Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
1
1 month ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubmalwareman007/cve-2022-36537

POC of CVE-2022-36537

authentication-authorizationexploitationinformation-gathering+3
361 year ago
CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read preview

CVE-2026-21015-PHP-Filter-Chain-Arbitrary-File-Read

GitHubgeorge0papasotiriou/cve-2026-21015-php-filter-chain-arbitrary-file-read

PoC exploit for CVE-2026-21015 that abuses PHP filter chains to read arbitrary files through a vulnerable include() call, disclosing source and…

data-exfiltrationexploitationinformation-gathering+4
1 month ago
CVE-2022-36537-EXPLOIT preview

CVE-2022-36537-EXPLOIT

GitHubagnihackers/cve-2022-36537-exploit

CVE-2022-36537

authentication-authorizationexploitationinformation-gathering+3
93 years ago
CVE-2026-89012 preview

CVE-2026-89012

GitHubfaceless0x7/cve-2026-89012

Python exploit for CVE-2026-89012, a Dolibarr SQL filter denylist bypass that uses a blind-boolean oracle to extract password hashes and API keys via…

api-securitydata-exfiltrationexploitation+6
11 day ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubh4x0r-dz/cve-2024-23897

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

exploitationinformation-gatheringpenetration-testing+3
2092 years ago
mqxss preview

mqxss

GitHubgrampae/mqxss

Hooked browser communication over MQTT

command-and-controlinformation-gatheringpayload-generation+4
82 years ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubethan-repo-lab4b6/cve-2022-36537

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

authentication-authorizationexploitationinformation-gathering+3
3 years ago
blind-sql-bitshifting preview
Archived

blind-sql-bitshifting

GitHubawnumar/blind-sql-bitshifting

A blind SQL injection module that uses bitshfting to calculate characters.

information-gatheringpenetration-testingvulnerability-analysis+1
1334 years ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubalt3kx/cve-2022-22965

Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)

exploitationinformation-gatheringpenetration-testing+3
1004 years ago
CVE-2024-56331 preview

CVE-2024-56331

GitHubgriisemine/cve-2024-56331

Proof-of-concept exploit for CVE-2024-56331, demonstrating Local File Inclusion in Uptime Kuma via improper URL handling in the real-browser monitor.…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
cve-2020-10977 preview

cve-2020-10977

GitHubthewhiteh4t/cve-2020-10977

GitLab 12.9.0 Arbitrary File Read

exploitationinformation-gatheringpenetration-testing+3
705 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubabhishekmorla/cve-2022-26134

Exploit scanner for CVE-2022-26134 in Atlassian Confluence. Uses Shodan to find vulnerable hosts, then executes commands via the OGNL injection…

exploitationinformation-gatheringpenetration-testing+3
84 years ago
CVE-2024-50395 preview

CVE-2024-50395

GitHubneko-hat/cve-2024-50395

Python exploit for CVE-2024-50395, an authorization bypass in QNAP Media Streaming add-on. Uses crafted User-Agent headers to bypass authentication…

exploitationinformation-gatheringpenetration-testing+2
21 year ago
CVE-2022-40881 preview

CVE-2022-40881

GitHubyilin1203/cve-2022-40881

Proof-of-concept exploit for CVE-2022-40881 targeting SolarView Compact devices. Uses fofa query for reconnaissance and payload delivery for…

exploitationiot-securitypenetration-testing+3
23 years ago
CVE-2020-17519 preview

CVE-2020-17519

GitHubgazettel/cve-2020-17519

Python-based directory traversal exploit for CVE-2020-17519 (Apache Flink) with multi-threading, proxy support, and configurable depth for retrieving…

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2024-2961 preview

CVE-2024-2961

GitHub4wayhandshake/cve-2024-2961

Exploits CVE-2024-2961 to read arbitrary files from vulnerable PHP applications using filter chain payloads.

exploitationinformation-gatheringpenetration-testing+2
1 year ago