Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
apache_normalize_path preview

apache_normalize_path

GitHubzeop-cybersec/apache_normalize_path

Metasploit-Framework modules (scanner and exploit) for the CVE-2021-41773 and CVE-2021-42013 (Path Traversal in Apache 2.4.49/2.4.50)

exploit-frameworkspayload-developmentpenetration-testing+3
12
4 years ago
CVE-2022-22954 preview

CVE-2022-22954

GitHubjax7sec/cve-2022-22954

提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码

command-and-controlexploitationpenetration-testing+2
124 years ago
CVE-2026-23744-MCPJam-Exploit preview

CVE-2026-23744-MCPJam-Exploit

GitHubcerberusmrxi/cve-2026-23744-mcpjam-exploit

A proof-of-concept exploit for CVE-2026-23744 - MCPJam Inspector Remote Code Execution (RCE) vulnerability. This tool demonstrates the security flaw…

command-and-controleducationexploitation+4
71 month ago
CVE-2024-2876 preview

CVE-2024-2876

GitHubkernel364/cve-2024-2876
exploitationreconnaissancevulnerability-analysis+1
21 year ago
By-Poloss..-..CVE-2026-12432-PoC preview

By-Poloss..-..CVE-2026-12432-PoC

GitHubpolosss/by-poloss..-..cve-2026-12432-poc

WP Full Stripe Free <= 8.4.3 - Missing Authorization

exploitationmisconfigurationpenetration-testing+3
11 month ago
CVE-2026-5718-Lab preview

CVE-2026-5718-Lab

GitHubrootdirective-sec/cve-2026-5718-lab
ctfeducationexploitation+3
13 months ago
CVE-2026-15748 preview

CVE-2026-15748

GitHububaydev/cve-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

exploitationpenetration-testingred-teaming+3
3 days ago
CVE-2026-14871 preview

CVE-2026-14871

GitHubjfoz1010/cve-2026-14871

BOLA/IDOR vulnerability in osTicket ajax.tickets.php | Responsible Disclosure

educationexploitationinformation-gathering+3
1 month ago
cve-2026-33067 preview

cve-2026-33067

GitHublopseg/cve-2026-33067

Nuclei template for detecting CVE-2026-33017, an unauthenticated remote code execution vulnerability in Langflow ≤ 1.8.2. Performs non-destructive…

exploitationpenetration-testingreconnaissance+3
3 months ago
CVE-2026-5513 preview

CVE-2026-5513

GitHubxaanziu/cve-2026-5513

CVE-2026-5513: Bookly <= 27.2 Stored XSS via Cookie (Unauthenticated)

exploitationinformation-gatheringpenetration-testing+3
2 months ago
CVE-2011-2461_Magento_Patch preview

CVE-2011-2461_Magento_Patch

GitHubedmondscommerce/cve-2011-2461_magento_patch
exploitationmisconfigurationvulnerability-analysis+2
8 years ago
log4j-vulnerability preview

log4j-vulnerability

GitHubmazhar-hassan/log4j-vulnerability

Log4Shell (CVE-2021-44228) is a zero-day vulnerability in Log4j

educationexploitationinformation-gathering+3
4 years ago
CTT-enhanced-VMware-vCenter preview

CTT-enhanced-VMware-vCenter

GitHubsimoesctt/ctt-enhanced-vmware-vcenter

Looking at current high-impact vulnerabilities, let's use the VMware vCenter Server CVE-2021-21972 (CVSS 9.8) as our base. This is a publicly known…

exploitationpenetration-testingred-teaming+2
6 months ago
PoC-Apache-CVE-2021-41773-Infrastructure-LAB preview

PoC-Apache-CVE-2021-41773-Infrastructure-LAB

GitHubisabbii/poc-apache-cve-2021-41773-infrastructure-lab
container-securityeducationexploitation+4
6 months ago
cve-2024-38819-lab preview

cve-2024-38819-lab

GitHubtrevorputbrese/cve-2024-38819-lab
educationlabs-practicemisconfiguration+3
2 months ago