Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
299 results
CVE-2024-53677-S2-067 preview

CVE-2024-53677-S2-067

GitHubtam-k592/cve-2024-53677-s2-067

A critical vulnerability, CVE-2024-53677, has been identified in the popular Apache Struts framework, potentially allowing attackers to execute…

exploitationpayload-developmentpenetration-testing+3
96
1 year ago
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

dynamic-code-analysiseducationencryption-decryption-tools+7
472 months ago
scarce-apache2 preview

scarce-apache2

GitHubhightechsec/scarce-apache2

A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public

exploitationpenetration-testingvulnerability-scanners+1
624 years ago
RedRoot preview

RedRoot

GitHubagampreet-singh/redroot

RedRoot is a Python-based, CLI-driven offensive security framework that brings essential red teaming tools into one unified terminal environment.…

ctfexploit-frameworksfuzzing+9
174 months ago
reactguard preview

reactguard

GitHubtheori-io/reactguard

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

code-analysispenetration-testingstatic-analysis+3
188 months ago
CVE-2022-22978-PoC preview

CVE-2022-22978-PoC

GitHubducluongtran9121/cve-2022-22978-poc

PoC of CVE-2022-22978 vulnerability in Spring Security framework

authentication-authorizationeducationexploitation+3
134 years ago
CVE-2019-5825 preview

CVE-2019-5825

GitHubtimwr/cve-2019-5825

Chrome V8 exploit for CVE-2019-5825 targeting version 73.0.3683.86 with --no-sandbox. Includes proof-of-concept code and integration with Metasploit…

binary-exploitationexploitationpenetration-testing+2
76 years ago
Havoc-C2-SSRF-to-RCE preview

Havoc-C2-SSRF-to-RCE

GitHubsebr-dev/havoc-c2-ssrf-to-rce

This is a modified version of the CVE-2024-41570 SSRF PoC from @chebuya chained with the auth RCE exploit from @hyperreality. This exploit executes…

command-and-controlexploitationpenetration-testing+3
91 year ago
CVE-2021-40444-POC preview

CVE-2021-40444-POC

GitHubkagura-maru/cve-2021-40444-poc

An attempt to reproduce Microsoft MSHTML Remote Code Execution (RCE) Vulnerability and using Metasploit Framework.

command-and-controlexploitationexploit-frameworks+4
104 years ago
CVE-2019-19609 preview

CVE-2019-19609

GitHubebadfd/cve-2019-19609

Strapi Framework Vulnerable to Remote Code Execution

exploitationpayload-developmentpenetration-testing+2
75 years ago
CVE-2026-60206-PoC-Exploit preview

CVE-2026-60206-PoC-Exploit

GitHubtc4dy/cve-2026-60206-poc-exploit

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

authentication-authorizationexploitationexploit-frameworks+8
41 month ago
CVE-2026-47883 preview

CVE-2026-47883

GitHubdaehyuh/cve-2026-47883

Minimal proof-of-concept for Spring Framework UrlHandlerFilter open redirect (CVE-2026-47883), demonstrating crafted double-slash requests produce…

exploitationvulnerability-analysisweb-application-exploitation+1
24 days ago
Project-CVE-2026-75604 preview

Project-CVE-2026-75604

GitHube4zyy/project-cve-2026-75604

Python-based exploitation framework for CVE-2026-75604, enabling authorized pentesters to validate Next.js Windows cache traversal vulnerabilities…

exploitationpayload-developmentpenetration-testing+4
218 days ago
Spring4Shell preview

Spring4Shell

GitHubloneyers/spring4shell

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

api-security-testingexploitationpenetration-testing+3
44 years ago
AEMPWN preview

AEMPWN

GitHubzoomdbz/aempwn

CVE-2025-54253 | CVE-2025-54254 | Adobe Experience Manager Forms XXE → RCE Framework

exploitationpayload-developmentpenetration-testing+3
47 months ago
CVE-2024-41570-Havoc-C2-RCE preview

CVE-2024-41570-Havoc-C2-RCE

GitHubleo-mitch/cve-2024-41570-havoc-c2-rce

This is a Chained RCE in the Havoc C2 framework using github.com/chebuya and github.com/IncludeSecurity pocs

command-and-controlexploitationpenetration-testing+3
31 year ago
CVE-2025-29972 preview

CVE-2025-29972

GitHubthemehackers/cve-2025-29972

CVE-2025-29927 is a critical security vulnerability affecting Next.js, a popular React framework for building full-stack web applications. This flaw…

authentication-authorizationexploitationpenetration-testing+2
21 year ago
CVE-2026-21628_PoC preview

CVE-2026-21628_PoC

GitHubchiefyoru/cve-2026-21628_poc

Unauthenticated Remote Code Execution in Astroid Framework 2.0.0 - 3.3.10 for Joomla

exploitationpenetration-testingremote-access-tool+2
1 month ago
Previous1…111213…17Next