Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
CVE-2023-38035-MobileIron-RCE preview

CVE-2023-38035-MobileIron-RCE

GitHubmind2hex/cve-2023-38035-mobileiron-rce

Script to exploit CVE-2023-38035

exploitationpenetration-testingreconnaissance+3
1
3 years ago
CVE-2021-31761 preview

CVE-2021-31761

GitHubmesh3l911/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

exploitationpenetration-testingremote-access-tool+2
55 years ago
ShatteredFTP preview

ShatteredFTP

GitHubghostsec420/shatteredftp

Shattered is a tool and POC for the new CrushedFTP vulns, CVE Exploit Script: CVE-2025-2825 vs CVE-2025-31161

exploitationpayload-developmentpenetration-testing+3
131 year ago
G0BurpSQLmaPI preview

G0BurpSQLmaPI

GitHubnu11secur1ty/g0burpsqlmapi

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

exploitationpayload-generationpenetration-testing+2
31 month ago
Nextjs_Exploit_Tool preview

Nextjs_Exploit_Tool

GitHubse1zer/nextjs_exploit_tool

Next.js RSC RCE Exploit Tool (CVE-2025-55182)

command-and-controlexploitationpayload-generation+5
51 month ago
Gitea-Forgejo-CVE-2025-68937 preview

Gitea-Forgejo-CVE-2025-68937

GitHubclemax/gitea-forgejo-cve-2025-68937

Directory traversal in Gitea and Forgejo's repository‑template processing allows remote authenticated attackers to process arbitrary files on the…

educationexploitationpenetration-testing+3
6 months ago
CVE-2022-41853 preview

CVE-2022-41853

GitHubmbadanoiu/cve-2022-41853

Research into CVE-2022-41853: Using static functions to obtian RCE via Java Deserialization & Remote Codebase Attack

exploitationpayload-developmentvulnerability-analysis+1
22 years ago
HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892 preview

HTTP-Request-for-PHP-object-injection-attack-on-CVE-2023-41892

GitHubcertologists/http-request-for-php-object-injection-attack-on-cve-2023-41892

Demonstrates a PHP object injection attack targeting CVE-2023-41892, including exploitation techniques and mitigation strategies for securing PHP…

code-analysiseducationexploitation+2
2 years ago
CVE-2025-12137 preview

CVE-2025-12137

GitHubjfriedli/cve-2025-12137

Proof-of-concept exploit for CVE-2025-12137 demonstrating local file disclosure via a WordPress plugin's REST API importer endpoint. Includes…

data-exfiltrationexploitationinformation-gathering+3
5 months ago
CVE-2023-49103 preview

CVE-2023-49103

GitHubcreacitysec/cve-2023-49103

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

educationexploitationpenetration-testing+2
302 years ago
CVE-2022-42889-Text4Shell-POC preview

CVE-2022-42889-Text4Shell-POC

GitHubalealeluyah/cve-2022-42889-text4shell-poc

This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id:…

exploitationpayload-generationpenetration-testing+2
133 years ago
TProxer preview

TProxer

GitHubethicalhackingplayground/tproxer

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

api-security-testingpenetration-testingvulnerability-analysis+2
1844 years ago
CVE-2026-21636 preview

CVE-2026-21636

GitHubpauldechassey/cve-2026-21636

Proof-of-concept demonstrating a Node.js permission model bypass (CVE-2026-21636) that allows network access via undici/fetch to local services,…

container-securityexploitationpenetration-testing+3
4 months ago
ghauri preview

ghauri

GitHubr0oth3x49/ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

database-securitypenetration-testingvulnerability-scanners+2
4.1k11 months ago
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
3251 month ago
PhEmail preview

PhEmail

GitHubdionach/phemail

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

email-harvestinginformation-gatheringosint+4
3496 years ago
POC-for-CVE-2023-41993 preview

POC-for-CVE-2023-41993

GitHubpo6ix/poc-for-cve-2023-41993

Proof-of-concept exploit for CVE-2023-41993, a WebKit JIT type confusion in Safari. Provides addrof/fakeobj primitives via heap manipulation and…

binary-exploitationexploitationpayload-development+2
2022 years ago
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

api-securityapi-security-testingcrawler+12
38.4k2 days ago
Previous123456Next