Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
160 results
chamilo-lms-unauthenticated-big-upload-rce-poc preview

chamilo-lms-unauthenticated-big-upload-rce-poc

GitHubm3m0o/chamilo-lms-unauthenticated-big-upload-rce-poc

This is a script written in Python that allows the exploitation of the Chamilo's LMS software security flaw described in CVE-2023-4220

exploitationpayload-developmentpenetration-testing+3
2 years ago
Sinister preview

Sinister

GitHubpushpenderindia/sinister

Sinister is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info

data-exfiltrationinformation-gatheringpassword-cracking+5
4661 year ago
ycsm preview

ycsm

GitHubinfosecn1nja/ycsm

This is a quick script installation for resilient redirector using nginx reverse proxy and letsencrypt compatible with some popular Post-Ex Tools…

anti-botcommand-and-controlids-ips-evasion+2
867 years ago
CVE-2019-13292-WebERP_4.15 preview

CVE-2019-13292-WebERP_4.15

GitHubalealeluyah/cve-2019-13292-weberp_4.15

This is a Python3 script that demonstrates an exploit for a Blind SQL Injection vulnerability in WebERP version 4.15.

exploitationpenetration-testingred-teaming+2
23 years ago
xencrypt preview

xencrypt

GitHubthe-xentropy/xencrypt

A PowerShell script anti-virus evasion tool

exploitationids-ips-evasionpayload-generation+2
1.2k6 years ago
CVE-2023-41425-RCE-WonderCMS-4.3.2 preview

CVE-2023-41425-RCE-WonderCMS-4.3.2

GitHubtea-on/cve-2023-41425-rce-wondercms-4.3.2

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

educationexploitationpayload-generation+5
81 year ago
CVE-2023-22622 preview

CVE-2023-22622

GitHubmichael-david-fry/cve-2023-22622

Python Script that will DoS a WP server that is utilizing WP-CRON

exploitationpenetration-testingred-teaming+2
42 years ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubac8999/cve-2025-24071

Python script to execute CVE-2025-24071

exploitationinformation-gatheringpassword-cracking+3
11 months ago
CVE-2023-43364-Exploit-CVE preview

CVE-2023-43364-Exploit-CVE

GitHublibertycityhacker/cve-2023-43364-exploit-cve

Python exploit script targeting CVE-2023-43364 in Searchor 2.4.0, leveraging insecure eval() for remote code execution with a built-in reverse shell…

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2024-1212 preview

CVE-2024-1212

GitHubr0otk3r/cve-2024-1212

Unauthenticated remote command execution exploit for Progress Kemp LoadMaster CVE-2024-1212. Supports proxy interception and output logging for…

command-and-controlexploitationpenetration-testing+3
1 year ago
BigFinger preview

BigFinger

GitHubcediegreyhat/bigfinger

CVE-2023-46747-RCE PoC

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2023-38831-Exploit preview

CVE-2023-38831-Exploit

GitHubtechnicalcorp0/cve-2023-38831-exploit

This project contains a Python script that exploits **CVE-2023-38831**, a vulnerability in **WinRAR** versions prior to 6.23. The exploit generates a…

educationexploitationpayload-generation+4
11 year ago
CVE-2020-6308 preview

CVE-2020-6308

GitHubthemmmdev/cve-2020-6308

Exploit script for SAP Business Objects SSRF

exploitationpenetration-testingred-teaming+2
15 years ago
CVE-2025-41646 preview

CVE-2025-41646

GitHubr0otk3r/cve-2025-41646

Python exploit script for CVE-2025-41646, an authentication bypass in RevPi Webstatus <= 2.4.5. Supports single/mass exploitation, proxy, silent…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2019-15107 preview

CVE-2019-15107

GitHubdiegojuan/cve-2019-15107

Bash script to exploit CVE-2019-15107 in Webmin without Metasploit. Executes remote commands on vulnerable targets with no dependencies.

exploitationpenetration-testingred-teaming+2
5 years ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubchristian93111/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authenticationcommand-and-controleducation+6
103 months ago
HTB-NanoCorp-CVE-2024-0670 preview

HTB-NanoCorp-CVE-2024-0670

GitHubdfdxarjy/htb-nanocorp-cve-2024-0670

PowerShell exploit for CVE-2024-0670, abusing CheckMK Agent MSI repair to escalate from low-privileged user to SYSTEM on Windows targets. Designed…

binary-exploitationctfeducation+5
2 months ago
CVE-2025-59712_CVE-2025-59713 preview

CVE-2025-59712_CVE-2025-59713

GitHubsynacktiv/cve-2025-59712_cve-2025-59713

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

exploitationpayload-developmentpenetration-testing+3
211 months ago
Previous1…567…9Next