Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3742 results
WebGoat preview

WebGoat

GitHubwebgoat/webgoat

Deliberately vulnerable web application with interactive lessons and challenges for learning web application security and penetration testing…

ctfeducationlabs-practice+4
9.4k12 days ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubklezvirus/cve-2021-40444

CVE-2021-40444 - Fully Weaponized Microsoft Office Word RCE Exploit

command-and-controleducationexploitation+4
8362 years ago
CVE-2025-7461 preview

CVE-2025-7461

GitHubbx33661/cve-2025-7461

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

educationpapers-researchvulnerability-analysis+1
41 year ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

ctfcurated-resourceseducation+8
81.5k1 month ago
SocialFish preview

SocialFish

GitHubundeadsec/socialfish

Modern dynamic phishing toolkit for authorized red team exercises. Clones login pages, captures credentials, cookies, and 2FA codes with a live…

command-and-controleducationids-ips-evasion+9
4.9k4 months ago
pentest-copilot preview

pentest-copilot

GitHubbugbasesecurity/pentest-copilot

AI-driven penetration testing agent that connects to a Kali box, autonomously runs security tools, analyzes results, and iterates through…

ai-securitycommand-and-controlctf+8
1.5k1 month ago
WinRAR-Exploit-Tool---Rust-Edition preview

WinRAR-Exploit-Tool---Rust-Edition

GitHubkitsuneshade/winrar-exploit-tool---rust-edition

A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance.

binary-exploitationeducationexploitation+6
81 year ago
CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal preview

CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal

GitHubrabakuku/cve-2026-87902-a-working-poc-for-wordpress-s-critical-path-traversal

Reference notes and mitigation configs for CVE-2026-87902, a WordPress Core unauthenticated path traversal and LFI flaw chainable to RCE, with Nginx,…

defensive-toolseducationpapers-research+3
13 days ago
CVE-2025-49113-Roundcube_1.6.10 preview

CVE-2025-49113-Roundcube_1.6.10

GitHubcyberquestor-infosec/cve-2025-49113-roundcube_1.6.10

Authenticated remote code execution exploit for Roundcube 1.6.10 (CVE-2025-49113). Delivers a reverse shell via a crafted PHP payload through the…

educationexploitationpenetration-testing+3
1 year ago
cve-2026-27483-lab preview

cve-2026-27483-lab

GitHubnabhan-mohy/cve-2026-27483-lab

A containerized enterprise-style lab for researching and defending against CVE-2026-27483.

educationexploitationincident-response+5
11 month ago
CVE-2026-9833 preview

CVE-2026-9833

GitHubaj2108/cve-2026-9833

Technical analysis of a reflected XSS vulnerability in the Tag Groups WordPress plugin before 2.2.0, covering root cause, attack flow, impact,…

educationvulnerability-analysisweb-application-exploitation+1
2 months ago
Firefox-CVE-2024-9680 preview

Firefox-CVE-2024-9680

GitHubtdonaworth/firefox-cve-2024-9680

Educational analysis of CVE-2024-9680, a use-after-free vulnerability in Firefox's CSS Animation Timeline, with detailed exploit mechanics and…

binary-exploitationeducationexploitation+3
111 year ago
ludus_crushftp_cve-2025-31161_sim preview

ludus_crushftp_cve-2025-31161_sim

GitHubrufflabs/ludus_crushftp_cve-2025-31161_sim

Ansible role that simulates a realistic CrushFTP CVE-2025-31161 exploitation scenario with rotating sensitive data files and automated defender…

ctfeducationexploitation+5
3 months ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources and tools

cloud-securityctfcurated-resources+10
27.4k2 months ago
CVE-2021-24145 preview

CVE-2021-24145

GitHubdnr6419/cve-2021-24145

WordPress File Upload Vulnerability, Modern Events Calendar Lite WordPress plugin before 5.16.5

educationexploitationpayload-generation+3
34 years ago
CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description preview

CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description

GitHubsromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description

Quick CMS 6.7 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

educationexploitationpenetration-testing+3
3 years ago
Common-Vulnerability-and-Exploit preview

Common-Vulnerability-and-Exploit

GitHubdonaldashdown/common-vulnerability-and-exploit

This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.

educationexploitationpenetration-testing+2
8 years ago
cve-2017-5638 preview

cve-2017-5638

GitHubjrrdev/cve-2017-5638

Docker-based vulnerable environment and Python exploit script demonstrating CVE-2017-5638 (Apache Struts2 RCE) for educational security testing.

educationexploitationpenetration-testing+2
149 years ago
Previous12…100Next