Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
2448 results
Indushell preview

Indushell

GitHubsecarmalabs/indushell

PoC C&C for the Industroyer malware

command-and-controlexploitationmalware-analysis+3
269 years ago
CVE-2025-55184-POC-Expolit preview

CVE-2025-55184-POC-Expolit

GitHubcybertechajju/cve-2025-55184-poc-expolit

Professional-grade Denial of Service (DoS) exploitation framework for CVE-2025-55184 targeting React Server Components. Features 8 attack modes, WAF…

educationexploitationpayload-generation+5
229 months ago
ptrace_may_dream preview

ptrace_may_dream

GitHubsgkdev/ptrace_may_dream

CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer

binary-exploitationcontainer-escapeexploitation+4
213 months ago
pyc2 preview

pyc2

GitHubr00k5a58/pyc2

simple c2 written in python to demonstrate security concepts

command-and-controleducationnetwork-security+3
138 years ago
CVE-2026-3888-snap-confine-systemd-tmpfiles-LPE preview

CVE-2026-3888-snap-confine-systemd-tmpfiles-LPE

GitHubthecybergeek/cve-2026-3888-snap-confine-systemd-tmpfiles-lpe

Local privilege escalation exploit for CVE-2026-3888 targeting snap-confine and systemd-tmpfiles on Ubuntu, providing SUID and capabilities variants…

binary-exploitationeducationexploitation+6
185 months ago
Microsoft-CVE-2022-26809-The-Little-Boy preview

Microsoft-CVE-2022-26809-The-Little-Boy

GitHubsherlocksecurity/microsoft-cve-2022-26809-the-little-boy

The poc for CVE-2022-26809 RCE via RPC will be updated here.

exploitationpayload-developmentpenetration-testing+3
194 years ago
CVE-2026-34486 preview

CVE-2026-34486

GitHub404-src/cve-2026-34486

Exploit for Apache Tomcat EncryptInterceptor bypass leading to unauthenticated RCE via Java deserialization on port 4000. Includes lab setup,…

educationexploitationpenetration-testing+3
95 months ago
CVE-2022-38374 preview

CVE-2022-38374

GitHubazhurtanov/cve-2022-38374

Proof-of-concept exploit for CVE-2022-38374, demonstrating the vulnerability and providing a working exploit for security testing and research.

exploitationpenetration-testingred-teaming+2
93 years ago
CVE-2019-20224 preview

CVE-2019-20224

GitHubmhaskar/cve-2019-20224

The offical exploit for Pandora v7.0NG Post-auth Remote Code Execution CVE-2019-20224

exploitationpayload-developmentpenetration-testing+3
146 years ago
CVE-2020-5902_RCE preview

CVE-2020-5902_RCE

GitHubsv3nbeast/cve-2020-5902_rce

Exploit for CVE-2020-5902 providing remote file read and remote code execution on F5 BIG-IP devices via directory traversal in the TMUI interface.

command-and-controlexploitationpenetration-testing+3
86 years ago
CVE-2026-63030-wp2r00t preview

CVE-2026-63030-wp2r00t

GitHubj4ck3lsyn-gen2/cve-2026-63030-wp2r00t

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

ctfeducationexploitation+5
61 month ago
CVE-2023-0315 preview

CVE-2023-0315

GitHubmhaskar/cve-2023-0315

The official exploit for Froxlor Remote Code Execution CVE-2023-0315

exploitationpayload-generationpenetration-testing+3
73 years ago
CVE-2026-15409-15410-Framework preview

CVE-2026-15409-15410-Framework

GitHubtc4dy/cve-2026-15409-15410-framework

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

command-and-controleducationexploitation+7
510 days ago
GenWiFiFaker preview

GenWiFiFaker

GitHubgeniuszly/genwififaker

is a tool for creating fake WiFi access points

educationnetwork-securitypenetration-testing+3
81 year ago
PoC-ubuntutouch-pin-privesc preview

PoC-ubuntutouch-pin-privesc

GitHubfilipkarc/poc-ubuntutouch-pin-privesc

CVE-2022-40297 - Proof of Concept: Privilege escalation in Ubuntu Touch 16.04 - by PIN Bruteforce

android-securityexploitationmobile-security+5
64 years ago
CVE-2025-69212-PoC preview

CVE-2025-69212-PoC

GitHubbridgeralderson/cve-2025-69212-poc

OpenSTAManager v2.9.8 and earlier versions contain a critical OS Command Injection vulnerability in the P7M (signed XML) file decoding function.

command-and-controlexploitationpayload-development+5
42 months ago
CVE-2025-12539 preview

CVE-2025-12539

GitHubnxploited/cve-2025-12539

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

educationexploitationinformation-gathering+6
710 months ago
Crimson-Cloak-ISH-wrapper-iOS- preview

Crimson-Cloak-ISH-wrapper-iOS-

GitHubsynchancybersecurity/crimson-cloak-ish-wrapper-ios-

Wrapper to maximize ISH iOS app capabilities without jailbreak

ios-securitymobile-securitypenetration-testing+3
42 months ago
Previous1…969798…100Next