Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
434 results
CVE-2025-7461 preview

CVE-2025-7461

GitHubbx33661/cve-2025-7461

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

educationpapers-researchvulnerability-analysis+1
4
1 year ago
ludus_crushftp_cve-2025-31161_sim preview

ludus_crushftp_cve-2025-31161_sim

GitHubrufflabs/ludus_crushftp_cve-2025-31161_sim

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

ctfeducationexploitation+5
2 months ago
exploitarium preview

exploitarium

GitHubbikini/exploitarium

Curated archive of public proof-of-concept exploits and vulnerability research writeups covering web, binary, and network security, with a focus on…

binary-exploitationctfcurated-resources+6
5.1k1 month ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubdungsocool/cve-2017-5638

Hands-on lab demonstrating Apache Struts2 OGNL injection (CVE-2017-5638) with step-by-step system analysis, exploitation, sandbox bypass, and…

educationexploitationlabs-practice+3
3 months ago
CVE-2026-3227-TP-Link-authenticated-RCE preview

CVE-2026-3227-TP-Link-authenticated-RCE

GitHubdo4choo/cve-2026-3227-tp-link-authenticated-rce

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

binary-exploitationeducationexploitation+6
432 months ago
pwn2own2018 preview

pwn2own2018

GitHubsaelo/pwn2own2018

A Pwn2Own exploit chain

binary-exploitationeducationexploitation+5
7607 years ago
CVE-2021-46398 preview
Archived

CVE-2021-46398

GitHublaliea/cve-2021-46398

A Proof of Concept for the CVE-2021-46398 flaw exploitation

educationexploitationlabs-practice+3
3 years ago
CVE-2021-32724-Target preview

CVE-2021-32724-Target

GitHubmaximeschlegel/cve-2021-32724-target

Deliberately vulnerable GitHub repository configured with CVE-2021-32724 for practicing exploitation of the Check Spelling Workflow in a controlled…

ctfeducationexploitation+2
4 years ago
spring4shell_victim preview

spring4shell_victim

GitHubfracturelabs/spring4shell_victim

Intentionally vulnerable Spring app to test CVE-2022-22965

educationexploitationlabs-practice+3
24 years ago
CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC preview

CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC

GitHubduc-nt/cve-2022-44268-imagemagick-arbitrary-file-read-poc

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

educationexploitationpayload-generation+3
2753 years ago
cve-2017-5638 preview

cve-2017-5638

GitHubjrrdev/cve-2017-5638

Docker-based vulnerable environment and Python exploit script demonstrating CVE-2017-5638 (Apache Struts2 RCE) for educational security testing.

educationexploitationpenetration-testing+2
149 years ago
CVE-2019-8641-reproduction preview

CVE-2019-8641-reproduction

GitHubchia33164/cve-2019-8641-reproduction

Reproduction code for CVE-2019-8641, designed for educational demonstration of the vulnerability exploitation process.

educationexploitationpenetration-testing+2
56 years ago
ICT287-CVE-2022-42889 preview

ICT287-CVE-2022-42889

GitHubkosmicowl045/ict287-cve-2022-42889

Setup and exploit recreation for CVE-2022-42889 Text4Shell.

educationexploitationlabs-practice+3
5 months ago
CVE-2025-6218_WinRAR preview

CVE-2025-6218_WinRAR

GitHubspeinador/cve-2025-6218_winrar

Educational lab demonstrating CVE-2025-6218 path traversal in WinRAR. Includes a malicious RAR file and step-by-step guide to observe file overwrite…

binary-exploitationeducationexploitation+3
161 year ago
CVE-2025-55182-LAB preview

CVE-2025-55182-LAB

GitHubamikanev/cve-2025-55182-lab

Hands-on lab environment for reproducing and analyzing CVE-2025-55182, providing a controlled setup for security testing and exploitation practice.

educationexploitationpenetration-testing+2
5 months ago
CVE-2017-3066 preview

CVE-2017-3066

GitHubcucadili/cve-2017-3066

Analysis and exploitation of CVE-2017-3066, a Java deserialization RCE in Adobe ColdFusion's BlazeDS library, with Suricata detection rules and…

educationexploitationids-ips-evasion+3
26 years ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubahmetramazank/cve-2024-4577

Demonstrates exploitation of CVE-2024-4577, a PHP CGI RCE on Windows, including attack steps, reverse shell deployment, and ransomware simulation…

educationexploitationforensics+5
1 year ago
CVE-2021-38297-Go-wasm-Replication preview

CVE-2021-38297-Go-wasm-Replication

GitHubparas98/cve-2021-38297-go-wasm-replication

Educational proof-of-concept replicating CVE-2021-38297, a Go WASM buffer overflow leading to stored XSS. Includes vulnerable app setup, exploit…

binary-exploitationctfeducation+6
2 years ago
Previous12…25Next