Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13165 results
scan4log4j preview
Archived

scan4log4j

GitHubssl/scan4log4j

Python script that sends CVE-2021-44228 log4j payload requests to url list

vulnerability-scannerspayload-generationexploitation+2
6
4 years ago
CVE-2022-38577-Processmaker preview
Archived

CVE-2022-38577-Processmaker

GitHubsornram9254/cve-2022-38577-processmaker

ProcessMaker before v3.5.4 was discovered to contain insecure permissions in the user profile page. This vulnerability allows attackers to escalate…

privilege-escalationexploit-frameworksvulnerability-analysis+3
31 year ago
CVE-2023-41080 preview
Archived

CVE-2023-41080

GitHubshiomiyan/cve-2023-41080
vulnerability-analysisexploitationweb-application-exploitation+2
112 years ago
CVE-2021-41773 preview
Archived

CVE-2021-41773

GitHubshiomiyan/cve-2021-41773
vulnerability-analysisexploitationweb-application-exploitation+2
4 years ago
CVE-2022-46169 preview
Archived

CVE-2022-46169

GitHubsaspect488/cve-2022-46169

PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22

vulnerability-analysisexploitationweb-application-exploitation+3
293 years ago
CVE-2020-0688 preview
Archived

CVE-2020-0688

GitHubravinacademy/cve-2020-0688

Exploitation Script for CVE-2020-0688 "Microsoft Exchange default MachineKeySection deserialize vulnerability"

payload-generationvulnerability-analysisexploitation+2
116 years ago
modsecurity-cve-2018-6389 preview
Archived

modsecurity-cve-2018-6389

GitHubrastating/modsecurity-cve-2018-6389

A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389

defensive-toolsvulnerability-scannersids-ips-evasion+3
8 years ago
CVE-2021-26855 preview
Archived

CVE-2021-26855

GitHubr0xdb/cve-2021-26855

CVE-2021-26855, also known as Proxylogon, is a server-side request forgery (SSRF) vulnerability in Exchange that allows an attacker to send arbitrary…

reconnaissancevulnerability-analysisexploitation+2
122 years ago
CVE-2021-2302 preview
Archived

CVE-2021-2302

GitHubquynhle7821/cve-2021-2302
vulnerability-analysisexploitationweb-application-exploitation+2
94 years ago
CVE-2020-8958 preview
Archived

CVE-2020-8958

GitHubqurbat/cve-2020-8958

Proof of concept for arbitrary OS command execution on Guangzhou/V-SOL 1GE ONU devices (CVE-2020-8958)

embedded-systems-securityiot-securityvulnerability-analysis+3
75 years ago
nodejs-http-transfer-encoding-smuggling-poc preview
Archived

nodejs-http-transfer-encoding-smuggling-poc

GitHubprogfay/nodejs-http-transfer-encoding-smuggling-poc

PoC of HTTP Request Smuggling in nodejs (CVE-2020-8287)

vulnerability-analysisexploitationweb-application-exploitation+2
25 years ago
CVE-2020-8165 preview
Archived

CVE-2020-8165

GitHubprogfay/cve-2020-8165

PoC for CVE-2020-8165

vulnerability-analysisexploitationweb-application-exploitation+2
5 years ago
proxylogon-exploit preview
Archived

proxylogon-exploit

GitHubpraetorian-inc/proxylogon-exploit

Proof-of-concept exploit for CVE-2021-26855 and CVE-2021-27065. Unauthenticated RCE in Exchange.

payload-generationvulnerability-analysisexploitation+3
525 years ago
sample-ldap-exploit preview
Archived

sample-ldap-exploit

GitHubphoswald/sample-ldap-exploit

A short demo of CVE-2021-44228

vulnerability-analysisexploitationweb-application-exploitation+3
54 years ago
CVE-2022-39275 preview
Archived

CVE-2022-39275

GitHubomar2535/cve-2022-39275

CVE-2022-39275 Setup and POC

vulnerability-analysisexploitationweb-application-exploitation+2
1 year ago
CVE-2025-46171 preview
Archived

CVE-2025-46171

GitHuboiyl/cve-2025-46171

Writeup of a Denial of Service vulnerability in the vBulletin 3.8.7 friends list.

vulnerability-analysisweb-application-exploitationpenetration-testing+2
41 year ago
WinboxExploit preview
Archived

WinboxExploit

GitHubmsterusky/winboxexploit

C# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]

vulnerability-analysisexploitationweb-application-exploitation+2
77 years ago
react2shell preview
Archived

react2shell

GitHubmantvmass/react2shell

A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code…

vulnerability-scannersexploitationweb-application-exploitation+3
28 months ago
Previous1…725726727…732Next