Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5041 results
CVE-2018-16763 preview

CVE-2018-16763

GitHubnot1cyyy/cve-2018-16763

CVE-2018-16763 FuelCMS 1.4 Remote Code Execution, this version of FuelCMS is still vulnerable until now

exploitationpenetration-testingremote-access-tool+2
2
3 years ago
follina_cve_2022-30190 preview

follina_cve_2022-30190

GitHubamitniz/follina_cve_2022-30190

proof of concept to CVE-2022-30190 (follina)

educationexploitationpayload-generation+3
24 years ago
CVE-2025-28062 preview

CVE-2025-28062

GitHubthvt0ne/cve-2025-28062

proof of concept

educationexploitationpenetration-testing+3
21 year ago
CVE-2023-29357-ExE preview

CVE-2023-29357-ExE

GitHubkeystroke95/cve-2023-29357-exe

Recreation of the SharePoint PoC for CVE-2023-29357 in C# from LuemmelSec

exploitationpayload-generationpenetration-testing+2
22 years ago
CVE-2024-36401_Geoserver_RCE_POC preview

CVE-2024-36401_Geoserver_RCE_POC

GitHubamoy6228/cve-2024-36401_geoserver_rce_poc

本脚本是针对 GeoServer 的远程代码执行漏洞(CVE-2024-36401)开发的 PoC(Proof of Concept)探测工具。该漏洞允许攻击者通过构造特定请求,在目标服务器上执行任意命令。

command-and-controlexploitationpenetration-testing+3
21 year ago
log4j2-exploit preview

log4j2-exploit

GitHubspasam/log4j2-exploit

log4j2 Log4Shell CVE-2021-44228 proof of concept

educationexploitationpayload-development+3
24 years ago
CVE-2023-50164-PoC preview

CVE-2023-50164-PoC

GitHubsunnyvale-it/cve-2023-50164-poc

CVE-2023-50164 (Apache Struts path traversal to RCE vulnerability) - Proof of Concept

exploitationpayload-developmentpenetration-testing+2
22 years ago
CVE-2026-7229-SQLI preview

CVE-2026-7229-SQLI

GitHubxmyronn/cve-2026-7229-sqli

Proof of concept for authenticated SQL injection in Coaching Management System, demonstrating database dump via unsanitized complaintreply parameter.

database-securityexploitationpenetration-testing+3
4 months ago
CVE-2026-42778-POC preview

CVE-2026-42778-POC

GitHubakinfue/cve-2026-42778-poc

CVE-2026-42778 EUVD-2026-26492 Deserialization of Untrusted Data (CWE-502)

binary-exploitationexploitationpayload-development+2
4 months ago
CVE-2026-42879 preview

CVE-2026-42879

GitHubguzrex/cve-2026-42879

FacturaScripts RCE Exploit - Proof of Concept

exploitationpayload-developmentpenetration-testing+3
4 months ago
CVE-2024-48910-POC preview

CVE-2024-48910-POC

GitHubalex-acero-security/cve-2024-48910-poc

Proof of concept demonstrating prototype pollution in DOMPurify leading to client-side XSS, with a demo of the attack chain.

educationexploitationvulnerability-analysis+2
3 months ago
CVE-2026-6355 preview

CVE-2026-6355

GitHubpenguinsecq/cve-2026-6355

Exploit PoC of CVE-2026-6356

educationinformation-gatheringpenetration-testing+3
4 months ago
CVE-2025-59536 preview

CVE-2025-59536

GitHubnetvanguard-cmd/cve-2025-59536

PoC exploit for CVE-2025-59536, a high-severity code injection vulnerability in Claude Code's startup trust dialog, enabling remote exploitation of…

code-analysisexploitationpenetration-testing+2
4 months ago
PoC-CVE-2025-52913 preview

PoC-CVE-2025-52913

GitHubpgasus99/poc-cve-2025-52913

A Proof of Concept (PoC) for CVE-2025-52913, a path normalization vulnerability affecting Mitel MiCollab.

educationexploitationinformation-gathering+3
5 months ago
CVE-2023-32315exp preview

CVE-2023-32315exp

GitHub5rgj5ach5ocq5yw9/cve-2023-32315exp

Proof-of-concept exploit for CVE-2023-32315, providing a demonstration of the vulnerability for security testing.

exploitationpenetration-testingreconnaissance+2
23 years ago
-CVE-2022-22954-scanner preview

-CVE-2022-22954-scanner

GitHubmumu2020629/-cve-2022-22954-scanner

Scans for and exploits CVE-2022-22954 in VMware Workspace ONE Access, Identity Manager, and Realize Automation appliances. Automates detection and…

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubabdulazizalsewedy/cve-2021-29447

Step-by-step demonstration of CVE-2021-29447, a WordPress Media Library XXE vulnerability leaking sensitive files via crafted WAVE uploads, including…

data-exfiltrationeducationexploitation+3
23 years ago
CVE-2022-22978 preview

CVE-2022-22978

GitHubumakant76705/cve-2022-22978

Step-by-step demonstration of CVE-2022-22978 authorization bypass in Spring Security's RegexRequestMatcher, with vulnerable app setup, payload…

authentication-authorizationeducationlabs-practice+3
24 years ago
Previous1…899091…100Next