Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2215 results
cve-2021-42013-apache preview

cve-2021-42013-apache

GitHubdream434/cve-2021-42013-apache

On October 4, 2021, Apache HTTP Server Project released Security advisory on a Path traversal and File disclosure vulnerability in Apache HTTP Server…

educationexploitationpenetration-testing+2
1 year ago
CVE-2017-8464-exp-generator preview

CVE-2017-8464-exp-generator

GitHubdoudouhala/cve-2017-8464-exp-generator

this tool can generate a exp for cve-2017-8486, it is developed by python

exploitationpayload-generationpenetration-testing+2
89 years ago
CVE-2021-21983 preview

CVE-2021-21983

GitHubmurataydemir/cve-2021-21983

[CVE-2021-21983] VMware vRealize Operations (vROps) Manager API Arbitrary File Write Leads to Remote Code Execution (RCE)

educationexploitationpayload-development+2
34 years ago
CVE-2016-16113-POC preview

CVE-2016-16113-POC

GitHubd3vn0mi/cve-2016-16113-poc

cve-2016-16113

exploitationpassword-attackspayload-generation+4
17 months ago
CVE-2025-56218 preview

CVE-2025-56218

GitHubsaykino/cve-2025-56218

Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing…

curated-resourceseducationphishing+2
10 months ago
wwwgrep preview
Archived

wwwgrep

GitHubowasp/wwwgrep

OWASP Foundation Web Respository

code-analysisinformation-gatheringpenetration-testing+3
364 years ago
CVE-2021-27850_POC preview

CVE-2021-27850_POC

GitHubdorkerdevil/cve-2021-27850_poc

A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.

exploitationpayload-developmentpenetration-testing+2
35 years ago
CVE-2021-27850_POC preview

CVE-2021-27850_POC

GitHubkahla-sec/cve-2021-27850_poc

A Proof of concept for CVE-2021-27850 affecting Apache Tapestry and leading to unauthencticated remote code execution.

exploitationpayload-generationvulnerability-analysis+1
53 years ago
CVE-2025-27591 preview

CVE-2025-27591

GitHub0x00jeff/cve-2025-27591

self cleaning CVE-2025-27591 Poc that grants a root reverse shell instead of modifying passwd files

binary-exploitationexploitationpayload-development+5
152 months ago
CVE-2017-8809_MediaWiki_RFD preview

CVE-2017-8809_MediaWiki_RFD

GitHubmotikan2010/cve-2017-8809_mediawiki_rfd

CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki

educationexploitationpenetration-testing+2
56 years ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubsentinelblue/cve-2022-29072

** DISPUTED ** 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the…

exploitationincident-responselog-analysis+3
84 years ago
CVE-2018-9958--Exploit preview

CVE-2018-9958--Exploit

GitHubt3rabyt3-zz/cve-2018-9958--exploit

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is…

binary-exploitationexploitationpenetration-testing+2
18 years ago
CVE-2024-23334 preview

CVE-2024-23334

GitHub0xr00/cve-2024-23334

Exploit script for CVE-2024-23334, an aiohttp static file path traversal vulnerability, enabling directory traversal to read arbitrary files.

exploitationpenetration-testingred-teaming+2
11 year ago
CVE-2025-58180 preview

CVE-2025-58180

GitHubprabhatverma47/cve-2025-58180

In OctoPrint version <=1.11.2, an attacker with file upload access (e.g., valid API key or session) can craft a malicious filename that bypasses…

command-and-controlexploitationpayload-generation+3
11 months ago
winrar-cve-2023-38831-poc-gen preview

winrar-cve-2023-38831-poc-gen

GitHubs4m98/winrar-cve-2023-38831-poc-gen

WinRAR cve-2023-38831-poc-generator

educationexploitationpayload-generation+2
12 years ago
Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC preview

Injection-vulnerability-in-Paradox-Security-Systems-IPR512-CVE-2023-24709-PoC

GitHubdarknesschieftain/injection-vulnerability-in-paradox-security-systems-ipr512-cve-2023-24709-poc

In Paradox Security System IPR512 Web console login form page, attacker can input JavaScript string, such as "</script>" that will overwrite…

exploitationiot-securitypenetration-testing+3
3 years ago
evilarc preview

evilarc

GitHubptoomey3/evilarc

Create tar/zip archives that can exploit directory traversal vulnerabilities

exploitationpayload-generationpenetration-testing+4
1.1k5 years ago
acropalypse-reconstructor preview

acropalypse-reconstructor

GitHubiqbaalilmii/acropalypse-reconstructor

A lightweight CLI tool to detect and reconstruct cropped images vulnerable to Acropalypse (CVE-2023-21036 and CVE-2023-28303) written in Python.

data-recoverydigital-forensicsexploitation+2
2 months ago
Previous1…567…100Next