Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
488 results
CVE-2026-35584 preview

CVE-2026-35584

GitHubspoo1k/cve-2026-35584

Proof-of-concept exploit for an unauthenticated IDOR vulnerability in FreeScout that allows thread enumeration and manipulation of read status via…

exploitationinformation-gatheringpenetration-testing+3
5 months ago
POC-of-CVE-2022-36271 preview

POC-of-CVE-2022-36271

GitHubsaumyajeetdas/poc-of-cve-2022-36271

This is working POC of CVE-2022-36271

binary-exploitationexploitationmalware-analysis+3
94 years ago
cve-2022-22947 preview

cve-2022-22947

GitHubtwseptian/cve-2022-22947

Spring Cloud Gateway Actuator API SpEL Code Injection (CVE-2022-22947)

command-and-controlexploitationpayload-generation+3
114 years ago
CVE-2021-21300 preview

CVE-2021-21300

GitHubfengzhouc/cve-2021-21300

Proof-of-concept exploit for CVE-2021-21300, demonstrating remote code execution via malicious git repository cloning with symlink and filter abuse…

command-and-controlexploitationlateral-movement+6
5 years ago
zencart_auth_rce_poc preview

zencart_auth_rce_poc

GitHubkaanaryoverflow/zencart_auth_rce_poc

Authenticated remote code execution exploit for Zen Cart via SQL injection in admin module editing. Proof-of-concept for CVE-2021-3291.

exploitationpenetration-testingvulnerability-analysis+1
75 years ago
OutOfTune preview

OutOfTune

GitHubstra-x/outoftune

Rogue device enrollment tool for Entra ID and Intune MDM. Automates device join, token acquisition, MDM enrollment, and OMA-DM checkin to extract…

authentication-authorizationcloud-securityconfiguration-auditing+9
345 months ago
3007Project preview

3007Project

GitHubtimon-l/3007project

Secure coding project, research on CVE-2019-17498 and implement a player score function written in C.

binary-analysiscode-analysiseducation+2
3 years ago
CVE-2026-56423-MISP-deleteSelection-BrokenAccessControl preview

CVE-2026-56423-MISP-deleteSelection-BrokenAccessControl

GitHubbiitts/cve-2026-56423-misp-deleteselection-brokenaccesscontrol

PoC for CVE-2026-56423: MISP deleteSelection broken access control (CWE-862, contributor hard-deletes other orgs' Event Reports/Sharing Groups, CVSS…

exploitationmisconfigurationpenetration-testing+3
2 months ago
CVE-2019-13361 preview

CVE-2019-13361

GitHublodi-g/cve-2019-13361

Smanos W100 1.0.0 devices have Insecure Permissions, exploitable by an attacker on the same Wi-Fi network.

exploitationiot-securitypenetration-testing+2
7 years ago
CloudSec preview

CloudSec

GitHubeshlomo1/cloudsec

Master the art of cloud exploitation. A specialized resource for offensive security researchers and red teamers focused on weaponizing…

anti-botcloud-securitycontainer-escape+8
3016 days ago
bucky preview

bucky

GitHubumair9747/bucky

An S3 account ID enumeration and bucket discovery tool

cloud-securityinformation-gatheringosint+3
206 months ago
Azure preview

Azure

GitHuboffsecpierogi/azure

Bash and PowerShell scripts for Azure security assessments, covering IAM privilege escalation, container registry exploitation, Key Vault exposure,…

cloud-infrastructure-securitycloud-securityconfiguration-auditing+8
11 month ago
CVE-2020-11800 preview

CVE-2020-11800

GitHubycseo-git/cve-2020-11800

PoC exploit for CVE-2020-11800, a command injection in Zabbix Server via malicious agent auto-registration, with Python-based payload delivery and…

command-and-controlexploitationpayload-development+3
4 months ago
CVE-2022-28346 preview

CVE-2022-28346

GitHubyougina/cve-2022-28346

SQL injection in QuerySet.annotate(), aggregate(), and extra()

educationlabs-practicepenetration-testing+2
24 years ago
CVE-2021-30862 preview

CVE-2021-30862

GitHub3h6-1/cve-2021-30862

Write-up and proof of concepts for CVE-2021-30862, 1-click RCE bug in iOS iTunes U

exploitationios-securitymobile-security+3
11 year ago
rails-cve-2017-17917 preview

rails-cve-2017-17917

GitHubmatiasarenhard/rails-cve-2017-17917

Educational demonstration of CVE-2017-17917 SQL injection in Rails, with step-by-step replication and secure coding mitigation using parameterized…

code-analysisdatabase-securityeducation+3
12 years ago
SCTT-2026-33-0002-DWM-Visual-Field-Singularity preview

SCTT-2026-33-0002-DWM-Visual-Field-Singularity

GitHubsimoesctt/sctt-2026-33-0002-dwm-visual-field-singularity

Exploit research targeting Windows DWM to achieve local privilege escalation via a theoretical Visual-Field Singularity, bypassing graphics isolation…

binary-exploitationexploitationexploit-frameworks+3
7 months ago
CVE-2024-29895.py preview

CVE-2024-29895.py

GitHubticofookfook/cve-2024-29895.py

Python exploit for Cacti RCE (CVE-2024-29895) via command injection in cmd_realtime.php. Includes reconnaissance dorks for Google, Shodan, and FOFA.

command-and-controlexploitationreconnaissance+2
2 years ago
Previous12…28Next