Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2022-0847-Dirty-Pipe- preview

CVE-2022-0847-Dirty-Pipe-

GitHubgaganhm3018-art/cve-2022-0847-dirty-pipe-

this is a repo who is facing a escalation issue in their linux system and a news regarding problem of "Dirty pipeline"

binary-exploitationeducationexploitation+2
3 months ago
CVE-2021-24884 preview

CVE-2021-24884

GitHubs1lkys/cve-2021-24884

If an authenticated user who is able to edit Wordpress PHP code in any kind, clicks a malicious link, PHP code can be edited through XSS in…

exploitationpayload-developmentphishing-tools+3
14 years ago
OTRS-4.0.1-6.0.1-Remote-Command-Execution preview

OTRS-4.0.1-6.0.1-Remote-Command-Execution

GitHubsmarttfoxx/otrs-4.0.1-6.0.1-remote-command-execution

CVE-2017-16921: In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an…

exploitationpenetration-testingremote-access-tool+2
1 year ago
CVE-2021-23017-POC preview

CVE-2021-23017-POC

GitHubz3usx01/cve-2021-23017-poc

The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is…

dns-analysisexploitationmemory-forensics+2
11 year ago
codeql-workshop preview

codeql-workshop

GitHubsylwia-budzynska/codeql-workshop

Take first steps in CodeQL for Python by writing a query to find CVE-2024-32022

code-analysiscurated-resourceseducation+4
131 month ago
CVE-2025-61229 preview

CVE-2025-61229

GitHubgraypixel2121/cve-2025-61229
educationexploitationpapers-research+2
8 months ago
CVE-2024-10605 preview

CVE-2024-10605

GitHubbevennyamande/cve-2024-10605
exploitationpenetration-testingvulnerability-analysis+2
1 year ago
L4J-Vuln-Patch preview
Archived

L4J-Vuln-Patch

GitHubjacobtread/l4j-vuln-patch

This tool patches the CVE-2021-44228 Log4J vulnerability present in all minecraft versions NOTE THIS TOOL MUST BE RE-RUN after downloading or…

exploitationmisconfigurationsupply-chain-security+2
54 years ago
ninja-forms-brute preview

ninja-forms-brute

GitHubrandomrobbiebf/ninja-forms-brute
information-gatheringvulnerability-analysisweb-application-exploitation
4 years ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubshadowbrokers-exploitleak/cve-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker…

exploitationpenetration-testingremote-access-tool+2
27 years ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubbarry-mccockiner/cve-2019-0708

A remote code execution vulnerability exists in Remote Desktop Services – formerly known as Terminal Services – when an unauthenticated attacker…

exploitationinformation-gatheringpenetration-testing+3
17 years ago
blueborne-CVE-2017-1000251 preview

blueborne-CVE-2017-1000251

GitHubsgxgsx/blueborne-cve-2017-1000251

Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC) BlueBorne - Proof of Concept - Unarmed/Unweaponized - DoS (Crash) only

binary-exploitationbluetooth-securityexploitation+1
62 years ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubmmakingdom/cve-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

educationexploitationpenetration-testing+2
19 months ago
OWASP-GoatDroid-Project preview
Archived

OWASP-GoatDroid-Project

GitHubnvisium-jack-mannino/owasp-goatdroid-project

*This project is no longer maintained* OWASP GoatDroid is a fully functional and self-contained training environment for educating developers and…

android-securityeducationlabs-practice+3
25612 years ago
ifuncd-up preview

ifuncd-up

GitHubrobertdfrench/ifuncd-up

GNU IFUNC is the real culprit behind CVE-2024-3094

binary-analysisdynamic-code-analysiseducation+5
603 months ago
CVE-2020-8559 preview

CVE-2020-8559

GitHubtdwyer/cve-2020-8559

This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability

cloud-securitycontainer-securityexploitation+5
546 years ago
CVE-2023-38545 preview

CVE-2023-38545

GitHubd0rb/cve-2023-38545

This script is designed to exploit a heap buffer overflow vulnerability in a socks5 proxy server.

exploitationpayload-developmentpenetration-testing+3
212 years ago
LogoFail-PoC preview

LogoFail-PoC

GitHubd0rb/logofail-poc

This is a hypothetical demonstration of the process involved in exploiting LogoFail, it theoretically includes the necessary steps.

binary-exploitationeducationexploitation+5
82 years ago
Previous12Next