Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
387 results
devin-cve48384-1789318364-1162143-parent preview

devin-cve48384-1789318364-1162143-parent

GitHubfishjojo1/devin-cve48384-1789318364-1162143-parent

Authorized reachability probe for CVE-2025-48384, used to verify whether a target is exposed to the vulnerability in a controlled testing context.

exploitationpenetration-testingreconnaissance+2
12h 9m ago
nuclei-CVE-2025-24813 preview

nuclei-CVE-2025-24813

GitHubsebastianmautner/nuclei-cve-2025-24813

University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting…

exploitationpenetration-testingreconnaissance+4
1 day ago
openfire-ssrf-cve-2019-18394 preview

openfire-ssrf-cve-2019-18394

GitHubl0lsec/openfire-ssrf-cve-2019-18394

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

exploitationpenetration-testingreconnaissance+4
4 days ago
spookyssl-pcaps preview

spookyssl-pcaps

GitHubfox-it/spookyssl-pcaps

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

intrusion-detectionnetwork-securitypacket-sniffing-analysis+2
103 years ago
CVE-2024-7593 preview

CVE-2024-7593

GitHubaerchy/cve-2024-7593

Exploit for CVE-2024-7593, a critical RCE in Pulse Secure VPN management interface, allowing authenticated attackers to execute arbitrary commands.…

exploitationpenetration-testingreconnaissance+2
1 year ago
CVE-2026-78850 preview

CVE-2026-78850

GitHubslo-cyber-sec/cve-2026-78850

Proof-of-concept demonstrating an authenticated blind SSRF in Matomo's SiteContentDetector, allowing internal network reconnaissance and requests to…

exploitationpenetration-testingreconnaissance+3
2 months ago
CVE-2024-9465 preview

CVE-2024-9465

GitHubmustafaakalin/cve-2024-9465

Proof-of-concept exploit for CVE-2024-9465, a time-based SQL injection in Check Point Expedition, with Shodan/FOFA search queries and integration…

exploitationpenetration-testingreconnaissance+2
1 year ago
kamene preview

kamene

GitHubphaethon/kamene

Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3…

information-gatheringnetwork-mappingnetwork-security+3
8725 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubalkaid176/cve-2017-7921

Exploit tool for CVE-2017-7921 in Hikvision cameras, supporting vulnerability detection, credential extraction, and snapshot retrieval via…

exploitationpenetration-testingreconnaissance+2
64 years ago
CVE-2026-42228 preview

CVE-2026-42228

GitHubrudsarkar/cve-2026-42228

Proof-of-concept exploit for CVE-2026-42228, an unauthenticated chat execution hijacking vulnerability in n8n, with automated scanning and attack…

exploitationpenetration-testingreconnaissance+3
4 months ago
CVE-2026-34160 preview

CVE-2026-34160

GitHubromain-deperne/cve-2026-34160

Unauthenticated SSRF in the Chamilo LMS PENS plugin — CVE-2026-34160 / CVSS 8.6

exploitationpenetration-testingreconnaissance+3
6 days ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

exploitationphishingreconnaissance+2
6 days ago
CVE-2026-33555 preview

CVE-2026-33555

GitHubr3verii/cve-2026-33555

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users…

exploitationnetwork-securitypapers-research+3
24 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubpuckiestyle/cve-2021-41773

Python script to exploit CVE-2021-41773, a path traversal vulnerability in Apache 2.4.49, allowing file disclosure and remote code execution.

exploitationpenetration-testingreconnaissance+2
4 years ago
CVE-2026-39842 preview

CVE-2026-39842

GitHubkeraattin/cve-2026-39842

Critical remote code execution vulnerability in OpenRemote's Rules Engine allows authenticated users with `write:rules` role to execute arbitrary…

exploitationpenetration-testingreconnaissance+3
14 months ago
CVE-2026-22679 preview

CVE-2026-22679

GitHubkeraattin/cve-2026-22679

Unauthenticated RCE exploit and detection scanner for Weaver E-cology, targeting the dubboApi debug endpoint. Includes PoC, Nmap NSE script, and…

exploitationpenetration-testingreconnaissance+3
45 months ago
CVE-2021-1965 preview

CVE-2021-1965

GitHubfoxtrot/cve-2021-1965

Proof-of-concept exploit for CVE-2021-1965, a Wi-Fi vulnerability, leveraging libwifi for packet parsing and crafted for educational purposes.

binary-exploitationexploitationexploit-frameworks+2
34 years ago
tenda-hg10-rce preview

tenda-hg10-rce

GitHube76f01z/tenda-hg10-rce

CVE-2026-1689 Unauthenticated RCE for the Tenda HG10

exploitationpenetration-testingreconnaissance+2
5 months ago
Previous12…22Next