Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
85 results
CVE-2026-66066-POC preview

CVE-2026-66066-POC

GitHubzer0sumgam3/cve-2026-66066-poc

PoC for CVE-2026-66066 in Ruby on Rails

educationexploitationlabs-practice+3
232 months ago
CVE-2015-3224 preview

CVE-2015-3224

GitHub0x00-0x00/cve-2015-3224

Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224

exploit-frameworkspayload-developmentpenetration-testing+3
28 years ago
metasploit-framework preview
Archived

metasploit-framework

GitHubmarkoarmitage/metasploit-framework

app turn nil publics and privates into blanks 3 months ago config Use bundler/setup for more graceful bundler related failures 11 days ago data…

command-and-controlexploitationexploit-frameworks+8
55 years ago
CVE-2016-2098 preview

CVE-2016-2098

GitHub3rg1s/cve-2016-2098

Proof-of-concept exploit for CVE-2016-2098, demonstrating remote Ruby code execution through Rails render method abuse; intended for security testing…

code-analysiseducationexploitation+2
6 years ago
bitbucket-test preview

bitbucket-test

GitHubjohangabrielson/bitbucket-test

Investigating CVE-2022-36804

educationexploitationlabs-practice+3
5 months ago
CVE-2025-61148 preview

CVE-2025-61148

GitHubsharma19d/cve-2025-61148

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

api-security-testingeducationinformation-gathering+3
10 months ago
CVE-2026-66066 preview

CVE-2026-66066

GitHubhackspeak/cve-2026-66066

CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

exploitationinformation-gatheringpenetration-testing+5
31 month ago
cve-2026-32699-facturascripts-nick-bypass preview

cve-2026-32699-facturascripts-nick-bypass

GitHubturkios/cve-2026-32699-facturascripts-nick-bypass

Broken Access Control in FacturaScripts EditUser controller allows authenticated users to rename any account (including admin) by modifying the…

authentication-authorizationexploitationpenetration-testing+3
5 months ago
CVE-2016-2098 preview

CVE-2016-2098

GitHubits-arun/cve-2016-2098

Bash-based proof-of-concept exploit for CVE-2016-2098, targeting Ruby on Rails Action Pack remote code execution via unrestricted render method.

exploitationpenetration-testingred-teaming+2
18 years ago
SCTT-2026-33-0004-FortiCloud-SSO-Identity-Singularity preview

SCTT-2026-33-0004-FortiCloud-SSO-Identity-Singularity

GitHubsimoesctt/sctt-2026-33-0004-forticloud-sso-identity-singularity

While Fortinet's January 27, 2026 mitigation for **CVE-2026-24858** focuses on blocking specific accounts like `[email protected]`, it fails to…

authentication-authorizationexploitationred-teaming+2
8 months ago
CVE-2016-2098 preview

CVE-2016-2098

GitHubdebalinax64/cve-2016-2098

CVE-2016-2098 - POC of RCE Ruby on Rails: Improper Input Validation (CVE-2016-2098) in bash. Remote attackers can execute arbitrary Ruby code by…

code-analysisexploitationpenetration-testing+2
5 years ago
rails-rce-cve-2016-0752 preview

rails-rce-cve-2016-0752

GitHubforced-request/rails-rce-cve-2016-0752

Proof-of-concept exploit for CVE-2016-0752, a remote code execution vulnerability in Ruby on Rails via dynamic render paths. Includes vulnerable app,…

educationexploitationpenetration-testing+2
1010 years ago
CVE-2026-73314 preview

CVE-2026-73314

GitHubbombobombone/cve-2026-73314

Proof-of-concept exploit for CVE-2026-73314, a PayPal REST webhook signature verification bypass in XenForo before 2.3.13, allowing unauthorized…

exploitationvulnerability-analysisweb-application-exploitation+1
23 days ago
CVE-2019-5420 preview

CVE-2019-5420

GitHuberemiel/cve-2019-5420

Python exploit script for CVE-2019-5420, targeting Ruby on Rails signed-session AES GCM key brute-forcing to achieve remote code execution in…

encryption-decryption-toolsexploitationpassword-attacks+3
5 years ago
CVE-2026-53913 preview

CVE-2026-53913

GitHuboscerd/cve-2026-53913

PoC reproducer for CVE-2026-53913 (Apache Camel camel-keycloak): KeycloakSecurityPolicy fails open in the Basic Setup — with no required…

authenticationcode-analysisexploitation+3
12 months ago
HTTP3ONSTEROIDS preview

HTTP3ONSTEROIDS

GitHubdhmosfunk/http3onsteroids

PoC and lab environment for CVE-2023-25950: HTTP request smuggling via malformed header fields in HAProxy's HTTP/3 implementation, enabling DoS and…

educationlabs-practicevulnerability-analysis+1
111 year ago
CVE-2020-8165 preview

CVE-2020-8165

GitHubhybryx/cve-2020-8165

Python exploit for CVE-2020-8165 targeting Rails MemCacheStore and RedisCacheStore. Enables remote command execution via user-provided object…

command-and-controlexploitationpayload-generation+3
45 years ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
12 months ago
Previous12345Next