Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2026-33267-PoC preview

CVE-2026-33267-PoC

GitHubboreas37/cve-2026-33267-poc

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

exploitationvulnerability-analysisweb-application-exploitation+1
4
1 month ago
CVE-2019-11043-Vulnerability preview

CVE-2019-11043-Vulnerability

GitHubmagentabear/cve-2019-11043-vulnerability

Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic…

educationexploitationlabs-practice+8
9 months ago
Apache-Solr-RCE-via-Velocity-template preview

Apache-Solr-RCE-via-Velocity-template

GitHubalewong/apache-solr-rce-via-velocity-template

Exploit for Apache Solr remote code execution via Velocity template injection, enabling command execution on vulnerable instances through crafted…

exploitationpayload-generationpenetration-testing+2
356 years ago
MITMer preview

MITMer

GitHubhusam212/mitmer

Automated man-in-the-middle attack tool.

dns-analysisnetwork-securitypacket-sniffing-analysis+5
5312 years ago
log4j-Scan-Burpsuite preview

log4j-Scan-Burpsuite

GitHubsnow0715/log4j-scan-burpsuite

Log4j漏洞(CVE-2021-44228)的Burpsuite检测插件

dynamic-analysis-sandboxingexploitationpenetration-testing+3
134 years ago
GoF5-CVE-2020-5902 preview

GoF5-CVE-2020-5902

GitHubdeepsecurity-pe/gof5-cve-2020-5902

Script para validar CVE-2020-5902 hecho en Go.

exploitationinformation-gatheringpenetration-testing+2
26 years ago
CVE-2024-7593_PoC_Exploit preview

CVE-2024-7593_PoC_Exploit

GitHubd3n14ld15k/cve-2024-7593_poc_exploit

CVE-2024-7593 Ivanti Virtual Traffic Manager 22.2R1 / 22.7R2 Admin Panel Authentication Bypass PoC [EXPLOIT]

authentication-authorizationexploitationpenetration-testing+3
91 year ago
CVE-2021-26258 preview

CVE-2021-26258

GitHubzwclose/cve-2021-26258

Files and tools for CVE-2021-26258

exploitationfirmware-analysismalware-analysis+3
33 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubnsflabs/cve-2020-5902

Python scanner to detect CVE-2020-5902 RCE vulnerability in F5 BIG-IP TMUI. Tests unauthenticated remote systems for arbitrary command execution via…

exploitationpenetration-testingremote-access-tool+2
86 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubyassineaboukir/cve-2020-5902

Proof of concept for CVE-2020-5902

exploitationpenetration-testingred-teaming+2
706 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubmurataydemir/cve-2020-5902

[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)

exploitationexploit-frameworkspenetration-testing+3
26 years ago
CVE-2020-5902-NSE preview

CVE-2020-5902-NSE

GitHubrwincey/cve-2020-5902-nse

Nmap NSE script for detecting and exploiting CVE-2020-5902, a remote code execution vulnerability in F5 BIG-IP traffic management user interface.

exploitationnetwork-mappingpenetration-testing+2
86 years ago
CVE-2025-53770-Vulnerable-Scanner preview

CVE-2025-53770-Vulnerable-Scanner

GitHubimbas007/cve-2025-53770-vulnerable-scanner

Python script to scan SharePoint hosts for CVE-2025-53770 using custom payloads, with optional Burp Suite proxy interception for traffic analysis and…

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubdnerzker/cve-2020-5902

Proof-of-concept exploit for CVE-2020-5902, a remote code execution vulnerability in F5 BIG-IP TMUI, with file read and command execution payloads…

exploitationinformation-gatheringreconnaissance+2
6 years ago
CVE-2020-23586 preview

CVE-2020-23586

GitHubhuzaifahussain98/cve-2020-23586

CSRF allows to Add Network Traffic Control Type Rule

exploitationmisconfigurationpenetration-testing+3
13 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubamitlttwo/cve-2020-5902

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface…

exploitationinformation-gatheringpenetration-testing+2
13 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubk3nundrum/cve-2020-5902

Python exploit for CVE-2020-5902 targeting F5 BIG-IP remote code execution vulnerability. Enables unauthenticated RCE via the Traffic Management User…

exploitationpenetration-testingred-teaming+2
6 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubjinnywc/cve-2020-5902

Proof-of-concept exploit for CVE-2020-5902, a critical remote code execution vulnerability in F5 BIG-IP traffic management systems.

exploitationpenetration-testingred-teaming+2
16 years ago
Previous12Next