Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
Facad1ng preview

Facad1ng

GitHubspyboy-productions/facad1ng

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

defensive-toolseducationphishing+3
529
9 months ago
POC-CVE-2025-55182 preview

POC-CVE-2025-55182

GitHubiamblacksolo2-bugbounty/poc-cve-2025-55182

Bash-based scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

educationexploitationpenetration-testing+3
10 months ago
CVE-2026-5027-Langflow preview

CVE-2026-5027-Langflow

GitHublayer-6/cve-2026-5027-langflow

Multi-CVE exploit tool for pre-auth remote code execution on Ivanti Sentry and FortiSandbox. Features interactive shell, webshell deployment,…

command-and-controlexploitationpayload-development+8
4 months ago
CVE-2024-46256 preview

CVE-2024-46256

GitHubkimtangker/cve-2024-46256

CVE-2024-46256 tool

exploitationpayload-generationpenetration-testing+3
11 months ago
CVE-2021-22941 preview

CVE-2021-22941

GitHubhoav18/cve-2021-22941

Python exploit for CVE-2021-22941 targeting Citrix ShareFile RCE with shell and ping options for remote command execution and network probing.

exploitationpenetration-testingred-teaming+3
134 years ago
CVE-2024-23692 preview

CVE-2024-23692

GitHubvanboomqi/cve-2024-23692

Python exploit script for CVE-2024-23692, a template injection RCE in Rejetto HFS 2.3m. Supports single and batch URL exploitation with custom…

exploitationpenetration-testingred-teaming+3
122 years ago
clickjacking-poc preview

clickjacking-poc

GitHubnccgroup/clickjacking-poc

Clickjacking PoC Generator

exploitationpenetration-testingred-teaming+2
366 years ago
CVE-2023-24488 preview

CVE-2023-24488

GitHubsecuritycipher/cve-2023-24488

POC for CVE-2023-24488

exploitationpenetration-testingred-teaming+2
143 years ago
CVE-2025-55182-exploit preview

CVE-2025-55182-exploit

GitHublemonteatw1/cve-2025-55182-exploit

Python-based proof-of-concept exploit for CVE-2025-55182, targeting web applications via URL parameter injection for authorized penetration testing.

exploitationpenetration-testingred-teaming+2
610 months ago
CVE-2025-33053-Proof-Of-Concept preview

CVE-2025-33053-Proof-Of-Concept

GitHubdevbuihieu/cve-2025-33053-proof-of-concept

CVE-2025-33053 Proof Of Concept (PoC)

command-and-controlexploitationlateral-movement+6
621 year ago
CVE-2022-24716 preview

CVE-2022-24716

GitHubpumpkinpiteam/cve-2022-24716

Python exploit for CVE-2022-24716: arbitrary file disclosure in Icinga Web 2 versions <2.8.6, <2.9.6, <2.10. Usage: python3 exploit.py -u <url> -f…

exploitationinformation-gatheringpenetration-testing+3
3 years ago
CVE-2014-6287 preview

CVE-2014-6287

GitHub10cks/cve-2014-6287

Rejetto http File Server 2.3.x (Reverse shell)

command-and-controlexploitationpayload-generation+3
3 years ago
CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept preview

CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

GitHubkra1t0/cve-2025-33053-webdav-rce-poc-and-c2-concept

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

command-and-controleducationexploitation+5
31 year ago
ip-obfuscation preview

ip-obfuscation

GitHubhackinglz/ip-obfuscation

Generates obfuscated IP addresses and URLs using DWORD, octal, hex, IPv6-mapped, and fake-domain @ tricks for penetration testing, phishing…

educationimpersonation-toolspenetration-testing+6
4710 months ago
CVE-2022-29464 preview

CVE-2022-29464

GitHubhev0x/cve-2022-29464

Python-based exploit for WSO2 RCE (CVE-2022-29464) supporting multi-target scanning via URL list input.

exploitationpenetration-testingred-teaming+2
54 years ago
flareprox preview

flareprox

GitHubmrturvey/flareprox

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

api-security-testinginformation-gatheringpenetration-testing+5
79511 months ago
CVE-2023-42442 preview

CVE-2023-42442

GitHubholygu/cve-2023-42442

Go-based exploit for JumpServer unauthorized access vulnerability (CVE-2023-42442) with a single-command execution interface for penetration testing.

exploitationpenetration-testingred-teaming+2
393 years ago
CVE-2026-27180-MajorDoMo-unauthenticated-RCE preview

CVE-2026-27180-MajorDoMo-unauthenticated-RCE

GitHubmbanyamer/cve-2026-27180-majordomo-unauthenticated-rce

Proof-of-concept exploit for CVE-2026-27180, an unauthenticated RCE in MajorDoMo via update URL poisoning, delivering a webshell to the web root.

exploitationpayload-developmentpenetration-testing+3
7 months ago
Previous123Next