Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
7427 results
dotnetpaddingoracle preview

dotnetpaddingoracle

GitHubnccgroup/dotnetpaddingoracle

Python Implementation of a .NET Padding Oracle Assessment Tool

cryptographyencryption-decryption-toolsexploitation+3
31
10 years ago
CVE-2023-42793-TeamCity-Unauthenticated-RCE preview

CVE-2023-42793-TeamCity-Unauthenticated-RCE

GitHubburakacar6/cve-2023-42793-teamcity-unauthenticated-rce

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

authenticationexploitationpenetration-testing+3
10 days ago
CVE-2022-46364-Proof-of-the-concept preview

CVE-2022-46364-Proof-of-the-concept

GitHubcybermaksx/cve-2022-46364-proof-of-the-concept

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

educationexploitationinformation-gathering+3
35 months ago
CVE-2019-19654 preview

CVE-2019-19654

GitHubjra89/cve-2019-19654

Proof-of-concept exploit for CVE-2019-19654: Chevereto denial of service via path traversal in the bulk importer, allowing authenticated admin to…

exploitationpenetration-testingvulnerability-analysis+1
6 years ago
vuln-chm-hijack preview

vuln-chm-hijack

GitHubyasinyilmaz/vuln-chm-hijack

Potential malicious code execution via CHM hijacking (CVE-2019-9896)

educationexploitationlabs-practice+3
77 years ago
CVE-2026-2472-Vertex-AI-SDK-Google-Cloud preview

CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

GitHubmegafart1/cve-2026-2472-vertex-ai-sdk-google-cloud

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

ai-securitycloud-securityeducation+3
27 hours ago
CVE-2024-24919-Exploit preview

CVE-2024-24919-Exploit

GitHubmr-kasim-mehar/cve-2024-24919-exploit

Java-based scanner that checks IP addresses for CVE-2024-24919 vulnerability, with interactive options to print response data and change target file…

exploitationpenetration-testingreconnaissance+2
12 years ago
CVE-2021-41349 preview

CVE-2021-41349

GitHubexploit-io/cve-2021-41349

Exploit tool for CVE-2021-41349 that generates an HTML form to deliver XSS payloads to Microsoft Exchange servers, enabling execution of arbitrary…

exploitationpayload-generationvulnerability-analysis+2
114 years ago
CVE-2026-10580 preview

CVE-2026-10580

GitHub0xgh057r3c0n/cve-2026-10580

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

authentication-authorizationeducationexploitation+4
2 months ago
CVE-2019-9053-python3-remastered preview

CVE-2019-9053-python3-remastered

GitHubteymurnovruzov/cve-2019-9053-python3-remastered

The script has been remastered by Teymur Novruzov to ensure compatibility with Python 3. This tool is intended for educational purposes only.…

educationinformation-gatheringpassword-cracking+2
12 years ago
poc-cve-2026-32255 preview

poc-cve-2026-32255

GitHubkoadt/poc-cve-2026-32255

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

educationexploitationpenetration-testing+3
26 months ago
CVE-2021-23639 preview

CVE-2021-23639

GitHubmohandacherir/cve-2021-23639

Exploit of CVE-2021-23639 for the vulnerable library 'md-to-pdf' in JS

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2023-22518 preview

CVE-2023-22518

GitHubrevoltsecurities/cve-2023-22518

An Exploitation tool to exploit the confluence server that are vulnerable to CVE-2023-22518 Improper Authorization

exploitationinformation-gatheringpenetration-testing+2
432 years ago
CVE-2026-2256-PoC preview

CVE-2026-2256-PoC

GitHubitamar-yochpaz/cve-2026-2256-poc

Proof-of-concept demonstrating a command injection vulnerability in MS-Agent Shell tool, enabling arbitrary command execution and reverse shell via…

command-and-controlexploitationpenetration-testing+2
27 months ago
CVE-2024-3273-EXPLOIT preview

CVE-2024-3273-EXPLOIT

GitHubk3ystr0k3r/cve-2024-3273-exploit

A PoC exploit for CVE-2024-3273 - D-Link Remote Code Execution RCE

command-and-controlexploitationpenetration-testing+3
52 years ago
CVE-2026-8347 preview

CVE-2026-8347

GitHubaj2108/cve-2026-8347

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0…

authentication-authorizationvulnerability-analysisweb-application-exploitation+1
1 month ago
edb-49263-fixed preview

edb-49263-fixed

GitHubxenophil90/edb-49263-fixed

Fixed version of the Python script to exploit CVE-2018-19571 and CVE-2018-19585 (GitLab 11.4.7 - Authenticated Remote Code Execution) that is…

exploitationpenetration-testingremote-access-tool+2
5 years ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubjayngng/cve-2021-22911

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

authentication-authorizationexploitationpassword-attacks+2
4 years ago
Previous1…345…100Next