Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
CVE-2022-0739 preview

CVE-2022-0739

GitHubelganz0/cve-2022-0739

BookingPress < 1.0.11 - Unauthenticated SQL Injection

exploitationinformation-gatheringpenetration-testing+2
3 years ago
CVE-2021-40222 preview

CVE-2021-40222

GitHubasang17/cve-2021-40222

Remote Code Execution at Rittal

command-and-controlexploitationpenetration-testing+3
4 years ago
name_reverser preview

name_reverser

GitHubterracatta/name_reverser

Silly Rails App to demonstrate vuln CVE-2013-0156

educationexploitationpenetration-testing+2
13 years ago
CVE-2025-5880 preview

CVE-2025-5880

GitHubac8999/cve-2025-5880

PoC for a Path Traversal vulnerability in Whistle v2.9.98 via the /cgi-bin/sessions/get-temp-file endpoint. (Unpatched)

exploitationvulnerability-analysisweb-application-exploitation
2 days ago
CVE-2025-7840 preview
Archived

CVE-2025-7840

GitHubbytereaper77/cve-2025-7840

Proof‑of‑concept exploit for CVE‑2025‑7840 that injects malicious payloads into the Firstname parameter of a reservation form to trigger XSS

educationexploitationpayload-generation+3
21 year ago
2017-11882_Generator preview

2017-11882_Generator

GitHubblackmathit/2017-11882_generator

CVE-2017-11882 File Generator PoC

educationexploitationpayload-generation+2
348 years ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubmrtiz/cve-2020-0688

Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys

educationexploitationpayload-development+3
215 years ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
23 days ago
bitbucket-test preview

bitbucket-test

GitHubjohangabrielson/bitbucket-test

Investigating CVE-2022-36804

educationexploitationlabs-practice+3
4 months ago
CVE-2026-7222-XSS preview

CVE-2026-7222-XSS

GitHubxmyronn/cve-2026-7222-xss
educationexploitationpenetration-testing+3
3 months ago
CVE-2025-15556-Notepad-WinGUp-Updater-RCE preview

CVE-2025-15556-Notepad-WinGUp-Updater-RCE

GitHubgeorge0papasotiriou/cve-2025-15556-notepad-wingup-updater-rce
educationexploitationpenetration-testing+3
16 months ago
CVE-2021-40223 preview

CVE-2021-40223

GitHubasang17/cve-2021-40223

XSS Vulnerability in Rittal

educationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2019-5420 preview

CVE-2019-5420

GitHubpentestical/cve-2019-5420

Exploit in Rails Development Mode. With some knowledge of a target application it is possible for an attacker to guess the automatically generated…

exploitationpenetration-testingred-teaming+2
4 years ago
rails-exploit-cve-2013-0156 preview

rails-exploit-cve-2013-0156

GitHubbsodmike/rails-exploit-cve-2013-0156

Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156

educationexploitationpenetration-testing+2
513 years ago
CVE-2020-8163 preview

CVE-2020-8163

GitHublucasamorimca/cve-2020-8163

CVE-2020-8163 - Remote code execution of user-provided local names in Rails

educationexploitationlabs-practice+2
603 years ago
CVE-2024-46987 preview

CVE-2024-46987

GitHubadvaitpathak21/cve-2024-46987

Exploit created using Python

educationexploitationinformation-gathering+3
16 months ago
Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE preview

Alternative-Approach-Reverse-Shell-Callback-Test-InvokeAI-RCE

GitHublu3ky13/alternative-approach-reverse-shell-callback-test-invokeai-rce

This repository contains alternative payload approaches for the InvokeAI RCE vulnerability (CVE-2024-12029) when SSH key injection fails. The…

command-and-controleducationexploitation+5
4 months ago
CVE-2026-66066-POC preview

CVE-2026-66066-POC

GitHubzer0sumgam3/cve-2026-66066-poc

PoC for CVE-2026-66066 in Ruby on Rails

educationexploitationlabs-practice+3
2321 days ago
Previous12345Next