Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1681 results
CVE-2024-41453_CVE-2024-41454 preview

CVE-2024-41453_CVE-2024-41454

GitHubcode5ecure/cve-2024-41453_cve-2024-41454

Proof-of-concept exploits for CVE-2024-41453 and CVE-2024-41454 demonstrating stored XSS and malicious file upload vulnerabilities in ProcessMaker 4…

crawlereducationmalware-analysis+3
1 year ago
Preproduce-CVE-2021-41773 preview

Preproduce-CVE-2021-41773

GitHubluongchivi/preproduce-cve-2021-41773

PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

educationexploitationpenetration-testing+3
1 year ago
Tomcat-CVE-2017-12615 preview

Tomcat-CVE-2017-12615

GitHubcyberharsh/tomcat-cve-2017-12615

Docker-based lab environment for exploiting Tomcat CVE-2017-12615 arbitrary file write via PUT method, with bypass techniques and proof-of-concept…

educationexploitationlabs-practice+3
6 years ago
PIL-CVE-2017-8291-study preview

PIL-CVE-2017-8291-study

GitHubshun1403/pil-cve-2017-8291-study

Educational lab demonstrating CVE-2017-8291 (PIL/GhostScript RCE) via crafted EPS file upload with PNG extension, including Docker setup and PoC…

code-analysiseducationexploitation+3
1 year ago
cve-2024-3400 preview

cve-2024-3400

GitHubkr0ff/cve-2024-3400

Python exploit and checker script for CVE-2024-3400 Palo Alto Command Injection and Arbitrary File Creation

command-and-controleducationexploitation+2
2 years ago
CVE-2023-31716 preview

CVE-2023-31716

GitHubmateustesser/cve-2023-31716

Proof-of-concept exploit for CVE-2023-31716, a Local File Inclusion vulnerability in FUXA SCADA/HMI software versions <= 1.1.12, enabling arbitrary…

embedded-systems-securityexploitationscada-ics-security+2
2 years ago
CVE-2024-1247-PoC preview

CVE-2024-1247-PoC

GitHubnxploited/cve-2024-1247-poc

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

code-analysiseducationexploitation+3
1 year ago
CVE-2024-9698 preview

CVE-2024-9698

GitHubnxploited/cve-2024-9698

Crafthemes Demo Import <= 3.3 - Authenticated ( Admin+) Arbitrary File Upload in process_uploaded_files

educationexploitationpayload-development+3
1 year ago
wargame-turkey_in_2 preview

wargame-turkey_in_2

GitHubm0d0ri205/wargame-turkey_in_2

CTF wargame platform featuring Unicode bypass exploitation (CVE-2015-9238), flag file segmentation, brute force delay, and password hashing for…

ctfeducationlabs-practice+3
1 year ago
wargame-tarpioka preview

wargame-tarpioka

GitHubm0d0ri205/wargame-tarpioka

YISF 2024 CTF-Web (Directory Traversal via ".tar" file, CVE-2007-4559), easy

ctfeducationlabs-practice+2
1 year ago
CVE-2026-5027 preview

CVE-2026-5027

GitHubmin8282/cve-2026-5027

Proof-of-concept exploit for CVE-2026-5027, a path traversal vulnerability in Langflow allowing arbitrary file write and potential remote code…

educationexploitationpenetration-testing+3
4 months ago
CVE-2026-60093 preview

CVE-2026-60093

GitHuboscerd/cve-2026-60093

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-60093) in camel-azure-storage-datalake, demonstrating arbitrary…

educationexploitationpapers-research+2
6 days ago
CVE-2026-66906 preview

CVE-2026-66906

GitHuboscerd/cve-2026-66906

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-66906) in camel-azure-storage-blob, demonstrating arbitrary file…

educationexploitationpapers-research+2
6 days ago
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write preview

CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

GitHubbiitts/cve-2026-82286-gpt-crawler-arbitrary-file-write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

educationexploitationlabs-practice+3
1 day ago
SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit preview

SASTRA-ADI-WIGUNA-CVE-2026-21858-Holistic-Audit

GitHubsastraadiwiguna-purpleeliteteaming/sastra-adi-wiguna-cve-2026-21858-holistic-audit

Technical audit and reproduction of CVE-2026-21858, an n8n RCE chain exploiting Content-Type confusion for arbitrary file read, session forgery, and…

curated-resourceseducationexploitation+4
7 months ago
Ashwesker-CVE-2026-21440 preview

Ashwesker-CVE-2026-21440

GitHubredpack-kr/ashwesker-cve-2026-21440

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…

educationexploitationpenetration-testing+3
7 months ago
CVE-2025-11371 preview

CVE-2025-11371

GitHublap1nou/cve-2025-11371

Proof-of-concept exploit for CVE-2025-11371, a local file inclusion vulnerability in Gladinet CentreStack/Triofox, demonstrating unauthorized file…

educationexploitationpenetration-testing+2
110 months ago
CVE-2025-11371 preview

CVE-2025-11371

GitHubnetvanguard-cmd/cve-2025-11371

Proof-of-concept exploit for CVE-2025-11371, an unauthenticated Local File Inclusion in Gladinet CentreStack and TrioFox, enabling remote file…

educationexploitationinformation-gathering+3
110 months ago
Previous1…899091…94Next