Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
256 results
CVE-2021-44077 preview

CVE-2021-44077

GitHubhorizon3ai/cve-2021-44077

Proof-of-concept exploit for PreAuth RCE in ManageEngine ServiceDesk Plus (CVE-2021-44077). Uploads and executes arbitrary Windows executables on…

exploitationpayload-generationpenetration-testing+3
36
4 years ago
DVAP preview

DVAP

GitHubsonuoffsec/dvap

An OWASP-aligned intentionally vulnerable platform for learning and testing AI, LLM, RAG, MCP, and Agentic AI security.

ai-securityctfeducation+4
282 months ago
0xKern3lCrush preview

0xKern3lCrush

GitHubdeathshotxd/0xkern3lcrush

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…

educationexploitationmalware-analysis+4
516 months ago
CVE-2024-4577-RCE preview

CVE-2024-4577-RCE

GitHubgh-ost00/cve-2024-4577-rce

Exploit for PHP CGI Argument Injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers running Apache and PHP-CGI.…

exploitationpayload-developmentpenetration-testing+3
252 years ago
watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 preview

watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523

GitHubwatchtowrlabs/watchtowr-vs-ivanti-sentry-rce-cve-2026-10520-cve-2026-10523

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

authenticationexploitationpenetration-testing+3
142 months ago
CVE-2021-26084 preview

CVE-2021-26084

GitHubcrowsec-edtech/cve-2021-26084

Python exploit for CVE-2021-26084 targeting Confluence Server pre-authentication remote code execution via OGNL injection. Executes arbitrary…

exploitationpayload-generationpenetration-testing+3
214 years ago
Basileak preview

Basileak

GitHubowasp/basileak

Intentionally vulnerable LLM

ai-securityctfeducation+6
116 days ago
CVE-2018-14665 preview

CVE-2018-14665

GitHubjas502n/cve-2018-14665

Local privilege escalation exploit for CVE-2018-14665 targeting X.Org Server on OpenBSD and Linux. Provides a proof-of-concept script to gain root…

exploitationpenetration-testingpost-exploitation+3
177 years ago
CVE-2024-8190 preview

CVE-2024-8190

GitHubhorizon3ai/cve-2024-8190

Proof-of-concept exploit for CVE-2024-8190, an authenticated command injection vulnerability in Ivanti Cloud Service Appliance, enabling remote…

command-and-controlexploitationpenetration-testing+3
161 year ago
watchTowr-vs-SmarterMail-CVE-2025-52691 preview

watchTowr-vs-SmarterMail-CVE-2025-52691

GitHubwatchtowrlabs/watchtowr-vs-smartermail-cve-2025-52691

Detection artifact generator for CVE-2025-52691, a pre-auth path traversal leading to unauthenticated RCE in SmarterMail. Probes vulnerable builds by…

exploitationinformation-gatheringpenetration-testing+3
197 months ago
WP2Shell preview

WP2Shell

GitHubnull200ok/wp2shell

WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1`…

exploitationpenetration-testingred-teaming+2
151 month ago
CVE-2014-7236_Exploit preview

CVE-2014-7236_Exploit

GitHubm0nad/cve-2014-7236_exploit

Perl-based exploit for CVE-2014-7236 targeting TWiki code execution vulnerability. Enables remote command injection on vulnerable TWiki installations…

exploitationpenetration-testingred-teaming+2
1011 years ago
BYOVD-CVE-2023-52271-POC preview

BYOVD-CVE-2023-52271-POC

GitHubvictoni/byovd-cve-2023-52271-poc

Exploit for CVE-2023-52271 in C++. The code exploits the vulnerable driver wsftprm.sys kernel driver 2.0.0.0, which allows kernel-level access to…

binary-exploitationeducationexploitation+3
107 months ago
CVE-2024-7029 preview

CVE-2024-7029

GitHubgeniuszly/cve-2024-7029

PoC exploit for CVE-2024-7029 in AvTech devices. Scans for vulnerable targets and provides an interactive remote shell for command execution with…

command-and-controlexploitationpenetration-testing+4
91 year ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubianxtianxt/cve-2019-19781

Shell-based remote code execution exploit targeting CVE-2019-19781 in Citrix Application Delivery Controller and Citrix Gateway. Executes arbitrary…

command-and-controlexploitationpenetration-testing+3
76 years ago
CVE-2022-29464 preview

CVE-2022-29464

GitHubgbrsh/cve-2022-29464

Remote Code Execution exploit for WSO2 products targeting CVE-2022-29464, enabling unauthenticated attackers to execute arbitrary commands on…

exploitationpenetration-testingred-teaming+2
73 years ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubzain3311/cve-2025-49844

Exploit CVE-2025-49844 Redis Lua UAF vulnerability to execute arbitrary shellcode and establish persistent backdoor access on vulnerable Redis…

command-and-controlexploitationpayload-development+3
26 days ago
Better-CVE-2022-29464 preview

Better-CVE-2022-29464

GitHubjimidk/better-cve-2022-29464

Proof-of-concept exploit for CVE-2022-29464 enabling unrestricted file upload and remote code execution on vulnerable WSO2 products, with a custom…

exploitationpayload-generationpenetration-testing+3
54 years ago
Previous1234…15Next