Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2216 results
CVE-2009-0182 preview

CVE-2009-0182

GitHubnobodyatall648/cve-2009-0182

CVE-2009-0182 VUPlayer2.49_LocalBufferOverflow

binary-exploitationeducationexploitation+3
5 years ago
CVE-2018-6905 preview

CVE-2018-6905

GitHubdnr6419/cve-2018-6905

Step-by-step reproduction environment for CVE-2018-6905, a stored XSS vulnerability in TYPO3 install.php, with Docker setup and payload execution…

educationexploitationpenetration-testing+2
5 years ago
Safer_PoC_CVE-2022-22965 preview

Safer_PoC_CVE-2022-22965

GitHubcolincowie/safer_poc_cve-2022-22965

Python-based proof-of-concept for CVE-2022-22965 (Spring4Shell) that writes a marker file to the Tomcat webapps directory and validates exploitation…

exploitationpayload-generationpenetration-testing+2
444 years ago
CVE-2025-24071_PoCExtra preview

CVE-2025-24071_PoCExtra

GitHubctabango/cve-2025-24071_pocextra

Proof-of-concept exploit for CVE-2025-24071 that creates a .searchconnector-ms file to trigger SMB authentication when copied, enabling credential…

exploitationinformation-gatheringlateral-movement+3
21 year ago
CVE-2021-46076 preview

CVE-2021-46076

GitHubsanupl/cve-2021-46076

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

code-analysisexploitationpenetration-testing+2
13 months ago
Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Code-Execution preview

Vehicle-Service-Management-System-Multiple-File-upload-Leads-to-Code-Execution

GitHubsanupl/vehicle-service-management-system-multiple-file-upload-leads-to-code-execution

CVE-2021-46076 - Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker can upload a malicious php file in…

code-analysisexploitationpayload-generation+3
3 months ago
ThisSeemsWrong preview

ThisSeemsWrong

GitHubmichalbednarski/thisseemswrong

Writeup and exploit for CVE-2024-49746: Android's Parcel::continueWrite closing File Descriptors that are later used

android-securitybinary-exploitationexploit-frameworks+3
4710 months ago
CVE-2025-24054 preview

CVE-2025-24054

GitHubuntouchable17/cve-2025-24054

Windows File Explorer Zero Click NTLMv2-SSP Hash Disclosure

exploitationpassword-crackingpayload-generation+4
29 months ago
CVE-2025-47810 preview

CVE-2025-47810

GitHubptrstr/cve-2025-47810

PunkBuster LPI to NT AUTHORITY\SYSTEM

binary-analysisexploitationlateral-movement+2
11 months ago
CVE-2020-24913-exploit preview

CVE-2020-24913-exploit

GitHubshpaw415/cve-2020-24913-exploit

automated SQL injection for QCubed profile.php file

penetration-testingvulnerability-analysisweb-application-exploitation
1 year ago
CVE-2021-22205 preview

CVE-2021-22205

GitHubcc3305/cve-2021-22205

Pre-authentication remote code execution exploit targeting GitLab CE/EE via ExifTool DjVu parsing. Uploads a crafted image to trigger RCE on…

exploitationpenetration-testingred-teaming+2
2 years ago
CVE-2024-29272 preview

CVE-2024-29272

GitHubawjkjflkwlekfdjs/cve-2024-29272

Proof-of-concept exploit for CVE-2024-29272, an unauthenticated arbitrary file upload vulnerability in VvvebJS < 1.7.5, enabling remote code…

exploitationpayload-developmentpenetration-testing+2
2 years ago
CVE-2023-24055_PoC preview

CVE-2023-24055_PoC

GitHubalt3kx/cve-2023-24055_poc

CVE-2023-24055 PoC (KeePass 2.5x)

data-exfiltrationexploitationpassword-attacks+3
2533 years ago
CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload preview

CVE-2025-64095---DNN-Unauthenticated-arbitrary-file-upload

GitHubh4x0r-dz/cve-2025-64095---dnn-unauthenticated-arbitrary-file-upload

POC of DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite

educationexploitationpenetration-testing+2
1410 months ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubozcanpng/cve-2024-9264

CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

command-and-controleducationexploitation+3
1 month ago
CVE-2025-66676 preview

CVE-2025-66676

GitHubcwjchoi01/cve-2025-66676

Proof-of-concept exploit for CVE-2025-66676 demonstrating arbitrary process termination via IOBit Unlocker kernel driver, with checksum bypass…

binary-exploitationeducationexploitation+2
36 months ago
CVE-2023-50164-HTB-strutted preview

CVE-2023-50164-HTB-strutted

GitHubmkirahmet/cve-2023-50164-htb-strutted

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use…

ctfeducationexploitation+3
11 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubwearehackers160/cve-2026-48907

CVE-2026-48907 is a critical improper access control vulnerability in the JCE editor extension for Joomla. It allows unauthenticated attackers to…

exploitationpayload-generationpenetration-testing+3
2 months ago
Previous1…8910…100Next