Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1682 results
CVE-2024-10571 preview

CVE-2024-10571

GitHubrandomrobbiebf/cve-2024-10571

Chartify – WordPress Chart Plugin <= 2.9.5 - Unauthenticated Local File Inclusion via source

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2024-10470 preview

CVE-2024-10470

GitHubrandomrobbiebf/cve-2024-10470

WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2024-50473 preview

CVE-2024-50473

GitHubrandomrobbiebf/cve-2024-50473

Ajar in5 Embed <= 3.1.3 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2024-50427 preview

CVE-2024-50427

GitHubrandomrobbiebf/cve-2024-50427

SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - Authenticated (Subscriber+) Arbitrary File Upload

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2024-49607 preview

CVE-2024-49607

GitHubrandomrobbiebf/cve-2024-49607

WP Dropbox Dropins <= 1.0 - Unauthenticated Arbitrary File Upload

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2024-31351_wordpress_exploit preview

CVE-2024-31351_wordpress_exploit

GitHubktn1990/cve-2024-31351_wordpress_exploit

Wordpress - Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
2 years ago
CVE-2014-6287 preview

CVE-2014-6287

GitHubzhsh9/cve-2014-6287

Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c

exploitationpayload-generationpenetration-testing+2
2 years ago
CVE-2021-25094 preview

CVE-2021-25094

GitHubxdx57/cve-2021-25094

Tatsu Plugin ZIP File add_custom_font unrestricted upload

exploitationpayload-generationpenetration-testing+2
4 years ago
CVE-2024-54262 preview

CVE-2024-54262

GitHubrandomrobbiebf/cve-2024-54262

Import Export For WooCommerce <= 1.5 - Authenticated (Subscriber+) Arbitrary File Upload

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2024-46209 preview

CVE-2024-46209

GitHubh4ckr4v3n/cve-2024-46209

Security research repository detailing CVE-2024-46209 (authenticated RCE) and CVE-2024-46210 (stored XSS via file upload) in Redaxo CMS v5.17.1, with…

code-analysisexploitationpenetration-testing+2
1 year ago
CVE-2024-24137 preview

CVE-2024-24137

GitHubburaksevben/cve-2024-24137

Proof-of-concept exploit for SQL injection in Student File Management System, demonstrating CVE-2024-24137 vulnerability.

exploitationinformation-gatheringpenetration-testing+2
2 years ago
Jenkins-CVE-2024-23897-Exploit-Demo preview

Jenkins-CVE-2024-23897-Exploit-Demo

GitHubbrandonhjh/jenkins-cve-2024-23897-exploit-demo

Demonstrates exploitation of Jenkins CVE-2024-23897, an arbitrary file read vulnerability, for security testing and educational purposes.

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2022-32074 preview

CVE-2022-32074

GitHubreewardius/cve-2022-32074

Proof-of-concept exploit for CVE-2022-32074 demonstrating stored XSS in osTicket via malicious SVG file upload in the file listing directory.

exploitationinformation-gatheringpenetration-testing+2
3 years ago
CVE-2023-50465 preview

CVE-2023-50465

GitHubev3rr3d/cve-2023-50465

Proof-of-concept exploit for a stored XSS vulnerability in MonicaHQ CRM via malicious SVG file upload, demonstrating cross-site scripting in document…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2015-1427 preview

CVE-2015-1427

GitHubxpgdgit/cve-2015-1427

Exploit for CVE-2015-1427 with single URL, batch file, and custom command execution capabilities for testing Elasticsearch Groovy sandbox bypass…

command-and-controlexploitationpenetration-testing+2
4 years ago
CVE-2025-24963 preview

CVE-2025-24963

GitHubhiteshpatra/cve-2025-24963

Proof-of-concept exploit for CVE-2025-24963, a local file read vulnerability in Vitest browser mode via the __screenshot-error handler, enabling…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2018-16370 preview

CVE-2018-16370

GitHubsnappyjack/cve-2018-16370

In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a…

code-analysisexploitationpenetration-testing+2
7 years ago
CVE-2024-3806 preview

CVE-2024-3806

GitHubrandomrobbiebf/cve-2024-3806

Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts

exploitationinformation-gatheringpenetration-testing+2
1 year ago
Previous1…717273…94Next