Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
CVE-2021-20038-SonicWall-RCE preview

CVE-2021-20038-SonicWall-RCE

GitHubvesperp/cve-2021-20038-sonicwall-rce

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

command-and-controlexploitationpenetration-testing+3
1
4 years ago
CVE-2014-4688-pfsense preview

CVE-2014-4688-pfsense

GitHubjaydenblair/cve-2014-4688-pfsense

Modified proof-of-concept exploit for CVE-2014-4688, a command injection vulnerability in pfSense status_rrd_graph_img.php, enabling authenticated…

command-and-controleducationexploitation+3
7 months ago
cve-2024-21762-poc preview

cve-2024-21762-poc

GitHubcrackercat/cve-2024-21762-poc

CVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞,存在于其 SSL VPN 组件中。

exploitationpenetration-testingred-teaming+2
1 year ago
CVE-2025-1910-WatchGuard-Privilege-Escalation preview

CVE-2025-1910-WatchGuard-Privilege-Escalation

GitHublutrasecurity/cve-2025-1910-watchguard-privilege-escalation

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

command-and-controlexploitationlateral-movement+6
8 months ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubsariamubeen/cve-2024-10924

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

authentication-authorizationeducationexploitation+3
1 year ago
CVE-2018-13379 preview

CVE-2018-13379

GitHubmilo2012/cve-2018-13379

CVE-2018-13379

exploitationpenetration-testingvulnerability-analysis+1
2537 years ago
NachoVPN preview

NachoVPN

GitHubamberwolfcyber/nachovpn

A delicious, but malicious SSL-VPN server 🌮

adversarial-attackexploitationnetwork-security+5
2687 months ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubjas502n/cve-2019-19781

Python exploit for CVE-2019-19781 targeting Citrix ADC with template injection to achieve remote code execution on vulnerable gateways.

exploitationpenetration-testingred-teaming+3
856 years ago
Log4Pot preview

Log4Pot

GitHubthomaspatzke/log4pot

A honeypot for the Log4Shell vulnerability (CVE-2021-44228).

intrusion-detectionlog-analysispayload-generation+2
941 year ago
Testability-CVE-2014-1266 preview

Testability-CVE-2014-1266

GitHublandonf/testability-cve-2014-1266

Demonstrating that SSLVerifySignedServerKeyExchange() is trivially testable.

code-analysiscryptographyeducation+1
2612 years ago
-CVE-2025-0133-GlobalProtect-XSS preview

-CVE-2025-0133-GlobalProtect-XSS

GitHubynsmroztas/-cve-2025-0133-globalprotect-xss

CVE-2025-0133 GlobalProtect XSS

exploitationpenetration-testingvulnerability-analysis+2
201 year ago
isslfix preview

isslfix

GitHubjan0/isslfix

CVE-2011-0228 fix for older idevices/firmwares

encryption-decryption-toolsios-securitymobile-security+1
915 years ago
CVE-2020-28502 preview

CVE-2020-28502

GitHubs-index/cve-2020-28502

CVE-2020-28502 node-XMLHttpRequest RCE

educationexploitationpayload-development+3
35 years ago
NGINX_2026_CVE_Bundle_CTI_Report preview

NGINX_2026_CVE_Bundle_CTI_Report

GitHubchpratik/nginx_2026_cve_bundle_cti_report

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

cloud-securitycurated-resourceseducation+6
2 months ago
CVE-2020-14645 preview

CVE-2020-14645

GitHubdaboquan/cve-2020-14645

Java-based exploit for CVE-2020-14645 targeting Oracle WebLogic T3 protocol with JNDI injection for remote code execution.

exploitationpayload-generationpenetration-testing+2
36 years ago
CVE-2025-68721 preview

CVE-2025-68721

GitHubosmancanvural/cve-2025-68721

Axigen WebAdmin Improper Access Control Vulnerability

exploitationmisconfigurationpenetration-testing+2
17 months ago
List-CVE-2025-2026 preview

List-CVE-2025-2026

GitHubmagercode/list-cve-2025-2026

Daftar CVE 2025-2026 terupdate

curated-resourceseducationinformation-gathering+3
18 months ago
CVE-2002-0082 preview

CVE-2002-0082

GitHubratiros01/cve-2002-0082

CVE-2002-0082

binary-exploitationexploitationvulnerability-analysis+2
1 year ago
Previous12345Next