Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5041 results
CVE-2024-23346 preview

CVE-2024-23346

GitHubsanity-archive/cve-2024-23346

PoC of the vulnerability CVE-2024-23346

educationexploitationpenetration-testing+2
2
1 year ago
CVE-2022-40317 preview

CVE-2022-40317

GitHubizdiwho/cve-2022-40317

Stored XSS proof-of-concept for OpenKM notes section, demonstrating a javascript: bypass of sanitization rules, with CVSS 3.1 scoring and…

educationpapers-researchpenetration-testing+2
23 years ago
cybersecurity-struts2 preview

cybersecurity-struts2

GitHubsighup1/cybersecurity-struts2

Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart…

educationexploitationpayload-development+3
17 years ago
wordpress_cve-2018-6389 preview

wordpress_cve-2018-6389

GitHubm3ssap0/wordpress_cve-2018-6389

Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.

exploitationpenetration-testingvulnerability-scanners+2
28 years ago
CVE-2025-52204 preview

CVE-2025-52204

GitHubj0qq3r/cve-2025-52204

Coordinated disclosure of CVE-2025-52204: reflected XSS and HTML injection in Znuny OTRS customer.pl endpoint. Includes technical summary, affected…

educationpapers-researchvulnerability-analysis+2
5 months ago
CVE-2022-46169 preview

CVE-2022-46169

GitHubnicostan15/cve-2022-46169

Educational demonstration of CVE-2022-46169: unauthenticated remote code execution in Cacti ≤1.2.22 via authorization bypass and command injection.…

educationexploitationlabs-practice+3
5 months ago
CVE-2017-12635_36 preview

CVE-2017-12635_36

GitHubdungsocool/cve-2017-12635_36

Step-by-step lab demonstrating exploitation of CVE-2017-12635 (privilege escalation) and CVE-2017-12636 (remote code execution) against Apache…

educationexploitationlabs-practice+3
3 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubsubhdotsol/cve-2025-55182

This project provides a fully functional demonstration of CVE-2025-55182 (React2Shell) - a critical Remote Code Execution vulnerability in React…

command-and-controleducationexploitation+5
28 months ago
ssrfnginx preview

ssrfnginx

GitHubknqyf263/ssrfnginx

Exploit Server-Side Request Forgery (SSRF) vulnerabilities through nginx configurations. Enables testing and exploitation of SSRF in web applications.

exploitationpenetration-testingweb-application-exploitation+1
16 years ago
CVE-2023-25690-POC preview

CVE-2023-25690-POC

GitHuboocyginxoo/cve-2023-25690-poc

CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling…

educationexploitationlabs-practice+3
21 year ago
CVE-2025-27415-PoC preview

CVE-2025-27415-PoC

GitHubjiseoung/cve-2025-27415-poc

Nuxt3 Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability

exploitationvulnerability-analysisweb-application-exploitation+1
21 year ago
CVE-2026-38526-POC preview

CVE-2026-38526-POC

GitHubpawpic/cve-2026-38526-poc

Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution

educationexploitationpayload-development+3
2 months ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubkaleth4/cve-2021-44228

Educational analysis of CVE-2021-44228 (Log4Shell) with PoC scripts, attack vector breakdown, and mitigation guidance for understanding and testing…

educationexploitationpayload-generation+3
4 months ago
CS4277-CVE-Path-Traversal-Apache-HTTP-Server preview

CS4277-CVE-Path-Traversal-Apache-HTTP-Server

GitHubjkim72403/cs4277-cve-path-traversal-apache-http-server

We hope to reproduce CVE-2021-41773 to deepen our understanding of real-world cybersecurity vulnerabilities so that we can be knowledgeable about…

educationexploitationpenetration-testing+3
4 months ago
cve-2025-55182-react2shell-analysis preview

cve-2025-55182-react2shell-analysis

GitHubporsellaj/cve-2025-55182-react2shell-analysis

Technical analysis of CVE-2025-55182 (React2Shell RCE vulnerability)

educationexploitationpapers-research+2
5 months ago
CVE-2021-44593 preview

CVE-2021-44593

GitHubmister-joe/cve-2021-44593

Public disclosure and writeup of CVE-2021-44593, an unauthenticated SQL injection in Simple College Website leading to arbitrary file upload and…

exploitationpenetration-testingvulnerability-analysis+2
24 years ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubrajneeshkarya/cve-2023-3460

Exploit for the vulnerability of Ultimate Member Plugin.

exploitationpassword-attackspenetration-testing+2
12 years ago
CVE-2020-29254 preview

CVE-2020-29254

GitHubs1lkys/cve-2020-29254

TikiWiki 21.2 allows to edit templates without the use of a CSRF protection.

educationexploitationmisconfiguration+3
12 years ago
Previous1…909192…100Next