Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
257 results
cve-2021-45232-exp preview

cve-2021-45232-exp

GitHubwuppp/cve-2021-45232-exp

Exploit for CVE-2021-45232 targeting Apache APISIX Dashboard remote code execution vulnerability. Provides proof-of-concept for security testing and…

api-securityexploitationpenetration-testing+2
78
4 years ago
CVE-2020-16947 preview

CVE-2020-16947

GitHub0neb1n/cve-2020-16947

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

binary-exploitationemail-securityexploitation+3
1225 years ago
CVE-2022-1388_PoC preview

CVE-2022-1388_PoC

GitHubalt3kx/cve-2022-1388_poc

F5 BIG-IP RCE exploitation (CVE-2022-1388)

api-securityauthenticationexploitation+3
874 years ago
snuck preview

snuck

GitHubmauro-g/snuck

Automatic XSS filter bypass

fuzzingpenetration-testingwaf-bypass+2
9011 years ago
sign-saboteur preview

sign-saboteur

GitHubd0ge/sign-saboteur

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

authentication-authorizationcryptographyfuzzing+7
1721 year ago
Research_Successful_Errors preview

Research_Successful_Errors

GitHubvladko312/research_successful_errors

Whitepaper introducing Error-Based and Boolean Error-Based Blind techniques for SSTI and Code Injection, with universal payloads for six programming…

code-analysisctfeducation+6
1247 months ago
ZIPFileRaider preview

ZIPFileRaider

GitHubdestine21/zipfileraider

ZIP File Raider - Burp Extension for ZIP File Payload Testing

fuzzingpayload-generationpenetration-testing+2
716 years ago
SpringBoot_Actuator_RCE preview

SpringBoot_Actuator_RCE

GitHubjas502n/springboot_actuator_rce

SpringBoot_Actuator_RCE

api-securityexploitationmisconfiguration+3
956 years ago
jenkins-cve-2016-0792 preview

jenkins-cve-2016-0792

GitHubjpiechowka/jenkins-cve-2016-0792

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

code-analysisdynamic-code-analysisexploitation+3
479 years ago
PoC preview

PoC

GitHubnickstadb/poc

Repo for proof of concept exploits and tools.

exploitationpenetration-testingvulnerability-analysis+1
545 years ago
joro preview

joro

GitHubbishopfox/joro

A collaborative web exploitation framework.

command-and-controlexploit-frameworksfuzzing+5
485 days ago
wordpress-hacking preview

wordpress-hacking

GitHubstealthcopter/wordpress-hacking

A collection of useful resources for hacking WordPress and it's plugins and themes

curated-resourcesdynamic-code-analysisexploitation+4
896 months ago
NebulaPulsar preview

NebulaPulsar

GitHubiss4cf0ng/nebulapulsar

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

dynamic-code-analysiseducationencryption-decryption-tools+7
462 months ago
My-CVEs preview

My-CVEs

GitHubsilverplate3/my-cves

CVE's I found. technical writeups, expolitation examples and fuzzing sessions walkthroughs

ai-assisted-reversingbinary-analysiscode-analysis+8
569 months ago
CVE-2013-2729 preview

CVE-2013-2729

GitHubfeliam/cve-2013-2729

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

binary-exploitationexploitationfuzzing+3
246 years ago
Payload-and-Polyglot-Lists preview

Payload-and-Polyglot-Lists

GitHubgromhacks/payload-and-polyglot-lists

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

educationfuzzingosint+4
385 months ago
CVE-2021-21017 preview

CVE-2021-21017

GitHubzeusbox/cve-2021-21017

Proof-of-concept exploit for Adobe Reader type confusion leading to heap overflow, with detailed root-cause analysis and detection guidance.

binary-exploitationexploitationfuzzing+3
445 years ago
CVE-2022-46169 preview

CVE-2022-46169

GitHub0xf4n9x/cve-2022-46169

CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.

authenticationcommand-and-controlexploitation+3
473 years ago
Previous1…456…15Next