Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
CVE-2018-6574-go-get-RCE preview

CVE-2018-6574-go-get-RCE

GitHubmalone5923/cve-2018-6574-go-get-rce

CVE-2018-6574: go get RCE solution for pentesterlab challenge

educationexploitationlabs-practice+2
1
6 years ago
Research-on-CVE-2025-9998 preview

Research-on-CVE-2025-9998

GitHubbalajigund/research-on-cve-2025-9998

vulnerability in CVE 2025-9998 and solution for those vulnerability with help artificial intelligence

ai-securityeducationpapers-research+2
7 months ago
CVE-2023-26136 preview

CVE-2023-26136

GitHubmorrisel/cve-2023-26136

This repository contains a solution for the CVE-2023-26136 vulnerability.

code-analysiseducationpapers-research+3
1 year ago
pentesterlab-cve-2018-6574 preview

pentesterlab-cve-2018-6574

GitHubthejuan1112/pentesterlab-cve-2018-6574

solution

binary-exploitationeducationexploitation+3
5 years ago
CVE-2026-39902 preview

CVE-2026-39902

GitHubkx00007/cve-2026-39902

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

code-analysisexploitationpenetration-testing+2
17 days ago
CVE-2026-39808 preview

CVE-2026-39808

GitHuberror-inside/cve-2026-39808

Fortinet FortiSandbox 4.4.0-4.4.8 - OS Command Injection via tracer-behavior Endpoint

command-and-controleducationexploitation+3
2 months ago
CVE-2022-34169 preview

CVE-2022-34169

GitHubdisnaming/cve-2022-34169

A PoC for CVE-2022-34169, for the SU_PWN challenge from SUCTF 2025

ctfeducationexploitation+3
31 year ago
cve-2026-31431-mitigation preview

cve-2026-31431-mitigation

GitHubyakovyakov/cve-2026-31431-mitigation

Detection and mitigation tooling for CVE-2026-31431 (Copy Fail) on Linux kernels. Includes Phalanx-CCS and Silent4Labs scripts plus an Ansible…

cloud-securityconfiguration-auditingdevsecops+3
3 months ago
CVE-2025-46295-fix-fms preview

CVE-2025-46295-fix-fms

GitHubsoliantconsulting/cve-2025-46295-fix-fms

Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with…

configuration-auditingdevsecopsscripting-automation+3
18 months ago
CVE-2020-15052 preview

CVE-2020-15052

GitHubpratikshad19/cve-2020-15052

Artica Proxy before 4.30.000000 Community Edition allows SQL Injection.

database-securityexploitationpenetration-testing+2
16 years ago
CVE-2021-36563 preview

CVE-2021-36563

GitHubedgarloyola/cve-2021-36563

Proof-of-concept for stored and reflected XSS vulnerabilities in CheckMK Management Web Console versions 1.5.0 to 2.0.0p9, with detailed disclosure…

educationexploitationpenetration-testing+3
13 years ago
CVE-2019-9653 preview

CVE-2019-9653

GitHubgrayoneday/cve-2019-9653

Proof-of-concept exploit for CVE-2019-9653 demonstrating unauthenticated remote code execution as root on NUUO NVR devices via vulnerable PHP scripts.

embedded-systems-securityexploitationiot-security+3
17 years ago
CVE-2020-15053 preview

CVE-2020-15053

GitHubpratikshad19/cve-2020-15053

Artica Proxy before 4.30.000000 Community Edition allows Reflected Cross Site Scripting.

educationinformation-gatheringpapers-research+3
6 years ago
CVE-2021-40905 preview

CVE-2021-40905

GitHubedgarloyola/cve-2021-40905

Proof-of-concept exploit for CVE-2021-40905, a remote code execution vulnerability in CheckMK Management Web Console via crafted .mkp extension…

code-analysisexploitationpenetration-testing+2
3 years ago
CVE-2020-13159 preview

CVE-2020-13159

GitHubinfosec4fun/cve-2020-13159

CVE-2020-13159 - Artica Proxy before 4.30.000000 Community Edition allows OS command injection.

command-and-controlexploitationpenetration-testing+2
6 years ago
log4j-CVE-2021-44228-workaround preview

log4j-CVE-2021-44228-workaround

GitHubgrimch/log4j-cve-2021-44228-workaround

general purpose workaround for the log4j CVE-2021-44228 vulnerability

exploitationincident-responsemisconfiguration+2
4 years ago
CVE-2026-15667 preview

CVE-2026-15667

GitHubcflowsec/cve-2026-15667

Python proof-of-concept for CVE-2026-15667, an authenticated local file inclusion in the WordPress Eventin plugin via the event_layout REST field.

exploitationpenetration-testingvulnerability-analysis+3
1 day ago
WinboxExploit preview
Archived

WinboxExploit

GitHubmsterusky/winboxexploit

C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]

exploitationpenetration-testingred-teaming+2
78 years ago
Previous12Next