Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
299 results
CVE-2022-22965-Spring4Shell preview

CVE-2022-22965-Spring4Shell

GitHubkuri119/cve-2022-22965-spring4shell

Exploit for CVE-2022-22965 (Spring4Shell) enabling remote code execution on unpatched Spring Framework applications via crafted HTTP requests.

exploitationpayload-developmentpenetration-testing+2
2 months ago
pythia-sql-clairvoyance preview

pythia-sql-clairvoyance

GitHubrodhnin/pythia-sql-clairvoyance

Advanced SQL Injection Scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlerdevsecops+5
24 months ago
CVE-2024-38821-POC preview

CVE-2024-38821-POC

GitHubmasa42/cve-2024-38821-poc

Proof-of-concept exploit for CVE-2024-38821, demonstrating authentication bypass in Spring Framework via path traversal to access restricted…

authentication-authorizationeducationexploitation+3
11 year ago
EpSiLoNPoInT- preview

EpSiLoNPoInT-

GitHubepsilonpoint88-glitch/epsilonpoint-

Modular exploit framework targeting CVE-2026-23550 in WordPress, featuring mass exploitation, obfuscation, post-exploitation, and Docker-based C2…

command-and-controlexploitationpayload-development+7
17 months ago
CVE-2018-14667 preview

CVE-2018-14667

GitHubr00t4dm/cve-2018-14667

about CVE-2018-14667 from RichFaces Framework 3.3.4

exploitationpayload-developmentpenetration-testing+2
17 years ago
CVE-2021-38314 preview

CVE-2021-38314

GitHub0xgabe/cve-2021-38314

Exploit in python3 to explore CVE-2021-38314 in Redux Framework a wordpress plugin

exploitationpenetration-testingreconnaissance+2
13 years ago
CVE-2025-10351-POC preview

CVE-2025-10351-POC

GitHubivansmc/cve-2025-10351-poc

Exploit for CVE-2025-10351. SQL Injection on Melis Platform Framework

database-securityexploitationinformation-gathering+3
17 months ago
CVE-2025-10352-POC preview

CVE-2025-10352-POC

GitHubivansmc/cve-2025-10352-poc

Exploit for CVE-2025-10352. Admin account creation on Melis Platform Framework

exploitationpenetration-testingred-teaming+2
111 months ago
CVE-2024-51996 preview

CVE-2024-51996

GitHubmoften/cve-2024-51996

CVE-2024-51996 es una vulnerabilidad crítica que afecta al componente security-http del framework Symfony.

authentication-authorizationexploitationpenetration-testing+3
11 year ago
CVE-2018-1270_EXP preview

CVE-2018-1270_EXP

GitHubtom4t0/cve-2018-1270_exp

Proof-of-concept exploit for CVE-2018-1270, a Spring Framework remote code execution vulnerability, demonstrating exploitation in Java.

exploitationpenetration-testingvulnerability-analysis+1
8 years ago
Letta-CVE-2025-51482-RCE preview

Letta-CVE-2025-51482-RCE

GitHubkai-one001/letta-cve-2025-51482-rce

Proof-of-concept exploit for CVE-2025-51482, demonstrating remote code execution via unsafe exec() usage and sandbox bypass in the Letta AI agent…

code-analysisexploitationpenetration-testing+3
11 year ago
CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit preview

CTT-Serverless-RCE-v1.0---Convergent-Time-Theory-Enhanced-MCP-Exploit

GitHubsimoesctt/ctt-serverless-rce-v1.0---convergent-time-theory-enhanced-mcp-exploit

Serverless Framework MCP Server (CVE-2025-69256) Base Score: 9.4/10 → CTT Enhanced Score: 9.9/10 A critical command injection vulnerability in…

ai-securitycloud-securitycommand-and-control+8
7 months ago
Spring4Shell-CVE-2022-22965-Exploitation-Attempt preview

Spring4Shell-CVE-2022-22965-Exploitation-Attempt

GitHubaditidutta696-dev/spring4shell-cve-2022-22965-exploitation-attempt

Exploit attempt for CVE-2022-22965 (Spring4Shell) targeting Spring Framework applications for remote code execution.

exploitationpayload-developmentpenetration-testing+2
7 months ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubethan-repo-lab4b6/cve-2022-36537

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

authentication-authorizationexploitationinformation-gathering+3
3 years ago
CVE-2022-22965_PoC preview

CVE-2022-22965_PoC

GitHubc4mx/cve-2022-22965_poc

Proof-of-concept exploit for CVE-2022-22965 (Spring4Shell) targeting Java Spring Framework applications via crafted HTTP requests.

code-analysisexploitationpenetration-testing+2
14 years ago
CVE-2025-59057-PoC preview

CVE-2025-59057-PoC

GitHubboroeurnprach/cve-2025-59057-poc

A XSS vulnerability exists in in React Router's meta()/<Meta> APIs in Framework Mode when generating script:ld+json tags which could allow arbitrary…

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla preview

CVE-2026-21627---Tassos-Novarain-Framework-plg_system_nrframework-Exploit---Joomla

GitHubyallasec/cve-2026-21627---tassos-novarain-framework-plg_system_nrframework-exploit---joomla

Python exploit for CVE-2026-21627, an unauthenticated arbitrary PHP file inclusion in Joomla's Novarain Framework, enabling file upload, delete, and…

exploitationpayload-developmentpenetration-testing+3
6 months ago
CVE-2025-64328_FreePBX-framework-Command-Injection preview

CVE-2025-64328_FreePBX-framework-Command-Injection

GitHubmcorybillington/cve-2025-64328_freepbx-framework-command-injection

CVE-2025-64328 FreePBX Authenticated Command Injection in the framework module.

command-and-controlexploitationpenetration-testing+2
10 months ago
Previous1…121314…17Next