Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
CVE-2026-44402 preview

CVE-2026-44402

GitHub0xcyp1337/cve-2026-44402

Exploit for CVE-2026-44402 targeting Voltronic Power SNMP Web Pro 1.1, enabling unauthenticated remote code execution via malicious firmware upload.…

exploitationpenetration-testingred-teaming+3
4 days ago
Spring-Cloud-Function-SpEL preview

Spring-Cloud-Function-SpEL

GitHubpizz33/spring-cloud-function-spel

Reproduction environment and proof-of-concept for Spring Cloud Function SpEL injection leading to remote code execution, with a runnable Java 11 demo…

educationexploitationlabs-practice+2
244 years ago
CVE-2025-67923 preview

CVE-2025-67923

GitHubrandomrobbiebf/cve-2025-67923

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

api-securityexploitationvulnerability-analysis+2
6 months ago
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityexploitationiot-security+5
129 days ago
Magento-ver.-2.4.6 preview

Magento-ver.-2.4.6

GitHubcapture0x/magento-ver.-2.4.6

Magento ver. 2.4.6 - XSLT Server Side Injection

exploitationpayload-developmentvulnerability-analysis+1
42 years ago
CVE-2025-8625 preview

CVE-2025-8625

GitHubnxploited/cve-2025-8625

Copypress Rest API 1.1 - 1.2 - Missing Configurable JWT Secret and File-Type Validation to Unauthenticated Remote Code Execution

exploitationpayload-generationpenetration-testing+3
211 months ago
gitlab-SSRF-redis-RCE preview

gitlab-SSRF-redis-RCE

GitHubjas502n/gitlab-ssrf-redis-rce

GitLab 11.4.7 SSRF配合redis远程执行代码

educationexploitationpenetration-testing+3
1207 years ago
roller-csrf preview

roller-csrf

GitHubvanlam2001/roller-csrf

PoC exploit for a CSRF vulnerability in Apache Roller v6.1.2 profile update endpoint. Includes HTML form exploit code to demonstrate unauthorized…

exploitationpenetration-testingvulnerability-analysis+2
10 months ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubxiaolvchen/cve-2025-54100

CVE-2025-54100(PowerShell 远程代码执行漏洞)

educationexploitationpayload-development+3
18 months ago
WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502 preview

WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502

GitHubkai-one001/wordpress-news-and-blog-designer-bundle-cve-2025-14502

WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中,存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件,从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型…

code-analysisexploitationpenetration-testing+3
27 months ago
Wordpress-ebook-CVE-2016-10924 preview

Wordpress-ebook-CVE-2016-10924

GitHublgenagul/wordpress-ebook-cve-2016-10924

Exploits CVE-2016-10924 file disclosure in WordPress eBook Download plugin to brute-force server processes and retrieve sensitive files.

exploitationinformation-gatheringpenetration-testing+2
1 year ago
lab-cve-2016-15042 preview

lab-cve-2016-15042

GitHubimbios/lab-cve-2016-15042

CVE-2016-15042 lab: Dockerized WordPress PoC for unauthenticated file upload in Frontend File Manager <4.0 and N‑Media Post Front‑end Form <1.1

ctfeducationlabs-practice+3
11 year ago
cve-2025-9933 preview

cve-2025-9933

GitHubtitanmaster96/cve-2025-9933

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file…

educationexploitationpenetration-testing+2
7 months ago
CVE-2025-63708 preview

CVE-2025-63708

GitHubdylandavis1/cve-2025-63708

Proof-of-concept exploit for CVE-2025-63708, a stored XSS vulnerability in AI Font Matcher. Demonstrates session cookie theft via unsanitized font…

exploitationinformation-gatheringpenetration-testing+3
9 months ago
CVE-2024-51793 preview

CVE-2024-51793

GitHubnxploited/cve-2024-51793

WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability

exploitationpenetration-testingvulnerability-analysis+2
11 year ago
CVE-2024-50492 preview

CVE-2024-50492

GitHubnxploited/cve-2024-50492

ScottCart <= 1.1 - Unauthenticated Remote Code Execution

educationexploitationpayload-generation+3
11 year ago
CVE-2023-38146 preview

CVE-2023-38146

GitHubjnnshschl/cve-2023-38146

PoC for the ThemeBleed Windows 11 CVE-2023-38146 written in python using impacket. https://jnns.de/posts/cve-2023-38146-poc/

exploitationpayload-developmentpenetration-testing+2
272 years ago
CVE-2021-43258 preview

CVE-2021-43258

GitHubmrvirusir/cve-2021-43258

ChurchInfo 1.2.13-1.3.0 Remote Code Execution Exploit

exploitationpenetration-testingremote-access-tool+2
23 years ago
Previous123Next