Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
CVE-2026-75604-poc preview

CVE-2026-75604-poc

GitHubrafabd1/cve-2026-75604-poc

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated remote code execution in Windows-hosted Next.js apps, with callback-based command…

exploitationpenetration-testingremote-access-trojan+2
82
9 days ago
poc-CVE-2026-0073 preview

poc-CVE-2026-0073

GitHubadityatelange/poc-cve-2026-0073

CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC

android-securityexploitationmobile-security+3
654 months ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubp1ckzi/cve-2022-22965

spring4shell | CVE-2022-22965

exploitationpayload-generationpenetration-testing+3
234 years ago
IPFire_2.19_RCE_Authenticated preview

IPFire_2.19_RCE_Authenticated

GitHubjoaoaugustom/ipfire_2.19_rce_authenticated

This exploit is based on CVE-2017-9757 and was built upon the original exploit by 0x09AL.

educationexploitationpenetration-testing+2
129 days ago
CVE-2025-54236 preview

CVE-2025-54236

GitHubdx3iz/cve-2025-54236

Adobe Magento SessionReaper LFI Vulnerability

educationexploitationpenetration-testing+2
2 months ago
CVE-2019-9053 preview

CVE-2019-9053

GitHubquliyevresul7777/cve-2019-9053

Exploit Title: Unauthenticated SQL Injection on CMS Made Simple <= 2.2.9

exploitationpenetration-testingvulnerability-analysis+1
115 days ago
CVE-2026-75604 preview

CVE-2026-75604

GitHubhackspeak/cve-2026-75604

Proof-of-concept exploit for CVE-2026-75604, an unauthenticated RCE in Windows-hosted Next.js via cache path traversal and forged Server Action, for…

educationexploitationpenetration-testing+3
111 days ago
CVE-2023-4861-PoC preview

CVE-2023-4861-PoC

GitHubnoambouillet/cve-2023-4861-poc

Automated proof-of-concept for authenticated remote code execution in WordPress File Manager Pro (Filester) via arbitrary file upload, including…

exploitationpayload-developmentpenetration-testing+2
22 months ago
CVE-2023-46604-RCE preview

CVE-2023-46604-RCE

GitHubreggyraider/cve-2023-46604-rce

CVE-2023-46604-RCE exploit with Linux reverse shell payload

exploitationpayload-generationremote-access-tool+3
3 months ago
cve-2023-38831 preview

cve-2023-38831

GitHubkuyrathdaro/cve-2023-38831

CVE-2023-38831 (PoC) - WinRAR Exploit

educationexploitationpayload-generation+3
31 year ago
CVE-2022-0169 preview

CVE-2022-0169

GitHubx3rx3ssec/cve-2022-0169

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

educationexploitationinformation-gathering+3
31 year ago
CVE-2025-57819_FreePBX preview

CVE-2025-57819_FreePBX

GitHuborange0mint/cve-2025-57819_freepbx

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

educationexploitationinformation-gathering+4
211 months ago
CVE-2025-6440 preview

CVE-2025-6440

GitHubsahmsec/cve-2025-6440

CVE-2025-6440

code-analysiseducationexploitation+4
14 months ago
CVE-2025-39459 preview

CVE-2025-39459

GitHubthebl4ckph4nt0m/cve-2025-39459

Unauthenticated Privilege Escalation

educationexploitationpenetration-testing+4
16 months ago
CVE-2025-39459 preview

CVE-2025-39459

GitHubnxploited/cve-2025-39459

Real Estate 7 <= 3.5.2 - Unauthenticated Privilege Escalation

educationexploitationpenetration-testing+3
16 months ago
CVE-2025-8110-PoC preview

CVE-2025-8110-PoC

GitHubmananispiwpiw/cve-2025-8110-poc

One-shot exploit for Gogs symlink RCE (CVE-2025-8110) that triggers a reverse shell via a single PUT request to UpdateRepoFile.

exploitationpenetration-testingred-teaming+3
3 months ago
Drupal_REST-RCE_Unauthenticated preview

Drupal_REST-RCE_Unauthenticated

GitHubjoaoaugustom/drupal_rest-rce_unauthenticated

This exploit is based on CVE-2019-6340 and was built upon the original exploit by leonjza and the Metasploit module, extending it can be executed…

ctfeducationexploitation+3
3 months ago
CVE-2024-34070 preview

CVE-2024-34070

GitHubokymi-x/cve-2024-34070

Proof-of-concept exploit for CVE-2024-34070, a stored XSS in Froxlor. Detects vulnerable instances, extracts version, and injects payload to create…

ctfeducationexploitation+3
3 months ago
Previous1…345…100Next