Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1682 results
CVE-2024-45590-PoC preview

CVE-2024-45590-PoC

GitHubevillm/cve-2024-45590-poc

Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…

educationexploitationpayload-development+3
6 months ago
rejjeto_hfs-rce-exploit-cve-2014-6287 preview

rejjeto_hfs-rce-exploit-cve-2014-6287

GitHubjoaz94/rejjeto_hfs-rce-exploit-cve-2014-6287

Remote Command Execution exploit for Rejetto HTTP File Server 2.3.x (CVE-2014-6287) rewritten in Python 3 for modern offensive security testing.

command-and-controleducationexploitation+5
8 months ago
CVE-2024-27954 preview

CVE-2024-27954

GitHubr0otk3r/cve-2024-27954

Python-based scanner for CVE-2024-27954, a Local File Inclusion vulnerability in the WordPress wp-automatic plugin. Supports multithreaded scanning,…

educationexploitationinformation-gathering+3
1 year ago
CVE_POC_test preview

CVE_POC_test

GitHublingchul/cve_poc_test

PoC exploit for CVE-2019-13086 targeting SQL injection and file upload vulnerabilities in CSZ CMS. Includes experimental setup and reproduction code…

educationexploitationlabs-practice+3
6 years ago
Blackash-CVE-2025-31131 preview

Blackash-CVE-2025-31131

GitHubgmh5225/blackash-cve-2025-31131

Exploit for CVE-2025-31131, a path traversal vulnerability in YesWiki < 4.5.2, enabling arbitrary file read via the squelette parameter. Includes…

educationexploitationpenetration-testing+2
1 year ago
CVE-2025-4389 preview

CVE-2025-4389

GitHubyucaerin/cve-2025-4389

Crawlomatic Multipage Scraper Post Generator <= 2.6.8.1 - Unauthenticated Arbitrary File Upload

educationexploitationpayload-generation+3
1 year ago
CVE-2025-3419 preview

CVE-2025-3419

GitHubyucaerin/cve-2025-3419

The Eventin plugin (<= 4.0.26) for WordPress contains an unauthenticated arbitrary file read vulnerability

educationexploitationinformation-gathering+3
1 year ago
CVE-2024-53677-Exploitation preview

CVE-2024-53677-Exploitation

GitHubhopsypopsy8/cve-2024-53677-exploitation

Step-by-step walkthrough for exploiting Apache Struts CVE-2024-53677 RCE via file upload manipulation, including OGNL injection, payload embedding,…

code-analysiseducationexploitation+6
1 year ago
CVE-2021-31856 preview

CVE-2021-31856

GitHubssst0n3/cve-2021-31856

Detailed CVE-2021-31856 report with PoC and code analysis for a SQL injection vulnerability in Meshery's pattern file API, enabling unauthenticated…

code-analysisdatabase-securitypenetration-testing+2
5 years ago
CVE-2024-51747 preview

CVE-2024-51747

GitHubl20170217b/cve-2024-51747

Proof-of-concept exploit for CVE-2024-51747 enabling authenticated file read and deletion via SQLite database manipulation in a web application's…

database-securitydata-exfiltrationexploitation+2
1 year ago
CVE-2023-40028 preview

CVE-2023-40028

GitHubrehan6658/cve-2023-40028

Python exploit for CVE-2023-40028 in Ghost CMS, enabling arbitrary file read via symlink abuse in ZIP uploads. Includes automated cleanup.

educationexploitationpenetration-testing+2
1 year ago
CVE-2024-25641-Exploit-for-Cacti-1.2.26 preview

CVE-2024-25641-Exploit-for-Cacti-1.2.26

GitHubregantemudo/cve-2024-25641-exploit-for-cacti-1.2.26

Automated exploit for CVE-2024-25641 targeting Cacti 1.2.26. Achieves remote code execution via authenticated arbitrary file write in the Package…

educationexploitationpayload-development+4
1 year ago
exploit-CVE-2023-27564 preview

exploit-CVE-2023-27564

GitHubdavid-botelho-mariano/exploit-cve-2023-27564

Proof-of-concept exploit for CVE-2023-27564 enabling anonymous file read in n8n via path traversal in the REST API. Intended for security research…

educationexploitationpenetration-testing+2
2 years ago
CVE-2024-56264 preview

CVE-2024-56264

GitHubdpakmrya/cve-2024-56264

Python exploit for CVE-2024-56264, an arbitrary file upload vulnerability in WordPress ACF City Selector plugin <=1.14.0, enabling remote code…

educationexploitationpenetration-testing+2
1 year ago
Mini_httpd-CVE-2018-18778 preview

Mini_httpd-CVE-2018-18778

GitHubcyberharsh/mini_httpd-cve-2018-18778

PoC exploit for CVE-2018-18778: arbitrary file read in mini_httpd 1.29 via empty Host header, affecting IoT devices from Huawei, Zyxel, and others.

embedded-systems-securityexploitationfuzzing+3
6 years ago
CVE-2024-56264 preview

CVE-2024-56264

GitHubnxploited/cve-2024-56264

WordPress ACF City Selector plugin <= 1.14.0 - Arbitrary File Upload vulnerability

educationexploitationpayload-generation+3
1 year ago
CVE-2024-7985-PoC preview

CVE-2024-7985-PoC

GitHubnxploited/cve-2024-7985-poc

FileOrganizer <= 1.0.9 - Authenticated (Subscriber+) Arbitrary File Upload

educationexploitationpayload-generation+3
1 year ago
CVE-2024-52375 preview

CVE-2024-52375

GitHubnxploited/cve-2024-52375

WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability

educationexploitationpayload-generation+3
1 year ago
Previous1…888990…94Next