Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2216 results
CVE-2026-37072 preview

CVE-2026-37072

GitHubjfs-jfs/cve-2026-37072

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php

authentication-authorizationexploitationmisconfiguration+3
2 months ago
CVE-2025-32434 preview

CVE-2025-32434

GitHubalexandergumeniuk/cve-2025-32434

Proof-of-concept exploit for CVE-2025-32434, a critical RCE in PyTorch's torch.load() that bypasses weights_only=True via memory-mapped file writing.

binary-exploitationexploitationpayload-generation+3
12 months ago
CVE-2018-14847 preview

CVE-2018-14847

GitHubtausifzaman/cve-2018-14847

This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The…

exploitationinformation-gatheringnetwork-security+3
11 year ago
btrfs_fixes preview

btrfs_fixes

GitHubmsedek/btrfs_fixes

Custom BTRFS repair tools for severe extent tree corruption where btrfs check --repair fails (segfault, loop, or deadlock)

data-recoveryeducationforensics+2
94 months ago
cve-2025-0364 preview

cve-2025-0364

GitHubvulncheck-oss/cve-2025-0364

CVE-2025-0364: BigAnt Server RCE Exploit

authenticationexploitationpenetration-testing+3
71 year ago
motioneye-authenticated-RCE preview

motioneye-authenticated-RCE

GitHubpizza-power/motioneye-authenticated-rce

A Python 3 script that uploads a tasks.pickle file that enables RCE in MotionEye. CVE-2021-44255

command-and-controlexploitationpenetration-testing+3
13 years ago
spydir preview

spydir

GitHubz3apa3a/spydir

Spydir is a small utility to monitor file changes in Windows directory regardless of subdirectory and files permissions (exploits CVE-2007-0843)

exploitationgeneral-purpose-utilitiesprivilege-escalation+1
99 years ago
CVE-2023-33253 preview

CVE-2023-33253

GitHubtoxich4/cve-2023-33253

Proof-of-concept exploit for CVE-2023-33253, enabling authenticated remote code execution in LabCollector 6.0-6.15 via malicious PHP file upload.

exploitationpenetration-testingremote-access-tool+2
43 years ago
XWFAcropalypse preview

XWFAcropalypse

GitHubpolitoinc/xwfacropalypse

X-Ways Acropalypse extension detects CVE-2023-21036 in common images

data-recoverydigital-forensicsexploitation+2
4 months ago
CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability preview

CVE-2024-21413-Microsoft-Outlook-Remote-Code-Execution-Vulnerability

GitHubdhananjayasj/cve-2024-21413-microsoft-outlook-remote-code-execution-vulnerability

Proof-of-concept exploit for CVE-2024-21413, a critical Outlook RCE vulnerability that leaks NetNTLMv2 hashes via crafted file:// links, enabling…

exploitationlateral-movementpassword-cracking+3
3 months ago
local-mcp preview

local-mcp

GitHubfan-67/local-mcp

A lightweight stdio-based MCP server for local file system operations — read, write, edit, search, exec for AI assistants. Specially optimized for…

exploitationgeneral-purpose-utilitiesscripting-automation+2
2 months ago
log4j-fix-CVE-2021-44228 preview

log4j-fix-CVE-2021-44228

GitHubchandru-gunasekaran/log4j-fix-cve-2021-44228

Windows Batch Scrip to Fix the log4j-issue-CVE-2021-44228

general-purpose-utilitiesmisconfigurationscripting-automation+2
24 years ago
apache__flink_CVE-2020-17519_1-11-2 preview

apache__flink_CVE-2020-17519_1-11-2

GitHubshoucheng3/apache__flink_cve-2020-17519_1-11-2

Exploit for Apache Flink CVE-2020-17519 targeting directory traversal vulnerability in versions 1.11.2 and earlier, enabling unauthorized file read…

exploitationgeneral-purpose-utilitiesvulnerability-analysis+1
1 year ago
Tarmageddon-CVE-2025-62518- preview

Tarmageddon-CVE-2025-62518-

GitHubairineiandrei/tarmageddon-cve-2025-62518-

PoC for CVE-2025-62518 demonstrating tar archive smuggling via tokio-tar PAX header parsing, creating malicious payloads and a vulnerable extractor…

educationexploitationmalware-analysis+3
7 months ago
file-away-exploit preview

file-away-exploit

GitHubwhattheslime/file-away-exploit

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)

exploitationinformation-gatheringpayload-development+5
1 year ago
CVE-2018-6574 preview

CVE-2018-6574

GitHubs-p4rk/cve-2018-6574

Go-based exploit for CVE-2018-6574 using a shared library (attack.so) to demonstrate remote code execution vulnerability.

binary-exploitationexploitationpayload-development+2
1 month ago
web-server-audit_CVE-2026-42945 preview

web-server-audit_CVE-2026-42945

GitHubsibersan/web-server-audit_cve-2026-42945

Trigger-aware web server CVE audit for nginx and Apache. Goes beyond version matching by checking whether the vulnerable code path is actually…

configuration-auditingdevsecopsmisconfiguration+3
3 months ago
FHEM-6.0-Local-File-Inclusion-LFI-Vulnerability preview

FHEM-6.0-Local-File-Inclusion-LFI-Vulnerability

GitHubemreovunc/fhem-6.0-local-file-inclusion-lfi-vulnerability

Local File Inclusion (LFI) in FHEM 6.0 allows an attacker to include a file, it can lead to sensitive information disclosure.

exploitationinformation-gatheringpenetration-testing+2
125 years ago
Previous1…678…100Next