-5777 preview

CitrixBleedCVE-2026-8452-2025-5777

GitHubmaxprog-svg/citrixbleedcve-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

exploitationinformation-gatheringpenetration-testing+3
3 days ago
CVE-2026-20131-POC preview

CVE-2026-20131-POC

GitHubp3nt3st3r-star/cve-2026-20131-poc

Proof-of-concept exploit for CVE-2026-20131, a pre-authentication RCE in Cisco Catalyst SD-WAN Controller and Manager, enabling admin access and…

exploitationnetwork-securitypenetration-testing+3
5 months ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubkaleth4/cve-2026-21858

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

authenticationexploitationpayload-development+4
4 months ago
CVE-2023-42793_POC preview

CVE-2023-42793_POC

GitHubjohnossawy/cve-2023-42793_poc

Automated exploit script for CVE-2023-42793 targeting TeamCity, enabling token manipulation and admin user creation for penetration testing.

exploitationpenetration-testingred-teaming+2
2 years ago
CVE-2025-10352-POC preview

CVE-2025-10352-POC

GitHubivansmc/cve-2025-10352-poc

Exploit for CVE-2025-10352. Admin account creation on Melis Platform Framework

exploitationpenetration-testingred-teaming+2
110 months ago
CVE-2026-30862 preview

CVE-2026-30862

GitHubdrkim-dev/cve-2026-30862

Proof-of-concept demonstrating stored XSS in Appsmith Table Widget leading to vertical privilege escalation and full admin takeover via XSS-to-CSRF…

exploitationpenetration-testingprivilege-escalation+4
24 months ago
calebstewart-CVE-2021-1675 preview

calebstewart-CVE-2021-1675

GitHubthejoyofhacking/calebstewart-cve-2021-1675

PowerShell script for local privilege escalation on Windows via the PrintNightmare vulnerability (CVE-2021-1675), adding a local admin user or…

binary-exploitationexploitationpenetration-testing+2
24 years ago
CVE-2026-16348 preview

CVE-2026-16348

GitHubslagzz/cve-2026-16348

TP-Link Archer BE800 V1 — VPN Key Injection RCE

exploitationpenetration-testingred-teaming+2
8 days ago
CTT-Sovereign-Vortex preview

CTT-Sovereign-Vortex

GitHubsimoesctt/ctt-sovereign-vortex

Exploit for CVE-2026-2406 targeting Terrminus Authentication Gateways, using temporal dispersion to bypass fingerprinting and behavioral AI,…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubdennisec/cve-2026-41940

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

authentication-authorizationexploitationpenetration-testing+3
4 months ago
Zabbix-CVE-2024-42327-SQL-Injection-RCE preview

Zabbix-CVE-2024-42327-SQL-Injection-RCE

GitHubbridgeralderson/zabbix-cve-2024-42327-sql-injection-rce

Exploits Zabbix SQL injection (CVE-2024-42327) to extract admin session and execute commands via API, achieving reverse shell.

exploitationpenetration-testingred-teaming+2
481 year ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubalhakim88/cve-2026-21858

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

exploitationpayload-developmentpenetration-testing+4
7 months ago
CVE-2025-59287 preview

CVE-2025-59287

GitHub0x7556/cve-2025-59287

Exploit for CVE-2025-59287, injecting WolfShell memory webshell into WSUS servers to achieve remote code execution when the admin console is opened.

exploitationpayload-developmentpenetration-testing+3
710 months ago
CVE-2026-26119 preview

CVE-2026-26119

GitHubcyb3rwitch3r/cve-2026-26119

WAC RCE - CVE-2026-26119 Windows Admin Center authenticated RCE via WinREST/PowerShell invokeCommand.

exploitationpenetration-testingred-teaming+1
123 days ago
serviceDetector preview

serviceDetector

GitHubtothi/servicedetector

Detect whether a service is installed (blindly) and/or running (if exposing named pipes) on a remote machine without using local admin privileges.

information-gatheringnetwork-securitypenetration-testing+2
2412 years ago
PE-Obfuscator preview

PE-Obfuscator

GitHubsaadahla/pe-obfuscator

PE obfuscator with Evasion in mind

adversarial-attackexploitationpayload-development+2
2113 years ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
28 days ago
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.8k6 months ago
Previous123456Next