Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
RevCAT preview

RevCAT

GitHubnickguitar/revcat

OpenCATS <= 0.9.4 RCE (CVE-2021-41560)

exploitationpenetration-testingred-teaming+2
114 years ago
cve-2019-5736-poc preview

cve-2019-5736-poc

GitHubagppp/cve-2019-5736-poc

Proof-of-concept exploit for CVE-2019-5736, a Docker container escape vulnerability, demonstrating how to overwrite the host runc binary to gain…

container-escapecontainer-securityexploitation+2
77 years ago
CVE-2026-22012-Diameter-Protocol-Credit-Control-Bypass-in-5G preview

CVE-2026-22012-Diameter-Protocol-Credit-Control-Bypass-in-5G

GitHubgeorge0papasotiriou/cve-2026-22012-diameter-protocol-credit-control-bypass-in-5g

Python simulation of CVE-2026-22012, showing how a missing Final-Unit-Indication in Diameter Credit-Control allows unlimited quota and service bypass…

exploitationmobile-securitynetwork-security+1
21 days ago
Wordpress-CVE-2020-35749 preview

Wordpress-CVE-2020-35749

GitHubm4xsec/wordpress-cve-2020-35749

Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit

exploitationinformation-gatheringpenetration-testing+2
64 years ago
CVE-2016-2098-my-first-exploit preview

CVE-2016-2098-my-first-exploit

GitHubdanielhemmati/cve-2016-2098-my-first-exploit

This exploit is remote code execution vulnerability in Ruby-on-Rails when using render on user-supplied data

code-analysisexploitationpenetration-testing+2
26 years ago
CVE-2013-3664_MAC preview

CVE-2013-3664_MAC

GitHubdefrancescojp/cve-2013-3664_mac

Sketchup MAC Pict Material Palette Stack Corruption

binary-exploitationexploitationfuzzing+2
6 years ago
CVE-2022-0739 preview

CVE-2022-0739

GitHubelganz0/cve-2022-0739

BookingPress < 1.0.11 - Unauthenticated SQL Injection

exploitationinformation-gatheringpenetration-testing+2
3 years ago
Bad secure rails app preview

Bad secure rails app

GitLabvivian.maes/bad-secure-rails-app
code-analysiseducationmisconfiguration+3
1 month ago
railsgoat preview

railsgoat

GitHubowasp/railsgoat

A vulnerable version of Rails that follows the OWASP Top 10

code-analysisctfeducation+5
9226 months ago
claude_opus_cve_2023_0266 preview

claude_opus_cve_2023_0266

GitHubseanheelan/claude_opus_cve_2023_0266

Demonstrates that Claude Opus fails to identify CVE-2023-0266, hallucinating lock acquisitions and producing false positives, with reproducible demos…

ai-securitycode-analysiseducation+3
162 years ago
CVE-2019-5418 preview

CVE-2019-5418

GitHubomarkurt/cve-2019-5418

Ruby on Rails test case demonstrating CVE-2019-5418 file content disclosure via path traversal in Accept header, with PoC and reproduction steps.

educationexploitationpenetration-testing+2
57 years ago
rails-cve-2012-5664-test preview

rails-cve-2012-5664-test

GitHubphusion/rails-cve-2012-5664-test

Demo app showing how the Rails CVE-2013-5664 vulnerability works.

code-analysisdatabase-securityeducation+2
213 years ago
CVE-2023-37190 preview

CVE-2023-37190

GitHubsahiloj/cve-2023-37190

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

educationexploitationpapers-research+3
16 months ago
cve-2020-8165-demo preview

cve-2020-8165-demo

GitHubdanielklim/cve-2020-8165-demo

Demonstration of CVE-2020-8165 Rails deserialization RCE exploit with realistic Shouter app, payload generation in Ruby, and Redis cache poisoning.

educationexploitationpayload-development+3
15 years ago
rails-cve-2017-17917 preview

rails-cve-2017-17917

GitHubmatiasarenhard/rails-cve-2017-17917

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

code-analysisdatabase-securityeducation+3
12 years ago
CVE-2007-4559 preview

CVE-2007-4559

GitHubdavidholiday/cve-2007-4559

Educational demonstration of CVE-2007-4559 Python tarfile symlink attack with a script showing why os.path.realpath() fails to prevent extraction…

code-analysiseducationexploitation+3
2 years ago
CVE-2019-5418 preview

CVE-2019-5418

GitHubmelardev/cve-2019-5418

Docker-based sandbox to reproduce and test CVE-2019-5418 Ruby on Rails path traversal vulnerability via crafted Accept headers.

educationexploitationpenetration-testing+2
7 years ago
name_reverser preview

name_reverser

GitHubterracatta/name_reverser

Silly Rails App to demonstrate vuln CVE-2013-0156

educationexploitationpenetration-testing+2
13 years ago
Previous1234567Next