Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
419 results
Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service preview

Log4J-Log4Shell-CVE-2021-44228-Spring-Boot-Test-Service

GitHubzsolt-halo/log4j-log4shell-cve-2021-44228-spring-boot-test-service

Dockerized Spring Boot service intentionally vulnerable to Log4Shell (CVE-2021-44228) for testing detection tools, payloads, and exploit capabilities…

educationexploitationlabs-practice+3
13
4 years ago
CVE-2017-1000117 preview

CVE-2017-1000117

GitHubtimwr/cve-2017-1000117

Proof of concept of CVE-2017-1000117

educationexploitationpenetration-testing+2
79 years ago
Vulfy preview

Vulfy

GitHubmindpatch/vulfy

🐺 Vulfy – Fast Rust based package version scanner

code-analysisdevsecopssupply-chain-security+2
161 year ago
pwnacle-fusion preview

pwnacle-fusion

GitHubmekanismen/pwnacle-fusion

Automated exploit for CVE-2012-3153 / CVE-2012-3152

exploitationpayload-generationpenetration-testing+2
812 years ago
CVE-2021-36934 preview

CVE-2021-36934

GitHubjoranslingerland/cve-2021-36934

Fix for the CVE-2021-36934

configuration-auditingeducationmisconfiguration+2
94 years ago
faraday_addon preview

faraday_addon

GitHubinfobyte/faraday_addon

A browser extension for faradaysec platform https://faradaysec.com

penetration-testingvulnerability-analysisweb-proxies-interception+1
67 years ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubvladrico/cve-2019-19781

Shitrix : CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit

exploitationpenetration-testingremote-access-tool+2
73 years ago
CVE-2015-6637 preview

CVE-2015-6637

GitHubbetalphafai/cve-2015-6637

Proof-of-concept exploit for Android privilege escalation vulnerability CVE-2015-6637, demonstrating memory corruption to gain elevated privileges.

android-securitybinary-exploitationexploitation+2
710 years ago
CVE-2021-38647 preview

CVE-2021-38647

GitHubmidoxnet/cve-2021-38647

CVE-2021-38647 POC for RCE

exploitationpenetration-testingred-teaming+2
85 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubabhishekmorla/cve-2022-26134

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

exploitationinformation-gatheringpenetration-testing+3
84 years ago
CVE-2023-51385 preview

CVE-2023-51385

GitHuble1a/cve-2023-51385

OpenSSH ProxyCommand RCE

command-and-controlexploitationpenetration-testing+2
52 years ago
CVE-2024-23334 preview

CVE-2024-23334

GitHubox1111/cve-2024-23334

CVE-2024-23334

educationexploitationpenetration-testing+2
62 years ago
CVE-2021-1965 preview

CVE-2021-1965

GitHubsqrtrev/cve-2021-1965

Proof-of-concept exploit for CVE-2021-1965, a WiFi zero-click RCE in Android's MBSSID parsing, causing buffer overflow and device reboot.

exploitationmobile-securitypenetration-testing+2
34 years ago
Fix-CVE-2021-44228 preview

Fix-CVE-2021-44228

GitHubalexandreheroux/fix-cve-2021-44228

Apply class remove process from ear/war/jar/zip archive, see https://logging.apache.org/log4j/2.x/

misconfigurationscripting-automationsupply-chain-security+2
64 years ago
jquery-prototype-pollution-fix preview

jquery-prototype-pollution-fix

GitHubbitnesswise/jquery-prototype-pollution-fix

A fix for CVE-2019-11358 (prototype pollution in jquery)

code-analysismisconfigurationstatic-analysis+2
67 years ago
CVE-2020-9484-exploit preview

CVE-2020-9484-exploit

GitHubanjai94/cve-2020-9484-exploit

Exploit script for Apache Tomcat RCE via deserialization (CVE-2020-9484), leveraging ysoserial payloads to achieve remote code execution.

exploitationpayload-developmentremote-access-tool+2
66 years ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubsolivaquaant/cve-2026-85706

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

data-exfiltrationexploitationinformation-gathering+7
16 days ago
CVE-2022-34303 preview

CVE-2022-34303

GitHubthemalwareguardian/cve-2022-34303

Demonstrates CVE-2022-34303 Secure Boot bypass via CryptoPro signed UEFI Shell, using the mm command to nullify gSecurity2 and load unsigned UEFI…

binary-exploitationeducationexploitation+7
16 days ago
Previous1…121314…24Next