Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
340 results
CVE-2025-48932-Invision-Community-SQLi-Exploit preview

CVE-2025-48932-Invision-Community-SQLi-Exploit

GitHubcerberusmrxi/cve-2025-48932-invision-community-sqli-exploit

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

data-exfiltrationexploitationinformation-gathering+6
1
2 months ago
cpx_proftpd preview

cpx_proftpd

GitHubxyk0x/cpx_proftpd

Tool for exploit CVE-2015-3306

exploitationinformation-gatheringpenetration-testing+2
111 years ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubtx-one/cve-2025-31161

CrushFTP CVE-2025-31161 Exploit Tool 🔓

authenticationexploitationinformation-gathering+3
21 year ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubwa6n3r/cve-2024-3400

Multi-threaded exploit tool for CVE-2024-3400 in Palo Alto PAN-OS with automated artifact download and detailed logging for confirmed RCE.

exploitationpenetration-testingreconnaissance+3
15 months ago
Gui-poc-test preview

Gui-poc-test

GitHubromanc9/gui-poc-test

A testing tool for CobaltStrike-RCE:CVE-2022-39197; Weblogic-RCE:CVE-2023-21839; MinIO:CVE-2023-28432

exploitationinformation-gatheringpayload-development+3
22 years ago
Chrome-and-Edge-Version-Dumper preview

Chrome-and-Edge-Version-Dumper

GitHubmav3r1ck0x1/chrome-and-edge-version-dumper

Powershell script that dumps Chrome and Edge version to a text file in order to determine if you need to update due to CVE-2022-1096

general-purpose-utilitiesinformation-gatheringscripting-automation+1
24 years ago
dnsmasq-cve-2026 preview

dnsmasq-cve-2026

GitHubjianrongxiao-linksys/dnsmasq-cve-2026

Automated defect verification tool for 6 dnsmasq CVEs (CVE-2026-2291, 4890, 4891, 4892, 4893, 5172)

binary-analysisdns-analysisexploitation+4
4 months ago
CVE-2023-20198 preview

CVE-2023-20198

GitHubcharlesjson/cve-2023-20198

Python-based exploit tool for CVE-2023-20198 targeting Cisco IOS XE routers. Provides automated exploitation and post-exploitation capabilities for…

exploitationinformation-gatheringpenetration-testing+3
3 months ago
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
5 months ago
Myesve preview

Myesve

GitHubnyakki-labs-0x420/myesve

CVE-2024-38475 exploitation & scanning tool with Mullvad VPN rotation

exploitationinformation-gatheringpenetration-testing+5
4 months ago
CVE-2022-29464-mass preview

CVE-2022-29464-mass

GitHubamit-pathak009/cve-2022-29464-mass

Mass exploit tool for CVE-2022-29464, a pre-auth RCE in WSO2 Carbon Server, with single-target and batch scanning via file input and search dorks.

exploitationinformation-gatheringreconnaissance+2
14 years ago
CVE-2025-15467 preview

CVE-2025-15467

GitHubmr-r3b00t/cve-2025-15467

discovery tool (powershell)

exploitationinformation-gatheringpenetration-testing+3
18 months ago
POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0 preview

POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0

GitHubheavyghost-le/poc_sql_injection_in_parse_server_prior_6.5.7_-_7.1.0

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

database-securityexploitationinformation-gathering+3
11 year ago
Apache-CVE-2021-42013-RCE-Exploit preview

Apache-CVE-2021-42013-RCE-Exploit

GitHubfakhricrd/apache-cve-2021-42013-rce-exploit

A powerful and reliable exploit tool for Apache HTTP Server vulnerabilities CVE-2021-41773 and CVE-2021-42013. This tool provides remote code…

exploitationpayload-developmentpenetration-testing+3
11 months ago
CVE-2024-11318 preview

CVE-2024-11318

GitHubxthalach/cve-2024-11318

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

authentication-authorizationexploitationinformation-gathering+3
11 year ago
CVE-2024-9821 preview

CVE-2024-9821

GitHubrandomrobbiebf/cve-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
12 years ago
CVE-2021-42237-SiteCore-XP preview

CVE-2021-42237-SiteCore-XP

GitHubvesperp/cve-2021-42237-sitecore-xp

Automated exploit tool for CVE-2021-42237 targeting SiteCore XP. Reads target URLs from a file and leverages DNSLog for out-of-band detection.

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2023-35078 preview

CVE-2023-35078

GitHub0nsec/cve-2023-35078

CVE-2023-35078 - Ivanti MobileIron Core Remote Unauthenticated API Access Exploit tool

exploitationinformation-gatheringpenetration-testing+3
11 year ago
Previous1…141516…19Next