Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
124 results
Exploit-for-CVE-2024-46987 preview

Exploit-for-CVE-2024-46987

GitHubsparrowhawk1113/exploit-for-cve-2024-46987

Exploit for CVE-2024-46987

educationexploitationpenetration-testing+2
7 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubtiborscholtz/cve-2026-24061

Educational Docker lab demonstrating Telnet NEW-ENVIRON username injection (CVE-2026-24061) with a Python client and vulnerable server for isolated…

educationexploitationlabs-practice+2
7 months ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubdwisiswant0/cve-2020-9496

Proof-of-concept exploit for CVE-2020-9496 (Apache OFBiz) with nuclei template integration and step-by-step vulnerable environment setup for security…

educationexploitationpenetration-testing+2
36 years ago
exploit-CVE-2024-25723 preview

exploit-CVE-2024-25723

GitHubdavid-botelho-mariano/exploit-cve-2024-25723

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

educationexploitationpassword-attacks+3
42 years ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
CyberSec2026 preview

CyberSec2026

GitHubsanderschepers1993/cybersec2026

Educational lab environment for exploiting CVE-2022-22947 in Spring Cloud Gateway, with automated victim VM setup and attacker configuration scripts.

educationexploitationlabs-practice+3
4 months ago
confluence-rce-poc preview

confluence-rce-poc

GitHubwolf1892/confluence-rce-poc

Setting up POC for CVE-2021-26084

educationexploitationpenetration-testing+2
5 years ago
CVE-2026-42568 preview

CVE-2026-42568

GitHubex-cal1bur/cve-2026-42568

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

authenticationeducationexploitation+3
3 months ago
CVE-2020-25273 preview

CVE-2020-25273

GitHubjonathanrey87/cve-2020-25273

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

authenticationeducationexploitation+3
5 years ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubjenderal92/cve-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

authenticationeducationexploitation+3
3 months ago
CVE-2025-8088-Multi-Document preview

CVE-2025-8088-Multi-Document

GitHubpentestfunctions/cve-2025-8088-multi-document

Exploit systems using older WinRAR without knowing their username (unlike other projects)

binary-exploitationeducationexploitation+4
351 year ago
CVE-2024-1698-Exploit preview

CVE-2024-1698-Exploit

GitHubkamranhasan/cve-2024-1698-exploit

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

educationexploitationpassword-attacks+3
82 years ago
CVE-2026-999999 preview

CVE-2026-999999

GitHub24520597-blip/cve-2026-999999

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

educationexploitationpenetration-testing+3
3 months ago
SSH_Enum_CVE-2018-15473 preview

SSH_Enum_CVE-2018-15473

GitHubnestyf/ssh_enum_cve-2018-15473

SSH username enumeration exploit targeting OpenSSH 2.3 through 7.7 (CVE-2018-15473). Enumerates valid users individually or from a wordlist via a…

educationexploitationinformation-gathering+3
1 year ago
cve-2018-15473-poc preview

cve-2018-15473-poc

GitHubmoften/cve-2018-15473-poc

Check if a username is valid on the SSH server by attempting an authentication. The server response will indicate whether the username exists.

educationexploitationinformation-gathering+3
1 year ago
CVE-2026-66418-OpenClaw-Dashboard-v3.0.0-Stored-XSS-via-Failed-Login-Username-Field preview

CVE-2026-66418-OpenClaw-Dashboard-v3.0.0-Stored-XSS-via-Failed-Login-Username-Field

GitHubtheopaid/cve-2026-66418-openclaw-dashboard-v3.0.0-stored-xss-via-failed-login-username-field

Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)

educationvulnerability-analysisweb-application-exploitation+1
11 month ago
Previous1234567Next