Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
885 results
CVE-2021-46422 preview

CVE-2021-46422

GitHubkelemaoya/cve-2021-46422

PoC exploit for CVE-2021-46422, an OS command injection vulnerability in Korean wireless routers. Includes a Python script for single or batch URL…

command-and-controlexploitationpenetration-testing+2
3 years ago
CVE-2020-11990-Cordova preview

CVE-2020-11990-Cordova

GitHubforse01/cve-2020-11990-cordova

Proof-of-concept exploit for CVE-2020-11990 targeting Apache Cordova applications, demonstrating a remote code execution vulnerability in the mobile…

exploitationmobile-securitypenetration-testing+2
5 years ago
CVE-2021-21315-POC preview

CVE-2021-21315-POC

GitHubxmohamed0/cve-2021-21315-poc

Proof-of-concept exploit for CVE-2021-21315, demonstrating remote code execution in a web application framework. Intended for security testing and…

exploitationpayload-generationpenetration-testing+2
4 years ago
CVE-2021-2394 preview

CVE-2021-2394

GitHubfasanhlieu/cve-2021-2394

Proof-of-concept exploit for CVE-2021-2394, demonstrating a specific vulnerability in a web application framework.

exploitationvulnerability-analysisweb-application-exploitation
2 years ago
Rogue-Framework preview

Rogue-Framework

GitHubthisistfs/rogue-framework

Desktop workbench for AFL++ fuzzing, cross-architecture QEMU emulation, harness development, Ghidra headless analysis, custom mutators, and patch…

binary-analysisdebuggersdynamic-analysis-sandboxing+4
1921 days ago
CVE-2024-54152 preview

CVE-2024-54152

GitHubmath-x-io/cve-2024-54152

PoC exploit for Angular Expressions sandbox escape (CVE-2024-54152) achieving RCE via malicious expression. Includes Docker environment and payload…

educationexploitationpayload-development+2
121 year ago
CVE-2019-19609 preview

CVE-2019-19609

GitHubebadfd/cve-2019-19609

Strapi Framework Vulnerable to Remote Code Execution

exploitationpayload-developmentpenetration-testing+2
75 years ago
CVE-2023-6019 preview

CVE-2023-6019

GitHubjoaquinrrr/cve-2023-6019

PoC exploit for CVE-2023-6019 targeting unauthenticated Remote Code Execution in Anyscale Ray Dashboard via the Jobs API. Delivers a reverse shell on…

command-and-controlexploitationpenetration-testing+3
63 months ago
EXPLOIT-CVE-2024-7804 preview

EXPLOIT-CVE-2024-7804

GitHubjoaovicdev/exploit-cve-2024-7804

Docker lab + Python exploit for CVE-2024-7804 (PyTorch torch.distributed.rpc unsafe pickle deserialization RCE, CWE-502, torch <= 2.3.1)

binary-exploitationeducationexploitation+2
11 days ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubkhidottrivi/cve-2022-22965

In-depth technical analysis of CVE-2022-22965 (Spring4Shell) with environment setup, debug walkthrough, and exploit chain breakdown for educational…

code-analysiseducationexploitation+3
44 years ago
CVE-2026-75429_PowerJob_friend_process_RCE preview

CVE-2026-75429_PowerJob_friend_process_RCE

GitHubunpredictable21/cve-2026-75429_powerjob_friend_process_rce

Unauthenticated remote code execution exploit for PowerJob Server via Groovy injection in the /friend/process endpoint, enabling arbitrary command…

exploitationpenetration-testingremote-access-trojan+2
1 month ago
CVE-2021-3560-exploit preview

CVE-2021-3560-exploit

GitHubjeanback1/cve-2021-3560-exploit

CVE-2021-3560 — Polkit privilege escalation exploit via accounts-daemon D-Bus race condition

educationexploitationpenetration-testing+3
3 months ago
JXL_Infotainment_CVE-2025-69515 preview

JXL_Infotainment_CVE-2025-69515

GitHubthorat-shubham/jxl_infotainment_cve-2025-69515

Proof-of-concept exploit for CVE-2025-69515 demonstrating static GPS spoofing on JXL 9-inch Android infotainment units via SDR-based signal…

embedded-systems-securityexploitationhardware-iot-security+4
5 months ago
CVE-2026-33701-Unsafe-Deserialization-in-OpenTelemetry-Java-Agent-RMI-Instrumentation preview

CVE-2026-33701-Unsafe-Deserialization-in-OpenTelemetry-Java-Agent-RMI-Instrumentation

GitHubpl4tyz/cve-2026-33701-unsafe-deserialization-in-opentelemetry-java-agent-rmi-instrumentation

Technical analysis of CVE-2026-33701, an unsafe deserialization vulnerability in OpenTelemetry Java Agent RMI instrumentation, including exploit…

educationexploitationvulnerability-analysis+1
5 months ago
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubw2hcorp/cve-2025-29927-poc

Here is a simple but effective exploit for CVE-2025-29927.

exploitationpenetration-testingred-teaming+3
11 year ago
Ashwesker-CVE-2026-21440 preview

Ashwesker-CVE-2026-21440

GitHubredpack-kr/ashwesker-cve-2026-21440

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…

educationexploitationpenetration-testing+3
8 months ago
CVE-2017-9822 preview

CVE-2017-9822

GitHubtranphuc2005/cve-2017-9822

Detailed analysis and proof-of-concept exploit for CVE-2017-9822, an XXE/insecure deserialization vulnerability in DotNetNuke CMS leading to remote…

binary-exploitationexploitationpayload-development+3
1 year ago
apache__flink_CVE-2020-17519_1-11-2 preview

apache__flink_CVE-2020-17519_1-11-2

GitHubshoucheng3/apache__flink_cve-2020-17519_1-11-2

Exploit for Apache Flink CVE-2020-17519 targeting directory traversal vulnerability in versions 1.11.2 and earlier, enabling unauthorized file read…

exploitationgeneral-purpose-utilitiesvulnerability-analysis+1
1 year ago
Previous1…202122…50Next