Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
566 results
CVE-2021-27877-PoC preview

CVE-2021-27877-PoC

GitHubyashswarup12/cve-2021-27877-poc

A modified version of the Rapid7 Metasploit module for CVE-2021-27877 that supports direct command execution for reliable vulnerability validation.…

educationexploitationexploit-frameworks+3
2 months ago
CVE-2024-6387-poc-1 preview

CVE-2024-6387-poc-1

GitHubanhvutuan/cve-2024-6387-poc-1

CVE-2024-6387, also known as RegreSSHion, is a high-severity vulnerability found in OpenSSH servers (sshd) running on glibc-based Linux systems. It…

exploitationnetwork-securitypenetration-testing+3
22 years ago
CVE-2025-15276-poc preview

CVE-2025-15276-poc

GitHubahmedreda38/cve-2025-15276-poc

Proof of concept for CVE-2025-15276 - FontForge SFD File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability

binary-exploitationeducationexploitation+3
25 months ago
CVE-2022-42889-text4shell preview

CVE-2022-42889-text4shell

GitHubgoultarde/cve-2022-42889-text4shell

Proof of Concept (PoC) for CVE-2022-42889 (Text4Shell) targeting Apache Commons Text versions prior to 1.10.0. This script automates Remote Code…

exploitationpayload-generationpenetration-testing+3
18 months ago
CVE-2024-24590 preview

CVE-2024-24590

GitHubjunnythemarksman/cve-2024-24590

Deserialization of untrusted data can occur in versions 0.17.0 to 1.14.2 of the client SDK of Allegro AI’s ClearML platform, enabling a maliciously…

exploitationpayload-generationpenetration-testing+3
12 years ago
PoC-CVE-2024-23113 preview

PoC-CVE-2024-23113

GitHubminhpham123456789/poc-cve-2024-23113

A proof of concept for CVE 2024 23113 inspired by WatchTowr's article.

exploitationnetwork-securitypenetration-testing+3
3 months ago
Log4Shell-CVE-2021-44228-PoC preview

Log4Shell-CVE-2021-44228-PoC

GitHubpierpaolosestito-dev/log4shell-cve-2021-44228-poc

CVE 2021-44228 Proof-of-Concept. Log4Shell is an attack against Servers that uses vulnerable versions of Log4J.

command-and-controlexploitationpayload-development+3
13 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHub0xabdullah/cve-2020-5902

Python script to check CVE-2020-5902 (F5 BIG-IP devices).

exploitationinformation-gatheringpenetration-testing+3
16 years ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubmonstertsl/cve-2026-24061

Python-based scanner that detects CVE-2026-24061 in GNU Inetutils telnetd, allowing batch testing of multiple targets for the authentication bypass…

authenticationexploitationpenetration-testing+2
17 months ago
cve-2021-31630 preview

cve-2021-31630

GitHubadibna/cve-2021-31630

This is a automation of cve-2021-31630 exploitation

command-and-controlexploitationpenetration-testing+3
12 years ago
gerapy-cve-2021-43857 preview

gerapy-cve-2021-43857

GitHubprowlsec/gerapy-cve-2021-43857

Proof of Concept exploit for CVE‑2021‑43857: Authenticated Remote Code Execution in Gerapy (<0.9.8). Updated and automated version of the original…

educationexploitationpenetration-testing+3
11 year ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubnxploited/cve-2026-39987

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability

exploitationinformation-gatheringpenetration-testing+4
4 months ago
bladelogic_bmc-cve-2016-1542 preview

bladelogic_bmc-cve-2016-1542

GitHubpatriknordlen/bladelogic_bmc-cve-2016-1542

A rebuilt version of the exploit for CVE-2016-1542 and CVE-2016-1543 from insinuator.net

exploitationpenetration-testingremote-access-tool+2
9 years ago
cve-2021-41773 preview

cve-2021-41773

GitHubmightysai1997/cve-2021-41773

Exploit script for Apache HTTP Server 2.4.49/2.4.50 path traversal and remote code execution (CVE-2021-41773). Includes Docker-based reproduction…

educationexploitationpenetration-testing+3
3 years ago
CVE-2022-31814 preview

CVE-2022-31814

GitHubarunhatter/cve-2022-31814

This script is a proof-of-concept exploit for pfBlockerNG <= 2.1.4_26 that allows for remote code execution. It takes a single target URL or a list…

exploitationpayload-developmentpenetration-testing+3
2 years ago
Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763- preview

Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-

GitHubartemcyberlab/project-exploiting-a-vulnerability-in-fuel-cms-cve-2018-16763-

The goal of this project was to conduct a security audit of a blog recently launched by Ackme Support Incorporated, identifying any critical…

exploitationpenetration-testingred-teaming+3
1 year ago
Revenant preview
Archived

Revenant

GitHub0xtriboulet/revenant

Revenant - A 3rd party agent for Havoc that demonstrates evasion techniques in the context of a C2 framework

command-and-controlids-ips-evasionpayload-development+3
3892 years ago
sliver preview

sliver

GitHubbishopfox/sliver

Adversary Emulation Framework

adversarial-attackcommand-and-controldata-exfiltration+16
11.8k3 days ago
Previous1…567…32Next