Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
281 results
CVE-2025-44137 preview

CVE-2025-44137

GitHubmheranco/cve-2025-44137

Proof-of-concept exploit for CVE-2025-44137: unauthenticated directory traversal in MapTiler Tileserver-php v2.0, enabling arbitrary file read via…

exploitationinformation-gatheringpenetration-testing+2
4 months ago
CVE-2025-44136 preview

CVE-2025-44136

GitHubmheranco/cve-2025-44136

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
CVE-2026-37070 preview

CVE-2026-37070

GitHubjfs-jfs/cve-2026-37070

Proof-of-concept exploit for CVE-2026-37070: an authenticated attacker can read arbitrary uploaded files in Veno File Manager 4.4.9 via a crafted GET…

exploitationinformation-gatheringpenetration-testing+2
3 months ago
CVE-2025-60574 preview

CVE-2025-60574

GitHubjacopoaugelli/cve-2025-60574

Proof-of-concept exploit for CVE-2025-60574, a Local File Inclusion vulnerability in tQuadra CMS 4.2.1117, enabling arbitrary file retrieval via…

exploitationinformation-gatheringpenetration-testing+2
10 months ago
CVE-2022-45600 preview

CVE-2022-45600

GitHubethancunt/cve-2022-45600

Proof-of-concept exploit for command injection vulnerability in Aztech WMB250AC routers, enabling authenticated privilege escalation to root shell…

command-and-controlembedded-systems-securityexploitation+5
3 years ago
CVE-2024-57784 preview

CVE-2024-57784

GitHubs4fv4n/cve-2024-57784

Exploit for CVE-2024-57784: authenticated directory traversal in Zenitel AlphaWeb XE 11.2.3.10. Enables remote file reading via HTTP GET requests…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2018-6574-POC preview

CVE-2018-6574-POC

GitHub20matan/cve-2018-6574-poc

Proof-of-concept exploit for CVE-2018-6574, demonstrating arbitrary command execution via crafted import paths in Go's go get command.

code-analysisexploitationpenetration-testing+2
7 years ago
ThreatPursuit-VM preview
Archived

ThreatPursuit-VM

GitHubmandiant/threatpursuit-vm

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

curated-resourcesdigital-forensicseducation+8
1.3k3 years ago
ProxyLogon preview

ProxyLogon

GitHubrickgeex/proxylogon

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

authenticationeducationexploitation+3
335 years ago
CVE-2025-4476-Exploit preview

CVE-2025-4476-Exploit

GitHubsoltanali0/cve-2025-4476-exploit

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

educationexploitationvulnerability-analysis+1
11 months ago
harpoon preview

harpoon

GitHubte-k/harpoon

CLI tool for open source and threat intelligence

dns-analysisemail-harvestinginformation-gathering+5
1.3k4 months ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubzcgonvh/cve-2020-0688

Exploit and detect tools for CVE-2020-0688

exploitationinformation-gatheringpenetration-testing+2
3536 years ago
raink preview

raink

GitHubbishopfox/raink

Use LLMs for document ranking

ai-securitymachine-learningvulnerability-analysis
1771 year ago
Log4jTools preview

Log4jTools

GitHubmalwaretech/log4jtools

Tools for investigating Log4j CVE-2021-44228

exploitationinformation-gatheringintrusion-detection+2
944 years ago
Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit preview

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

GitHub34zy/microsoft-office-word-mshtml-remote-code-execution-exploit

Exploits CVE-2021-40444 in Microsoft Office Word to achieve remote code execution through the MSHTML engine by injecting malicious content into a…

exploitationexploit-frameworkspayload-development+4
654 years ago
Adversarial-Detection-Engineering-Framework preview

Adversarial-Detection-Engineering-Framework

GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

curated-resourcesdefensive-toolseducation+7
616 months ago
Ticketbleed preview

Ticketbleed

GitHubegebalci/ticketbleed

This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.

exploitationinformation-gatheringmemory-forensics+2
309 years ago
CVE-2017-8295 preview

CVE-2017-8295

GitHubcyberheartmi9/cve-2017-8295

Proof-of-concept exploit for CVE-2017-8295, a WordPress password reset vulnerability allowing attackers to obtain reset links without authentication,…

exploitationpassword-attackspenetration-testing+3
206 years ago
Previous1…567…16Next