Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
122 results
CVE-2015-8562 preview

CVE-2015-8562

GitHubparalelo14/cve-2015-8562

Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header

exploitationpayload-generationpenetration-testing+3
4
9 years ago
Apache-Log4j-POC preview

Apache-Log4j-POC

GitHubbadb33f/apache-log4j-poc

Proof of Concept of apache log4j LDAP lookup vulnerability. CVE-2021-44228

command-and-controlexploitationpayload-generation+2
34 years ago
CVE-2020-27603-bbb-libreoffice-poc preview

CVE-2020-27603-bbb-libreoffice-poc

GitHubhannob/cve-2020-27603-bbb-libreoffice-poc

Proof of Concept of Libreoffice file exfiltration vulnerability in Big Blue Button

data-exfiltrationexploitationpenetration-testing+2
31 year ago
CVE-2022-22965-PoC_Payara preview

CVE-2022-22965-PoC_Payara

GitHubcalumhutton/cve-2022-22965-poc_payara

Proof-of-concept exploit for CVE-2022-22965 in Payara/Glassfish, demonstrating arbitrary file download via web root manipulation. Includes Docker…

exploitationpayload-developmentpenetration-testing+2
34 years ago
Webmin_CVE-2019-15107 preview

Webmin_CVE-2019-15107

GitHubsquid22/webmin_cve-2019-15107

CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920

exploitationpenetration-testingremote-access-tool+2
35 years ago
Zimbra-Valid-Login-Checker preview

Zimbra-Valid-Login-Checker

GitHubjenderal92/zimbra-valid-login-checker

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

authenticationpassword-attackspenetration-testing+2
13 months ago
CVE-2021-24647 preview

CVE-2021-24647

GitHubrandomrobbiebf/cve-2021-24647

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

authenticationexploitationpenetration-testing+2
13 years ago
Commvault-CVE-2025-34028 preview

Commvault-CVE-2025-34028

GitHubbecrevex/commvault-cve-2025-34028

Commvault Remote Code Execution (CVE-2025-34028) NSE

exploitationpenetration-testingremote-access-tool+2
11 year ago
cve-2020-10977-read-and-execute preview

cve-2020-10977-read-and-execute

GitHublisp3r/cve-2020-10977-read-and-execute

cve-2020-10977 read and execute

exploitationpayload-generationpenetration-testing+2
15 years ago
Exploit-CSRF-on-SCOPIA-XT-Desktop-version-8.3.915.4 preview

Exploit-CSRF-on-SCOPIA-XT-Desktop-version-8.3.915.4

GitHubv1n1v131r4/exploit-csrf-on-scopia-xt-desktop-version-8.3.915.4

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

exploitationpenetration-testingvulnerability-analysis+2
15 years ago
CVE-2025-29927-Nextjs-Bypass-PoC preview

CVE-2025-29927-Nextjs-Bypass-PoC

GitHubdanielhallbro/cve-2025-29927-nextjs-bypass-poc

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

authenticationeducationexploitation+3
17 months ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubtvdat20004/cve-2020-0688

CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2025-5095-POC preview

CVE-2025-5095-POC

GitHubteteuxd2/cve-2025-5095-poc

Python POC for CVE-2025-5095

exploitationpassword-attackspenetration-testing+2
11 months ago
activemq-cve-2023-46604 preview

activemq-cve-2023-46604

GitHubtomasmussi/activemq-cve-2023-46604

Repository to exploit CVE-2023-46604 reported for ActiveMQ

educationexploitationpayload-generation+3
1 year ago
learning-management-system preview

learning-management-system

GitHubrandomrobbiebf/learning-management-system

Masteriyo - LMS for WordPress <= 1.6.7 - Sensitive Information Exposure

data-exfiltrationexploitationinformation-gathering+2
3 years ago
CVE-2022-29856-PoC preview

CVE-2022-29856-PoC

GitHubflo451/cve-2022-29856-poc

Minimal PoC for CVE-2022-29856

exploitationinformation-gatheringpenetration-testing+2
3 years ago
CVE-2018-20250 preview

CVE-2018-20250

GitHubtzwlhack/cve-2018-20250

Automated exploit script for CVE-2018-20250 (WinRAR ACE extraction code execution) that generates a malicious archive file embedding a payload into…

exploitationpayload-generationpenetration-testing+3
4 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubjoojiii/cve-2025-29927

Proof-of-concept exploit for CVE-2025-29927 in Next.js 15.2.0, demonstrating a specific web application vulnerability for testing and educational…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
Previous1234567Next