Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
CVE-2026-999999 preview

CVE-2026-999999

GitHub24520597-blip/cve-2026-999999

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

educationexploitationpenetration-testing+3
4 months ago
POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0 preview

POC_SQL_injection_in_Parse_Server_prior_6.5.7_-_7.1.0

GitHubheavyghost-le/poc_sql_injection_in_parse_server_prior_6.5.7_-_7.1.0

Advanced PostgreSQL database enumeration tool exploiting CVE-2024-39309 in Parse Server - Comprehensive SQL injection exploitation for security…

database-securityexploitationinformation-gathering+3
11 year ago
CVE-2025-55315 preview

CVE-2025-55315

GitHubmartinfabianionut/cve-2025-55315

Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle…

educationexploitationpenetration-testing+3
110 months ago
CVE-2024-58258 preview

CVE-2024-58258

GitHubweb3-serializer/cve-2024-58258

Proof‑of‑concept for CVE‑2024‑58258, a SugarCRM (<13.0.4 / <14.0.1) flaw where user input is parsed as LESS in /css/preview, allowing unauthenticated…

educationexploitationpenetration-testing+2
110 months ago
CVE-2025-49844 preview

CVE-2025-49844

GitHubelyasbassir/cve-2025-49844

Exploit script for CVE-2025-49844, a use-after-free vulnerability in Redis Lua parser, enabling remote code execution on vulnerable Redis servers.

command-and-controlexploitationremote-access-trojan+2
11 months ago
CVE-2020-13756-env preview

CVE-2020-13756-env

GitHubkre80r/cve-2020-13756-env

Vulnerable test environment for CVE-2020-13756 (Sabberworm PHP CSS Parser RCE)

educationexploitationlabs-practice+3
10 months ago
CVE-2023-20052 preview

CVE-2023-20052

GitHubcy83rr0h1t/cve-2023-20052

CVE-2023-20052 information leak vulnerability in the DMG file parser of ClamAV

exploitationinformation-gatheringmalware-analysis+2
3 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubcc3305/cve-2024-23897

Exploit script for CVE-2024-23897, leveraging Jenkins CLI command parser misconfiguration to read arbitrary files on unpatched Jenkins controllers…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubdbgee/cve-2021-44228

Apache Log4j 2 a remote code execution vulnerability via the ldap JNDI parser.

exploitationpayload-developmentremote-access-tool+2
4 years ago
CVE-2016-4437 preview

CVE-2016-4437

GitHubm3terpreter/cve-2016-4437

Proof-of-concept exploit for CVE-2016-4437, an Apache Struts2 remote code execution vulnerability. Demonstrates exploitation of the Jakarta Multipart…

exploitationvulnerability-analysisweb-application-exploitation
5 years ago
splitting-the-email-atom preview

splitting-the-email-atom

GitHubportswigger/splitting-the-email-atom

Research materials and tooling for exploiting email address parser discrepancies to bypass access controls, including fuzzers, Hackvertor tags, CSS…

ctfeducationemail-security+7
9910 months ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubh4x0r-dz/cve-2024-23897

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

exploitationinformation-gatheringpenetration-testing+3
2092 years ago
CVE-2024-32640-SQLI-MuraCMS preview

CVE-2024-32640-SQLI-MuraCMS

GitHubstuub/cve-2024-32640-sqli-muracms

CVE-2024-32640 | Automated SQLi Exploitation PoC

exploitationpenetration-testingvulnerability-analysis+1
792 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubwin3zz/cve-2017-5638

Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script

exploitationpenetration-testingremote-access-tool+2
168 years ago
CVE-2013-2028-Exploit preview

CVE-2013-2028-Exploit

GitHubm4drat/cve-2013-2028-exploit

CVE-2013-2028 python exploit

binary-exploitationexploitationpayload-development+4
196 years ago
Joomla-JCK-Editor-6.4.4-SQL-Injection preview

Joomla-JCK-Editor-6.4.4-SQL-Injection

GitHubnickguitar/joomla-jck-editor-6.4.4-sql-injection

Exploit for Joomla JCK Editor 6.4.4 (CVE-2018-17254)

exploitationpayload-generationpenetration-testing+2
105 years ago
CVE-2018-11761 preview

CVE-2018-11761

GitHubbrianwrf/cve-2018-11761

Apache Tika Denial of Service Vulnerability (CVE-2018-11761)

educationexploitationpenetration-testing+2
97 years ago
Roundcube-CVE-2025-49113 preview

Roundcube-CVE-2025-49113

GitHubbiitts/roundcube-cve-2025-49113

Proof-of-concept to CVE-2025-49113

exploitationpayload-developmentpenetration-testing+3
61 year ago
Previous123Next