Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
150 results
CVE-2019-1367 preview

CVE-2019-1367

GitHubmandarenmanman/cve-2019-1367

CVE-2019-1367

educationexploitationprivilege-escalation+3
37 years ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubmracumen/cve-2021-40444

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

binary-analysisexploitationmalware-analysis+3
24 years ago
CVE-2021-21425-RCE preview

CVE-2021-21425-RCE

GitHubs1lentf00thold/cve-2021-21425-rce

Python exploit script for CVE-2021-21425 targeting Grav CMS admin panel, delivering a reverse shell via HTTP POST request with configurable LHOST and…

exploitationpayload-generationpenetration-testing+3
3 months ago
sap_igs_xxe preview

sap_igs_xxe

GitHubvladimir-ivanov-git/sap_igs_xxe

SAP IGS XXE attack CVE-2018-2392 and CVE-2018-2393

exploitationinformation-gatheringpenetration-testing+2
16 years ago
spring-shell-vuln preview

spring-shell-vuln

GitHubsnip3r69/spring-shell-vuln

Spring has Confirmed the RCE in Spring Framework. The team has just published the statement along with the mitigation guides for the issue. Now, this…

educationexploitationpenetration-testing+2
14 years ago
CVE-2021-3138 preview

CVE-2021-3138

GitHubmesh3l911/cve-2021-3138

Discource POC

authentication-authorizationexploitationpenetration-testing+2
15 years ago
angularjs-poc-cve-2022-25869 preview

angularjs-poc-cve-2022-25869

GitHubneverendingsupport/angularjs-poc-cve-2022-25869

A minimal reproduction of an AngularJS <textarea> XSS vulnerability on IE (tracked as CVE-2022-25869).

educationexploitationvulnerability-analysis+2
11 year ago
CVE-2023-20209 preview

CVE-2023-20209

GitHubpeter5he1by/cve-2023-20209

Detailed technical analysis and proof-of-concept exploit for CVE-2023-20209, a post-authentication remote code execution vulnerability in Cisco…

command-and-controlexploitationpenetration-testing+3
3 years ago
CVE-2017-7269 preview

CVE-2017-7269

GitHubvanishedpeople/cve-2017-7269

Python proof-of-concept for CVE-2017-7269, a buffer overflow in IIS 6.0 WebDAV, enabling remote code execution on Windows Server 2003 R2.

ctfexploitationpenetration-testing+2
2 years ago
Juiceshopgl preview

Juiceshopgl

GitLabmbrandner-group/juiceshopgl

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

ctfeducationlabs-practice+5
2 years ago
cve-2017-7269 preview

cve-2017-7269

GitHubhomjxi0e/cve-2017-7269

Exploit for CVE-2017-7269: buffer overflow in IIS 6.0 WebDAV service enabling remote code execution via crafted PROPFIND request.

exploitationpenetration-testingvulnerability-analysis+1
9 years ago
CVE-2021-40444 preview

CVE-2021-40444

GitHubtiagob0b/cve-2021-40444

Malicious DOCX generator exploiting CVE-2021-40444 (Microsoft Office Word RCE) with CAB-based DLL side-loading and CAB-less RAR/WSF attack chains for…

binary-exploitationexploitationpayload-generation+3
4 years ago
CVE-2017-1000486 preview

CVE-2017-1000486

GitHublongwayhomie/cve-2017-1000486

Remote Code Execution exploit for PrimeFaces 5.x - EL Injection (CVE-2017-1000486)

exploitationpayload-generationpenetration-testing+2
2 years ago
Symfony-CVE-Scanner-PoC- preview

Symfony-CVE-Scanner-PoC-

GitHubmoften/symfony-cve-scanner-poc-

CVE-2021-21424 - CRLF Injection - CVE-2021-41268 - Host Header Injection - CVE-2022-24894 - WebProfiler abierto - CVE-2019-10909 - Directory Traversal

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2018-9995_dvr_credentials preview

CVE-2018-9995_dvr_credentials

GitHubezelf/cve-2018-9995_dvr_credentials

(CVE-2018-9995) Get DVR Credentials

exploitationiot-securitypassword-attacks+3
5598 years ago
Xiaomi_Mi_WiFi_R3G_Vulnerability_POC preview

Xiaomi_Mi_WiFi_R3G_Vulnerability_POC

GitHubultramangaia/xiaomi_mi_wifi_r3g_vulnerability_poc

A login bypass(CVE-2019-18371) and a command injection vulnerability(CVE-2019-18370) in Xiaomi Router R3G up to version 2.28.23.

exploitationiot-securitypenetration-testing+2
1866 years ago
CVE-2021-36260 preview

CVE-2021-36260

GitHubcuerz/cve-2021-36260

海康威视RCE漏洞 批量检测和利用工具

exploitationiot-securitypenetration-testing+3
1704 years ago
DVR-Exploiter preview

DVR-Exploiter

GitHubcyb0r9/dvr-exploiter

Bash script exploiting CVE-2018-9995 to extract credentials from vulnerable DVRs via web interface, supporting multiple DVR brands for automated…

exploitationiot-securityvulnerability-analysis+1
1128 years ago
Previous1234…9Next