Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
885 results
Havoc-C2-SSRF-to-RCE preview

Havoc-C2-SSRF-to-RCE

GitHubsebr-dev/havoc-c2-ssrf-to-rce

This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE exploit from @hyperreality. This exploit executes…

command-and-controlexploitationpenetration-testing+3
9
1 year ago
cve-2021-38314 preview

cve-2021-38314

GitHubphrantom/cve-2021-38314

Python exploit for CVE-2021-38314 targeting unauthenticated information disclosure in the Gutenberg Template Library & Redux Framework WordPress…

exploitationinformation-gatheringpenetration-testing+2
64 years ago
CVE-2019-2107 preview

CVE-2019-2107

GitHubinfiniteloopers/cve-2019-2107

Proof-of-concept exploit for CVE-2019-2107, demonstrating remote code execution via crafted HEVC video on Android media framework. Includes crash…

android-securitybinary-exploitationexploitation+4
47 years ago
ImageMagick-CVE-2017-15277 preview

ImageMagick-CVE-2017-15277

GitHubhexrom/imagemagick-cve-2017-15277

Proof-of-concept exploit for ImageMagick CVE-2017-15277 memory leak vulnerability, designed for use with the gifoeb fuzzing framework.

binary-analysisexploitationfuzzing+2
56 years ago
CVE-2019-16097 preview

CVE-2019-16097

GitHubluckybool1020/cve-2019-16097

PoC exploit for CVE-2019-16097 targeting unauthorized admin creation in Harbor, built on the pocsuite framework for automated vulnerability…

exploitationpayload-generationpenetration-testing+2
23 years ago
CVE-2022-22965-Spring4Shell preview

CVE-2022-22965-Spring4Shell

GitHubkuri119/cve-2022-22965-spring4shell

Exploit for CVE-2022-22965 (Spring4Shell) enabling remote code execution on unpatched Spring Framework applications via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
2 months ago
CVE-2018-20062 preview

CVE-2018-20062

GitHubyilin1203/cve-2018-20062

Exploit for CVE-2018-20062 targeting ThinkPHP 5.0.23, designed for vulnerability verification and penetration testing of web applications running the…

exploitationinformation-gatheringpenetration-testing+2
23 years ago
CVE-2019-11043 preview

CVE-2019-11043

GitHubfairyming/cve-2019-11043

Proof-of-concept exploit for CVE-2019-11043, a PHP-FPM underflow vulnerability, built on the pocsuite framework for automated web application…

exploitationpayload-developmentpenetration-testing+2
16 years ago
Letta-CVE-2025-51482-RCE preview

Letta-CVE-2025-51482-RCE

GitHubkai-one001/letta-cve-2025-51482-rce

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

code-analysisexploitationpenetration-testing+3
11 year ago
CVE-2018-15133-laravel-framework preview

CVE-2018-15133-laravel-framework

GitHubflame-11/cve-2018-15133-laravel-framework

Reproducible Docker lab for CVE-2018-15133 (Laravel Framework token unserialize RCE) with a known APP_KEY and a /poc route for testing exploit…

container-securityeducationexploitation+3
8 months ago
CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla preview

CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla

GitHubyallasec/cve-2026-21627---tassos-novarain-framework-plg_system_nrframework-exploit---joomla

Python exploit for CVE-2026-21627, an unauthenticated arbitrary PHP file inclusion in Joomla's Novarain Framework, enabling file upload, delete, and…

exploitationpayload-developmentpenetration-testing+3
6 months ago
CVE-2024-46506 preview

CVE-2024-46506

GitHubfufu-byte/cve-2024-46506

Standalone Python exploit for CVE-2024-46506, providing a lightweight, portable remote code execution module without requiring the Metasploit…

educationexploitationpenetration-testing+2
8 months ago
yamcs__yamcs_CVE-2023-45277_5-8-6 preview

yamcs__yamcs_CVE-2023-45277_5-8-6

GitHubshoucheng3/yamcs__yamcs_cve-2023-45277_5-8-6

Java-based mission control framework with YAML configuration, supporting telemetry, commanding, and simulation for spacecraft operations. Includes…

configuration-auditingexploitationnetwork-security+3
1 year ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubc33dd/cve-2022-22965

C-based exploit for Spring4Shell (CVE-2022-22965) remote code execution vulnerability in Spring Core framework.

exploitationpayload-developmentpenetration-testing+2
3 years ago
G3_Frameworks_av_CVE-2024-0023 preview

G3_Frameworks_av_CVE-2024-0023

GitHubabrarkhan/g3_frameworks_av_cve-2024-0023

Proof-of-concept exploit for CVE-2024-0023 in Android's frameworks/av, implemented in C++ to demonstrate the media framework vulnerability.

android-securitybinary-exploitationembedded-systems-security+3
2 years ago
CVE-2017-8759_-SOAP_WSDL preview

CVE-2017-8759_-SOAP_WSDL

GitHubhomjxi0e/cve-2017-8759_-soap_wsdl

Proof-of-concept exploit for CVE-2017-8759, a remote code execution vulnerability in Microsoft .NET Framework via SOAP WSDL, with a Python-based web…

exploitationpayload-developmentpenetration-testing+2
8 years ago
frameworks_base_Aosp10_r33_CVE-2021-0315 preview

frameworks_base_Aosp10_r33_CVE-2021-0315

GitHubpazhanivel07/frameworks_base_aosp10_r33_cve-2021-0315

Android framework base repository for AOSP 10 r33, containing a patch or exploit related to CVE-2021-0315.

android-securityexploitationvulnerability-analysis
4 years ago
apache__myfaces_CVE-2011-4367_2-0-11 preview

apache__myfaces_CVE-2011-4367_2-0-11

GitHubshoucheng3/apache__myfaces_cve-2011-4367_2-0-11

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

code-analysisstatic-analysisvulnerability-analysis+2
1 year ago
Previous1…192021…50Next