Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3938 results
CVE-2026-43735 preview

CVE-2026-43735

GitHubdem0ns/cve-2026-43735

Proof-of-concept exploit for CVE-2026-43735, a WebKit cross-origin information disclosure vulnerability in Safari < 26.5.2. Demonstrates leaking user…

exploitationinformation-gatheringvulnerability-analysis+1
1
3 months ago
BlueDoor preview

BlueDoor

GitHubsethwhy/bluedoor

Can you exploit the EternalBlue vulnerability (CVE-2017-0144) on a Windows 7 system and retrieve the hidden flag? Your goal is to gain administrative…

ctfeducationexploitation+7
21 year ago
Gui-poc-test preview

Gui-poc-test

GitHubromanc9/gui-poc-test

A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432

exploitationinformation-gatheringpayload-development+3
22 years ago
CVE-2019-17662 preview

CVE-2019-17662

GitHubbl4ck574r/cve-2019-17662

Exploit for CVE-2019-17662, a path traversal vulnerability in ThinVNC, demonstrating URL normalization bypass to access arbitrary files on the target…

exploitationpenetration-testingreconnaissance+2
23 years ago
CVE-2022-41401 preview

CVE-2022-41401

GitHubixsly/cve-2022-41401

Proof-of-concept exploit for CVE-2022-41401, a server-side request forgery (SSRF) vulnerability in OpenRefine <= v3.5.2, enabling unauthorized…

exploitationinformation-gatheringpenetration-testing+2
13 years ago
ImageMagick-lfi-poc preview

ImageMagick-lfi-poc

GitHubfanbyprinciple/imagemagick-lfi-poc

Proof-of-concept exploit for CVE-2022-44268 enabling arbitrary file read via crafted PNG images processed by ImageMagick. Includes generation and…

ctfexploitationinformation-gathering+3
13 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubr00tven0m/cve-2021-41773

Simple proof-of-concept exploit script for Apache HTTP Server path traversal vulnerability CVE-2021-41773, targeting version 2.4.49 to read arbitrary…

exploitationinformation-gatheringpenetration-testing+2
15 years ago
CVE-2023-27163-POC preview

CVE-2023-27163-POC

GitHubthickcoco/cve-2023-27163-poc

Poc of SSRF for Request-Baskets (CVE-2023-27163)

exploitationfuzzinginformation-gathering+2
13 years ago
CVE-2019-11510-PulseVPN preview

CVE-2019-11510-PulseVPN

GitHubpwn3z/cve-2019-11510-pulsevpn

Exploit and detection scripts for CVE-2019-11510, enabling unauthenticated remote file reading on Pulse Secure VPN appliances, with IP scanning and…

exploitationinformation-gatheringreconnaissance+2
15 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubnico989/cve-2022-1388

PoC for CVE-2022-1388 affecting F5 BIG-IP.

exploitationpenetration-testingreconnaissance+2
12 years ago
CVE-2022-1388-F5-BIG-IP preview

CVE-2022-1388-F5-BIG-IP

GitHubvesperp/cve-2022-1388-f5-big-ip

Exploit for CVE-2022-1388 targeting F5 BIG-IP iControl REST API authentication bypass. Reads targets from a file and executes the vulnerability check.

exploitationinformation-gatheringpenetration-testing+2
14 years ago
CVE-2019-17671 preview

CVE-2019-17671

GitHubrhbb/cve-2019-17671

Proof-of-concept exploit for CVE-2019-17671, a WordPress plugin vulnerability exploitable via crafted URL parameters to achieve unauthorized data…

exploitationpenetration-testingreconnaissance+2
26 years ago
CVE-2018-13379-FortinetVPN preview

CVE-2018-13379-FortinetVPN

GitHubpwn3z/cve-2018-13379-fortinetvpn

Exploit for CVE-2018-13379: unauthenticated path traversal in Fortinet FortiOS SSL VPN portal allowing system file download via crafted HTTP requests.

exploitationinformation-gatheringpenetration-testing+2
15 years ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubch3m1cl/cve-2025-31161

Python exploit script for CVE-2025-31161 targeting CrushFTP. Enumerates users and creates malicious accounts with elevated permissions via HTTP…

exploitationinformation-gatheringpayload-generation+3
110 months ago
CVE-2013-3827 preview

CVE-2013-3827

GitHubthistehneisen/cve-2013-3827

Quick PoC checker for common configurations that might be available via directory traversal due to CVE-2013-3827

exploitationinformation-gatheringpenetration-testing+2
13 years ago
CVE-2019-9053-exploit preview

CVE-2019-9053-exploit

GitHubjeanback1/cve-2019-9053-exploit

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

exploitationinformation-gatheringpassword-cracking+3
4 months ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubayiezola/cve-2026-48908

Unauthenticated RCE PoC for CVE-2026-48908 SP Page Builder (Joomla) arbitrary file upload and remote code execution exploit with mass scaning…

exploitationinformation-gatheringpayload-development+4
3 months ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
4 months ago
Previous1…99100Next