Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
74 results
CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC preview

CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC

GitHubcyfare/cve-2026-23918-apache-http-server-doublefree-poc

Proof-of-concept exploit for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server, demonstrating remote crash via crafted requests.

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
cve-2025-3248 preview

cve-2025-3248

GitHubbambooqj/cve-2025-3248

Langflow 在对用户提交的“验证代码”做 AST 解析和编译时,在未做鉴权与沙箱限制的情况下调用了 Python 的 compile()/exec()(以及在编译阶段会评估函数默认参数与装饰器),攻击者可把恶意载荷放在参数默认值或装饰器里,借此在服务器上下文中执行任意语句(反弹…

command-and-controlexploitationpenetration-testing+3
110 months ago
CVE-2026-20127_EXP preview

CVE-2026-20127_EXP

GitHubbugfor-pings/cve-2026-20127_exp

Cisco Catalyst SD-WAN 身份验证绕过漏洞(CVE-2026-20127)利用EXP

exploitationpenetration-testingred-teaming+2
46 months ago
poc-yaws-cgi-shell-injection preview

poc-yaws-cgi-shell-injection

GitHubvulnbe/poc-yaws-cgi-shell-injection

Yaws web server OS command injection POC

exploitationvulnerability-analysisweb-application-exploitation
16 years ago
poc-yaws-dav-xxe preview

poc-yaws-dav-xxe

GitHubvulnbe/poc-yaws-dav-xxe

Yaws web server XML external entity injection POC

exploitationpenetration-testingvulnerability-analysis+1
6 years ago
CVE-2021-20038-SonicWall-RCE preview

CVE-2021-20038-SonicWall-RCE

GitHubvesperp/cve-2021-20038-sonicwall-rce

Python exploit for CVE-2021-20038 targeting SonicWall SSL VPN with command-line URL/file input for remote code execution.

command-and-controlexploitationpenetration-testing+3
14 years ago
CVE-2021-21972 preview

CVE-2021-21972

GitHubl-pin/cve-2021-21972

Exploit for CVE-2021-21972 targeting VMware vCenter with options for webshell or SSH key upload, proxy support, and batch scanning.

exploitationpayload-generationpenetration-testing+2
15 years ago
CVE-2020-1938-Tool preview

CVE-2020-1938-Tool

GitHubjust1cep4rtn3r/cve-2020-1938-tool

批量检测幽灵猫漏洞

exploitationinformation-gatheringpenetration-testing+2
36 years ago
CVE-2023-28432 preview

CVE-2023-28432

GitHubmzzdtot/cve-2023-28432

MinIO敏感信息泄露漏洞批量扫描poc&exp

cloud-securityexploitationinformation-gathering+3
373 years ago
CVE-2023-4165 preview

CVE-2023-4165

GitHubmvpyyds/cve-2023-4165

Python-based exploit for CVE-2023-4165 targeting Tongda OA, enabling automated vulnerability verification against single or multiple URLs via…

exploitationinformation-gatheringpenetration-testing+2
3 years ago
CVE-2023-4166 preview

CVE-2023-4166

GitHubmvpyyds/cve-2023-4166

Python exploit for CVE-2023-4166 targeting Tongda OA. Supports single URL and file-based batch scanning for automated vulnerability verification.

exploitationpenetration-testingreconnaissance+2
13 years ago
harbor-give-me-admin preview

harbor-give-me-admin

GitHubthelsa/harbor-give-me-admin

harbor(<1.7.6/1.8.3) privilege escalation (CVE-2019-16097)

cloud-securityexploitationpenetration-testing+3
6 years ago
CVE-2025-1974 preview

CVE-2025-1974

GitHubzulloper/cve-2025-1974

CVE-2025-1974 PoC 코드

cloud-securitycontainer-securityexploitation+3
1 year ago
GitLab-Graphql-CVE-2020-26413 preview

GitLab-Graphql-CVE-2020-26413

GitHubkento-sec/gitlab-graphql-cve-2020-26413

GitLab-Graphql-CVE-2020-26413 POC

exploitationinformation-gatheringpenetration-testing+2
14 years ago
CVE-2024-36401 preview

CVE-2024-36401

GitHubniuwoo/cve-2024-36401

POC

command-and-controlexploitationremote-access-tool+2
42 years ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubddestinys/cve-2023-42793

Batch vulnerability scanner for CVE-2023-42793 targeting JetBrains TeamCity servers. Automates credential extraction and login URL discovery across…

exploitationinformation-gatheringpenetration-testing+2
8 months ago
CVE-2022-31793 preview

CVE-2022-31793

GitHubxpgdgit/cve-2022-31793

Proof-of-concept exploit for CVE-2022-31793 with IP/file-based target scanning, validation mode, and arbitrary file read via HTTP requests.

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2022-31269 preview

CVE-2022-31269

GitHubhenry4e36/cve-2022-31269

Nortek Control Linear eMerge E3-Series 信息泄露

exploitationinformation-gatheringiot-security+2
14 years ago
Previous12345Next