Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
136 results
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
34
11h 29m ago
CVE-2020-10770-keycloak-exploit-poc preview

CVE-2020-10770-keycloak-exploit-poc

GitHub0xlyvio/cve-2020-10770-keycloak-exploit-poc

Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

educationexploitationpenetration-testing+3
7 days ago
CVE-2026-71300 preview

CVE-2026-71300

GitHuboscerd/cve-2026-71300

Proof-of-concept reproducer for Apache Camel camel-atmosphere-websocket dispatch header injection (CVE-2026-71300), demonstrating how an injected…

educationexploitationpapers-research+2
19 days ago
WSGoat preview

WSGoat

GitHubmakarov05bm/wsgoat

The vulnerable application that will teach you how to hack WebSockets

authenticationeducationlabs-practice+3
720 days ago
CVE-2026-11107-Insecure-Direct-Object-Reference-with-Predictable-UUIDv1 preview

CVE-2026-11107-Insecure-Direct-Object-Reference-with-Predictable-UUIDv1

GitHubgeorge0papasotiriou/cve-2026-11107-insecure-direct-object-reference-with-predictable-uuidv1

Educational CVE-2026-11107 demo with vulnerable Flask API and exploit script, showing how predictable UUIDv1 identifiers enable insecure direct…

educationexploitationvulnerability-analysis+2
1 month ago
CVE-2026-1010-WebSocket-Connection-Smuggling-via-Malformed-Upgrade-Header preview

CVE-2026-1010-WebSocket-Connection-Smuggling-via-Malformed-Upgrade-Header

GitHubgeorge0papasotiriou/cve-2026-1010-websocket-connection-smuggling-via-malformed-upgrade-header

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
cve-2021-41773-lab preview

cve-2021-41773-lab

GitHubkunalkhandelwal-dev/cve-2021-41773-lab

Educational FastAPI lab demonstrating CVE-2021-41773 directory traversal and local file inclusion, with a vulnerable server, patched code, and…

educationlabs-practicevulnerability-analysis+2
1 month ago
graylog-cve-2024-24824-exploit preview

graylog-cve-2024-24824-exploit

GitHubrootkited/graylog-cve-2024-24824-exploit

Proof-of-concept exploit for CVE-2024-24824 demonstrating how an arbitrary class loading primitive can be transformed into remote code execution on…

code-analysiseducationexploitation+3
2 months ago
CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough preview

CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough

GitHubbenedictejepu/cve-2024-24945-nginx-rift---tryhackme-lab-walkthrough

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

binary-exploitationctfeducation+5
2 months ago
struts-uploader-vulnerability preview

struts-uploader-vulnerability

GitHubbaburkin/struts-uploader-vulnerability

Research of exploit options for CVE-2024-53667 and their remediation

educationexploitationlabs-practice+3
3 months ago
Zimbra-Valid-Login-Checker preview

Zimbra-Valid-Login-Checker

GitHubjenderal92/zimbra-valid-login-checker

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

authenticationpassword-attackspenetration-testing+2
13 months ago
CVE-2026-32136_exploit preview

CVE-2026-32136_exploit

GitHub0xdak/cve-2026-32136_exploit

Proof-of-concept exploit for CVE-2026-32136: unauthenticated authentication bypass in AdGuard Home via HTTP/2 cleartext (h2c) upgrade. Demonstrates…

authentication-authorizationeducationexploitation+4
4 months ago
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
264 months ago
CVE-2022-46364-Proof-of-the-concept preview

CVE-2022-46364-Proof-of-the-concept

GitHubcybermaksx/cve-2022-46364-proof-of-the-concept

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

educationexploitationinformation-gathering+3
35 months ago
vuln-chain-lab preview

vuln-chain-lab

GitHubechosecure/vuln-chain-lab

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

ctfeducationlabs-practice+5
15 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubahmadf77/cve-2026-23744

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

command-and-controlexploitationpayload-development+3
5 months ago
CVE-2024-36039_PoC preview

CVE-2024-36039_PoC

GitHubzenniskayy2k4/cve-2024-36039_poc

PoC for CVE-2024-36039: Demonstrating SQL Injection via PyMySQL Object-to-String serialization flaw

database-securityeducationexploitation+3
15 months ago
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
15 months ago
Previous12…8Next