Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
CVE-2024-36840-Exploit preview

CVE-2024-36840-Exploit

GitHubtheexploiters/cve-2024-36840-exploit

Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)

exploitationinformation-gatheringpenetration-testing+2
2
1 year ago
CVE-2024-27198-RCE preview

CVE-2024-27198-RCE

GitHubpasswa11/cve-2024-27198-rce

Exploit for JetBrains TeamCity authentication bypass (CVE-2024-27198/27199) enabling remote code execution. Includes dork queries for asset discovery…

authentication-authorizationexploitationpenetration-testing+3
32 years ago
CVE-2025-29306 preview

CVE-2025-29306

GitHubverylazytech/cve-2025-29306

Proof-of-concept exploit for FoxCMS v1.2.5 remote code execution via the index.html component, with FOFA dork for target discovery.

educationexploitationreconnaissance+2
21 year ago
CVE-2024-4956 preview

CVE-2024-4956

GitHubgoatsecurity/cve-2024-4956

CVE-2024-4956 : Nexus Repository Manager 3 poc exploit

exploitationinformation-gatheringpenetration-testing+3
32 years ago
F5-BIG-IP-exploit preview

F5-BIG-IP-exploit

GitHubsashka3076/f5-big-ip-exploit

CVE-2022-1388

command-and-controlexploitationremote-access-tool+2
4 years ago
CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning preview

CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning

GitHubnotspepino/cve-2024-4879-cve-2024-5217-servicenow-rce-scanning

CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.

exploitationinformation-gatheringpenetration-testing+3
52 years ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubegi08/cve-2024-10914

CVE-2024-10914_Manual testing with burpsuite

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2023-29983 preview

CVE-2023-29983

GitHubzprototype/cve-2023-29983

Proof-of-concept for CVE-2023-29983: stored cross-site scripting via unsanitized token parameter in cmaps auditlog, enabling admin cookie theft.

educationexploitationpenetration-testing+3
3 years ago
CVE-2023-29809 preview

CVE-2023-29809

GitHubzprototype/cve-2023-29809

Proof-of-concept exploit for CVE-2023-29809: unauthenticated SQL injection in cmaps booking system. Demonstrates time-based blind injection and…

exploitationpenetration-testingvulnerability-analysis+1
13 years ago
CVE-2023-29808 preview

CVE-2023-29808

GitHubzprototype/cve-2023-29808

Reflected cross-site scripting (XSS) proof-of-concept exploit for CVE-2023-29808 targeting the /index.php?map=overview&findme= endpoint in cmaps…

exploitationpenetration-testingvulnerability-analysis+2
43 years ago
CVE-2022-26138 preview

CVE-2022-26138

GitHubshavchen/cve-2022-26138

Exploit for CVE-2022-26138, a SAML SSO bypass vulnerability in Atlassian products, with a FOFA dork for identifying vulnerable instances.

exploitationinformation-gatheringreconnaissance+2
4 years ago
CVE-2022-22954 preview

CVE-2022-22954

GitHuborwagodfather/cve-2022-22954

Proof-of-concept exploit for CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access via SSTI injection. Includes Shodan…

exploitationinformation-gatheringreconnaissance+2
84 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubun4ckn0wl3z/cve-2017-5638

Exploit for Apache Struts2 remote code execution vulnerability (CVE-2017-5638) with Google Dork reconnaissance for target discovery.

exploitationinformation-gatheringreconnaissance+2
17 years ago
cve-2017-5638 preview

cve-2017-5638

GitHubxsscx/cve-2017-5638

Example PoC Code for CVE-2017-5638 | Apache Struts Exploit

exploitationinformation-gatheringpayload-development+3
229 years ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubkh4sh3i/cve-2022-23131

Python exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Includes Shodan and FOFA dorks for vulnerable instance discovery.

authenticationexploitationinformation-gathering+3
154 years ago
CVE-2017-14322 preview

CVE-2017-14322

GitHubjoesmithjaffa/cve-2017-14322

CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit

authentication-authorizationeducationexploitation+3
58 years ago
MoodleExploit preview

MoodleExploit

GitHubdarrynten/moodleexploit

Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133

exploitationpenetration-testingremote-access-tool+2
107 years ago
CVE-2024-29269 preview

CVE-2024-29269

GitHubchsxthwik/cve-2024-29269

Exploit for CVE-2024-29269 enabling unauthenticated OS command injection on TLR-2005KSH routers, with integrated reconnaissance dork queries for…

educationexploitationreconnaissance+2
11 year ago
Previous12Next