Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
290 results
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.8k12 days ago
CVE-2024-48914 preview

CVE-2024-48914

GitHubeqstlab/cve-2024-48914

Arbitrary File Read and DoS in vendure-ecommerce exploit

data-exfiltrationexploitationinformation-gathering+3
51 year ago
Kousei preview

Kousei

GitHubnu11secur1ty/kousei

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

exploitationpassword-crackingpayload-generation+6
37 days ago
CVE-2024-13513.py preview

CVE-2024-13513.py

GitHub0axz-tools/cve-2024-13513.py

Automated scanner and exploiter for CVE-2024-13513 in Oliver POS WordPress plugin, checking vulnerable installations and changing password-reset…

exploitationinformation-gatheringpenetration-testing+3
11 months ago
CVE-2025-39601 preview

CVE-2025-39601

GitHubnxploited/cve-2025-39601

WordPress Custom CSS, JS & PHP plugin <= 2.4.1 - CSRF to RCE vulnerability

ctfeducationexploitation+3
11 year ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubmin8282/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

educationexploitationpenetration-testing+3
6 months ago
CVE-2025-52399-SQLi-Institute-of-Current-Students preview

CVE-2025-52399-SQLi-Institute-of-Current-Students

GitHubuserr404/cve-2025-52399-sqli-institute-of-current-students

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the loginlinkfaculty endpoint of Institute-of-Current-Students, enabling…

educationexploitationpapers-research+3
11 year ago
strutt-cve-2014-0114 preview

strutt-cve-2014-0114

GitHubaenlr/strutt-cve-2014-0114

Technical analysis and proof-of-concept for Apache Struts 1 class parameter manipulation (CVE-2014-0114), demonstrating remote code execution on…

educationexploitationpapers-research+3
27 years ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubk4nfr3/cve-2024-9474

Python exploit script for CVE-2024-9474 targeting PAN-OS SSL VPN, enabling remote code execution and reverse shell deployment for penetration testing.

exploitationpayload-generationpenetration-testing+3
101 year ago
CVE-2026-33137 preview

CVE-2026-33137

GitHubportbuster1337/cve-2026-33137

XWiki Platform - CVE-2026-33137 PoC - Unauthenticated XAR Import via REST /wikis/{wikiName}

educationexploitationpayload-generation+4
4 months ago
CVE-2026-8809 preview

CVE-2026-8809

GitHubizxci/cve-2026-8809

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

authenticationexploitationpenetration-testing+3
3 months ago
CVE-2023-31717 preview

CVE-2023-31717

GitHubmateustesser/cve-2023-31717

Proof-of-concept SQL injection exploit for FUXA SCADA software (<=1.1.12) via HTTP POST JSON id parameter, enabling extraction of SQLite database…

database-securityexploitationscada-ics-security+2
3 years ago
CVE-2025-54782 preview

CVE-2025-54782

GitHubddestinys/cve-2025-54782

CVE-2025-54782

command-and-controlexploitationpenetration-testing+2
11 months ago
vBulletin_Routestring-RCE preview

vBulletin_Routestring-RCE

GitHubludy-dev/vbulletin_routestring-rce

PoC exploit for CVE-2019-16759 enabling remote code execution on vBulletin 5.0.0–5.6.2 via malicious POST request due to input validation flaw.

exploitationpayload-generationpenetration-testing+2
15 years ago
CVE-2024-39211 preview

CVE-2024-39211

GitHubartemy-ccrsky/cve-2024-39211

User Enumeration vulnerability in Kaiten (workflow management system)

information-gatheringosintpassword-attacks+3
71 year ago
CVE-2021-25646 preview

CVE-2021-25646

GitHublp008/cve-2021-25646

Exploit for CVE-2021-25646 Apache Druid RCE via crafted HTTP POST request to the sampler endpoint, with embedded payload delivery and Snort detection…

exploitationpayload-generationpenetration-testing+3
25 years ago
CVE-2026-37071 preview

CVE-2026-37071

GitHubjfs-jfs/cve-2026-37071

Proof-of-concept exploit for CVE-2026-37071: arbitrary file rename in Veno File Manager 4.4.9 enabling privilege escalation to super administrator…

exploitationmisconfigurationprivilege-escalation+2
3 months ago
CVE-2017-8046 preview

CVE-2017-8046

GitHubbkhablenko/cve-2017-8046

Demonstrates exploitation of CVE-2017-8046 in a Spring Boot application, including a SpEL injection payload and dependency-check verification for…

code-analysiseducationpenetration-testing+3
8 years ago
Previous12…17Next