Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
CVE-2022-42475-POC preview

CVE-2022-42475-POC

GitHubarthurhendrich/cve-2022-42475-poc

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

exploitationpayload-developmentpenetration-testing+4
7 months ago
CVE-2026-42533 preview

CVE-2026-42533

GitHubjelasin/cve-2026-42533

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

binary-exploitationcode-analysisdebuggers+4
2 months ago
FUCK-CDN preview

FUCK-CDN

GitHub0xshe/fuck-cdn

Automated CDN origin-IP discovery skill for Claude Code that runs 40+ prioritized OSINT methods, cross-validates candidates via SSL and HTTP…

dns-analysisdns-subdomain-enumerationinformation-gathering+9
1012 months ago
FinalRecon preview

FinalRecon

GitHubthewhiteh4t/finalrecon

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

crawlerdns-analysisinformation-gathering+7
3.0k4 months ago
Damn-Vulnerable-Bank preview

Damn-Vulnerable-Bank

GitHubrewanthtammana/damn-vulnerable-bank

Intentionally vulnerable Android banking app for practicing mobile security testing, featuring root detection, anti-debugging, SSL pinning, and…

android-securityeducationlabs-practice+2
7582 years ago
CrushFTP-CVE-2024-4040-illdeed preview

CrushFTP-CVE-2024-4040-illdeed

GitHubill-deed/crushftp-cve-2024-4040-illdeed

Exploit for CVE-2024-4040 – Authentication bypass in CrushFTP via CrushAuth cookie and AWS-style header spoofing. Stealthy Python PoC with secure…

authenticationexploitationpayload-generation+3
1 year ago
cve-2019-11477-poc preview

cve-2019-11477-poc

GitHubsasqwatch/cve-2019-11477-poc

Proof-of-concept exploit for CVE-2019-11477, demonstrating a denial-of-service attack against Linux kernel TCP SACK panic via crafted netfilter…

exploitationnetwork-securitypenetration-testing+2
87 years ago
CVE-2020-8289 preview

CVE-2020-8289

GitHubgeffner/cve-2020-8289

Proof-of-concept exploit for CVE-2020-8289 demonstrating remote code execution as SYSTEM/root via Backblaze backup client's SSL verification bypass…

command-and-controlexploitationpayload-development+5
115 years ago
CVE-2026-35616-check preview

CVE-2026-35616-check

GitHubbishopfox/cve-2026-35616-check

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

api-security-testingauthenticationexploitation+3
25 months ago
cve-2024-21762-checker preview

cve-2024-21762-checker

GitHubrdoix/cve-2024-21762-checker

Shodan-based scanner that discovers FortiGate SSL VPN devices and tests them for CVE-2024-21762 vulnerability, displaying organization and country…

exploitationnetwork-securityosint+3
12 years ago
unwaf preview

unwaf

GitHubmmarting/unwaf

Go tool that passively discovers the real origin IP behind a WAF/CDN using multiple OSINT sources, then verifies candidates via HTML similarity, SSL…

dns-subdomain-enumerationinformation-gatheringnetwork-mapping+7
1877 months ago
PoC-CVE-2021-41773 preview

PoC-CVE-2021-41773

GitHubiilegacyyii/poc-cve-2021-41773

Proof-of-concept scanner for Apache HTTP Server path traversal (CVE-2021-41773) with multi-host support, SSL verification toggle, and concurrent…

exploitationinformation-gatheringpenetration-testing+3
524 years ago
SSLPinDetect preview

SSLPinDetect

GitHubaancw/sslpindetect

SSLPinDetect is a tool for analyzing Android APKs to detect SSL pinning implementations by scanning for known patterns in decompiled code. It helps…

android-securitycode-analysismobile-security+4
871 year ago
wordpress-cve-2024-10924-pentest preview

wordpress-cve-2024-10924-pentest

GitHubademto/wordpress-cve-2024-10924-pentest

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

authenticationeducationexploitation+5
31 year ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubvulnpire/cve-2024-24919

Exploit script for CVE-2024-24919 targeting Check Point SSL VPN, with Shodan and FOFA search queries for vulnerable devices.

exploitationpenetration-testingreconnaissance+2
2 years ago
CVE-2024-3400-Check preview

CVE-2024-3400-Check

GitHubsxyrxyy/cve-2024-3400-check

Python script to check for CVE-2024-3400 vulnerability in Palo Alto Networks PAN-OS SSL VPN by probing /ssl-vpn/hipreport.esp and verifying file…

exploitationpenetration-testingreconnaissance+2
2 years ago
CVE-2014-1266-poc preview

CVE-2014-1266-poc

GitHubgabrielg/cve-2014-1266-poc

Proof-of-concept exploit for Apple SSL/TLS verification vulnerability (CVE-2014-1266) in iOS and OS X, demonstrating HTTPS interception via a proxy…

exploitationios-securitymobile-security+3
7812 years ago
CVE-2018-13382 preview

CVE-2018-13382

GitHubmilo2012/cve-2018-13382

CVE-2018-13382

authenticationexploitationpenetration-testing+3
1467 years ago
Previous12345Next