Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
1
5 months ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubthemalwareguardian/cve-2017-14980

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can…

binary-exploitationdebuggerseducation+7
15 months ago
DarkSword_analysis preview

DarkSword_analysis

GitHubstationedk-06/darksword_analysis

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

binary-analysiseducationexploit-frameworks+5
15 months ago
cve-2017-9822 preview

cve-2017-9822

GitHubtnot123/cve-2017-9822

In-depth technical analysis and proof-of-concept for CVE-2017-9822, an insecure deserialization vulnerability in DotNetNuke leading to remote code…

binary-exploitationcode-analysisdebuggers+8
10 months ago
cve-2019-1663 preview

cve-2019-1663

GitHubkylvgoi/cve-2019-1663

Educational exploit for CVE-2019-1663 targeting a stack-based buffer overflow in Cisco RV routers. Includes a Python exploit script, reverse shell…

binary-exploitationeducationembedded-systems-security+5
8 months ago
CVE-2025-60854 preview

CVE-2025-60854

GitHubk0n9-log/cve-2025-60854

Technical analysis and proof-of-concept exploit for a command injection vulnerability (CVE-2025-60854) in D-Link AX1500 routers, enabling…

binary-analysiscommand-and-controlembedded-systems-security+7
8 months ago
CVE-2014-6271-Shellshock- preview

CVE-2014-6271-Shellshock-

GitHubdrhaitham/cve-2014-6271-shellshock-

Hands-on lab for exploiting Shellshock (CVE-2014-6271) with curl, Burp Suite, Metasploit, and reverse shells. Includes attack chain, countermeasures,…

command-and-controlctfeducation+8
8 months ago
CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit preview

CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit

GitHubpl4tyz/cve-2025-14611-centrestack-and-triofox-full-poc-exploit

PoC exploit for CVE-2025-14611 targeting hardcoded AES keys in Gladinet CentreStack/Triofox. Forges access tickets for unauthenticated arbitrary file…

authenticationcryptographyexploitation+6
7 months ago
analyze-Exploit-CVE-2023-22518-Confluence preview

analyze-Exploit-CVE-2023-22518-Confluence

GitHubd3ckkno0b/analyze-exploit-cve-2023-22518-confluence

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

code-analysisdebuggerseducation+4
11 year ago
Log4Shell-CVE-2021-44228 preview

Log4Shell-CVE-2021-44228

GitHubdrhaitham/log4shell-cve-2021-44228

Hands-on lab demonstrating Log4Shell (CVE-2021-44228) exploitation using Docker, Kali Linux, Burp Suite, and log4j-shell-poc. Designed for controlled…

command-and-controleducationexploitation+7
8 months ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubhqdat809/cve-2021-40444

Malicious DOCX generator exploiting CVE-2021-40444 for remote code execution via crafted Office documents, with integrated hosting server for payload…

exploitationmalware-analysispayload-generation+3
3 years ago
CVE-2020-12124 preview

CVE-2020-12124

GitHubscorpion-security-labs/cve-2020-12124

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

binary-analysiscommand-and-controleducation+8
6 months ago
cve-2021-40444 preview

cve-2021-40444

GitHubjamesrep/cve-2021-40444

Reverse-engineered analysis of CVE-2021-40444 exploitation via malicious Word document, OLE-object loading, ActiveX CAB download, and PE payload…

educationexploitationmalware-analysis+3
4 years ago
CVE-2025-26244 preview

CVE-2025-26244

GitHubjarm222/cve-2025-26244

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

command-and-controlexploitationpayload-development+4
1 year ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubalexcot25051999/cve-2021-40444

Generates malicious DOCX files exploiting CVE-2021-40444 to achieve remote code execution via crafted CAB and HTML payloads, with a built-in hosting…

command-and-controlexploitationmalware-analysis+3
4 years ago
CVE-2023-50564 preview
Archived

CVE-2023-50564

GitHubipuig/cve-2023-50564

Proof-of-concept exploit for CVE-2023-50564 targeting Pluck CMS, delivering a reverse shell via malicious module installation.

exploitationpayload-generationreverse-engineering+2
2 years ago
InjuredAndroid preview
Archived

InjuredAndroid

GitHubb3nac/injuredandroid

A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.

android-securityctfeducation+5
7635 years ago
Previous123Next