Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2069 results
cve-2026-48282-pentest-lab preview

cve-2026-48282-pentest-lab

GitHubarpit-bansal15/cve-2026-48282-pentest-lab

Hands-on penetration testing lab environment for CVE-2026-48282, designed for practicing exploitation and vulnerability analysis in a controlled web…

educationexploitationpenetration-testing+2
2 months ago
VulnerableGWTApp preview

VulnerableGWTApp

GitHubbishopfox/vulnerablegwtapp

An intentionally-vulnerable GWT-based web application to test tooling and techniques

educationexploitationlabs-practice+4
52 years ago
loader-CVE-2020-14343 preview

loader-CVE-2020-14343

GitHubj4k0m/loader-cve-2020-14343

A web application vulnerable to CVE-2020-14343 insecure deserialization leading to command execution in PyYAML package.

ctfeducationexploitation+3
34 years ago
log4shell-vulnerable-app preview

log4shell-vulnerable-app

GitHubprmawyer/log4shell-vulnerable-app

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

educationexploitationlabs-practice+3
1 month ago
CVE-2025-45778 preview

CVE-2025-45778

GitHubsmarttfoxx/cve-2025-45778

A stored cross-site scripting (XSS) vulnerability in The Language Sloth Web Application v1.0 allows attackers to execute arbitrary javascript or HTML…

exploitationpenetration-testingvulnerability-analysis+2
21 year ago
CVE-2026-26718 preview

CVE-2026-26718

GitHubibrahim-sartawi/cve-2026-26718

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

exploitationids-ips-evasionpenetration-testing+3
12 months ago
WAFEC preview

WAFEC

GitHubowasp/wafec

Structured evaluation criteria framework for assessing Web Application Firewalls (WAFs), enabling users, vendors, and third parties to compare…

curated-resourceseducationlearning-paths-courses+3
12 years ago
CVE-2022-36067-vm2-POC-webapp preview

CVE-2022-36067-vm2-POC-webapp

GitHub0x1nsomnia/cve-2022-36067-vm2-poc-webapp

Proof-of-concept web application demonstrating CVE-2022-36067, a vm2 sandbox escape, enabling remote code execution by uploading exploit code to a…

exploitationpayload-developmentpenetration-testing+2
23 years ago
CVE-2024-5246 preview

CVE-2024-5246

GitHubabdurahmon3236/cve-2024-5246

Proof-of-concept Python script demonstrating authenticated remote code execution in NETGEAR ProSAFE Network Management System via vulnerable Apache…

educationexploitationpayload-development+3
22 years ago
CVE-2018-14667 preview

CVE-2018-14667

GitHubzeroto01/cve-2018-14667

Proof-of-concept exploit for CVE-2018-14667 with a Windows calc payload, demonstrating remote code execution in a web application context.

educationexploitationpayload-development+3
27 years ago
CVE-2021-38819 preview

CVE-2021-38819

GitHubm4sk0ff/cve-2021-38819

Proof-of-concept exploit for CVE-2021-38819, demonstrating a specific web application vulnerability with a targeted exploitation script.

exploitationvulnerability-analysisweb-application-exploitation
23 years ago
cve-2019-16097 preview

cve-2019-16097

GitHubdacade/cve-2019-16097

Automated exploit script for CVE-2019-16097, performing batch URL scanning to detect and exploit a web application vulnerability, writing successful…

exploitationpenetration-testingvulnerability-analysis+1
16 years ago
CVE-2008-7220 preview

CVE-2008-7220

GitHubfollowboy1999/cve-2008-7220

Proof-of-concept exploit for CVE-2008-7220, demonstrating a remote code execution vulnerability in a web application.

exploitationvulnerability-analysisweb-application-exploitation
19 years ago
CVE-2022-29464 preview

CVE-2022-29464

GitHub0xagun/cve-2022-29464

Proof-of-concept exploit for CVE-2022-29464, a web application vulnerability in WSO2 products allowing arbitrary file upload and remote code…

exploitationpenetration-testingvulnerability-analysis+1
14 years ago
Bili-cracker preview

Bili-cracker

GitHubusernameisunavailable-cell/bili-cracker

Exploit tool leveraging CVE-2026-350234 to obtain bilibili membership privileges, demonstrating web application vulnerability exploitation.

exploitationpenetration-testingvulnerability-analysis+2
14 months ago
MegaQuagga_Pentesting_Report preview

MegaQuagga_Pentesting_Report

GitHubaktia1/megaquagga_pentesting_report

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

educationexploitationpenetration-testing+5
4 months ago
CVE-2019-13574 preview

CVE-2019-13574

GitHubmasahiro331/cve-2019-13574

Proof-of-concept exploit for CVE-2019-13574, demonstrating a specific vulnerability in a web application for testing and verification purposes.

exploitationvulnerability-analysisweb-application-exploitation
17 years ago
CVE-2026-41242 preview

CVE-2026-41242

GitHub4chech/cve-2026-41242

Proof-of-concept exploit for CVE-2026-41242 in a Node.js web application, demonstrating the vulnerability and potential impact.

exploitationvulnerability-analysisweb-application-exploitation+1
4 months ago
Previous1…789…100Next