Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
216 results
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

command-and-controlexploitationinformation-gathering+8
1
1 month ago
WP-Bricks-Exploit-CVE-2024-25600 preview

WP-Bricks-Exploit-CVE-2024-25600

GitHubcerberusmrxi/wp-bricks-exploit-cve-2024-25600

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

command-and-controlexploitationinformation-gathering+7
11 month ago
CVE-2025-68493 preview

CVE-2025-68493

GitHubhsltz/cve-2025-68493

Python PoC script and Nuclei YAML template for detecting and exploiting CVE-2025-68493, an XXE vulnerability in Apache Struts, enabling file read and…

exploitationpenetration-testingvulnerability-analysis+3
26 months ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
4 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubkindone09/cve-2025-55182

Automated Python PoC scanner for CVE-2025-55182 targeting Next.js 16.0.6. Reads URLs from file, sends exploit requests, and displays responses for…

exploitationpenetration-testingvulnerability-scanners+1
28 months ago
f5scan preview

f5scan

GitHubhalencarjunior/f5scan

CVE-2020-5902 scanner for F5 BIG-IP with Shodan host discovery, LFI file reading, and remote command execution capabilities.

exploitationinformation-gatheringreconnaissance+2
16 years ago
Aj-Report-sql-CVE-2024-5356-POC preview

Aj-Report-sql-CVE-2024-5356-POC

GitHubdroyuu/aj-report-sql-cve-2024-5356-poc

Proof-of-concept exploit for CVE-2024-5356 SQL injection vulnerability in Aj-Report. Supports single URL and batch file scanning with configurable…

exploitationpenetration-testingvulnerability-scanners+1
11 year ago
CVE-2024-28995-Nuclei-Template preview

CVE-2024-28995-Nuclei-Template

GitHubhuseyinstif/cve-2024-28995-nuclei-template

Nuclei template for detecting CVE-2024-28995, a directory traversal vulnerability in Serv-U FTP server, enabling file read via crafted HTTP requests.

exploitationpenetration-testingvulnerability-analysis+3
12 years ago
CVE-2024-31351_wordpress_exploit preview

CVE-2024-31351_wordpress_exploit

GitHubktn1990/cve-2024-31351_wordpress_exploit

Wordpress - Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
2 years ago
W3TotalChache preview

W3TotalChache

GitHubspyata123/w3totalchache

Testing for CVE-2019-6715 (Arbitrary File Read)/ CVE-2024-12365 (SSRF/Info Disclosure)

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubim-hanzou/cve-2026-3844

Breeze Cache WordPress <=2.4.4 allows unauthenticated file upload via fetch_gravatar_from_remote when local gravatar hosting is enabled.

exploitationpenetration-testingred-teaming+2
4 months ago
CVE-2026-3844 preview

CVE-2026-3844

GitHub0xgh057r3c0n/cve-2026-3844

WordPress - Breeze Cache <= 2.4.4 - Unauthenticated Arbitrary File Upload

exploitationpenetration-testingvulnerability-scanners+2
14 months ago
CVE-2021-43798-mass_scanner preview

CVE-2021-43798-mass_scanner

GitHubrodpwn/cve-2021-43798-mass_scanner

Mass scanner for Grafana CVE-2021-43798 unauthorized file read, supporting single targets, hostname lists, and IP ranges with PoC verification.

exploitationinformation-gatheringreconnaissance+2
54 years ago
-CVE-2026-1657 preview

-CVE-2026-1657

GitHubvimashdilshara/-cve-2026-1657

Exploit for CVE-2026-1657, an unauthenticated image upload vulnerability via the 'ep_upload_file_media' AJAX endpoint, allowing remote file upload.

exploitationpenetration-testingvulnerability-scanners+2
5 months ago
FreePBX-Vulns-December-25 preview

FreePBX-Vulns-December-25

GitHubrxerium/freepbx-vulns-december-25

Detection for CVE-2025-61675, CVE-2025-61678 & CVE-2025-66039

exploitationpenetration-testingvulnerability-analysis+3
488 months ago
CVE-2020-1938TomcatAjpScanner preview

CVE-2020-1938TomcatAjpScanner

GitHubwoaiqiukui/cve-2020-1938tomcatajpscanner

批量扫描TomcatAJP漏洞

exploitationinformation-gatheringpenetration-testing+3
146 years ago
CVE-2022-22954 preview

CVE-2022-22954

GitHubmlx15/cve-2022-22954

CVE-2022-22954 VMware Workspace ONE Access free marker SSTI

command-and-controlexploitationpayload-generation+3
44 years ago
CVE-2024-3400 preview

CVE-2024-3400

GitHubschooldropout1337/cve-2024-3400

Nuclei template and bash script for detecting and exploiting CVE-2024-3400 command injection in Palo Alto PAN-OS GlobalProtect, enabling…

command-and-controlexploitationpayload-generation+3
52 years ago
Previous1…9101112Next