Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
CVE-2020-13259 preview

CVE-2020-13259

GitHuburielyochpaz/cve-2020-13259

PoC of Full Account Takeover on RAD SecFlow-1v

exploitationpenetration-testingred-teaming+2
3
3 years ago
CVE-2025-57819-FreePBX-RCE2Root preview

CVE-2025-57819-FreePBX-RCE2Root

GitHubozcanpng/cve-2025-57819-freepbx-rce2root

Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.

exploitationpayload-developmentpenetration-testing+4
12 months ago
CVE-2025-13390 preview

CVE-2025-13390

GitHubnxploited/cve-2025-13390

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

authenticationexploitationpayload-development+5
17 months ago
CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise preview

CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise

GitHubsteampunk424/cve-2025-58434-unauthenticated-password-reset-flowwise

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

authentication-authorizationexploitationpenetration-testing+3
14 months ago
Vehicle-Service-Management-System-Multiple-Cookie-Stealing-Leads-to-Full-Account-Takeover preview

Vehicle-Service-Management-System-Multiple-Cookie-Stealing-Leads-to-Full-Account-Takeover

GitHubsanupl/vehicle-service-management-system-multiple-cookie-stealing-leads-to-full-account-takeover

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

educationexploitationpenetration-testing+3
3 months ago
evilqr preview

evilqr

GitHubkgretzky/evilqr

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

authenticationpenetration-testingphishing+4
4093 years ago
PortForwarder preview

PortForwarder

GitHublsecqt/portforwarder

TCP Port Forwarding Utility on C

general-purpose-utilitiesids-ips-evasionlateral-movement+4
422 months ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubrandomrobbiebf/cve-2023-7028

CVE-2023-7028

authentication-authorizationexploitationpenetration-testing+3
582 years ago
CVE-2017-10271 preview

CVE-2017-10271

GitHubs3xy/cve-2017-10271

Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected…

exploitationpenetration-testingred-teaming+2
228 years ago
CVE-2025-59501 preview

CVE-2025-59501

GitHubgarrettfoster13/cve-2025-59501

CVE-2025-59501 POC code

authenticationcloud-securityexploitation+5
259 months ago
CVE-2026-31309 preview

CVE-2026-31309

GitHubsch8ill/cve-2026-31309

Improper Access Control in Mysterium Node before v1.36.0

exploitationinformation-gatheringpenetration-testing+3
1 month ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit
authenticationexploitationpayload-generation+4
1 month ago
CVE-2026-8732-EXPLOIT preview

CVE-2026-8732-EXPLOIT

GitHubdiznev/cve-2026-8732-exploit

PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)

exploitationpayload-generationpenetration-testing+3
2 months ago
FlowiseAI-Critical-KillChain preview

FlowiseAI-Critical-KillChain

GitHubcveteam/flowiseai-critical-killchain

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

authenticationeducationexploitation+5
14 months ago
skyjack preview

skyjack

GitHubsamyk/skyjack

A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying…

command-and-controlexploitationhardware-iot-security+5
1.8k8 years ago
smbtakeover preview

smbtakeover

GitHubzyn3rgy/smbtakeover

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

authentication-authorizationlateral-movementpenetration-testing+2
3611 year ago
relay_bible preview

relay_bible

GitHubrootsecdev/relay_bible

Technical Reference to multiple relay techniques

authenticationcurated-resourceseducation+8
1933 months ago
IngressNightmare-PoC preview

IngressNightmare-PoC

GitHubhakaioffsec/ingressnightmare-poc

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

cloud-securitycontainer-securityeducation+5
2491 year ago
Previous1234Next