Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
CVE-2025-68400 preview

CVE-2025-68400

GitHublukasz-rybak/cve-2025-68400

Technical disclosure of a critical time-based blind SQL injection vulnerability (CVE-2025-68400) in ChurchCRM, including vulnerable code analysis,…

database-securityeducationexploitation+3
4 months ago
cve-2025-55182-analysis preview

cve-2025-55182-analysis

GitHubmohamedniane/cve-2025-55182-analysis

Security research & exploitation analysis of CVE-2025-55182 (React) — CVSS + OWASP Top 10 mapping

educationexploitationpenetration-testing+2
4 months ago
meesho-android-improper-encryption-cve-2026-5682 preview

meesho-android-improper-encryption-cve-2026-5682

GitHubhonestcorrupt/meesho-android-improper-encryption-cve-2026-5682

Proof of concept demonstrating insecure AES-CBC encryption with MD5 key derivation in the Meesho Android app, enabling ciphertext tampering and…

android-securitycryptographymobile-security+3
5 months ago
APACHE-PATH-TRAVERSAL-RCE-CVE-2021-41773- preview

APACHE-PATH-TRAVERSAL-RCE-CVE-2021-41773-

GitHubabds059/apache-path-traversal-rce-cve-2021-41773-

A comprehensive analysis of CVE-2021-41773 (Apache HTTP Server 2.4.49), featuring vulnerability research, controlled lab-based exploitation,…

educationexploitationlabs-practice+3
5 months ago
React2Shell preview

React2Shell

GitHubprowlsec/react2shell

An advanced command-line framework for discovery, validation, and exploitation of CVE-2025-55182 and CVE-2025-66478 affecting Next.js applications…

command-and-controlexploitationpayload-generation+4
18 months ago
CVE-2026-20180 preview

CVE-2026-20180

GitHubkaleth4/cve-2026-20180

In-depth technical analysis of Cisco ISE RCE vulnerabilities, including exploitation techniques, evasion methods, and remediation strategies for…

educationexploitationlateral-movement+6
14 months ago
DrupalCVE-2018-7602 preview

DrupalCVE-2018-7602

GitHubcyberharsh/drupalcve-2018-7602

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

code-analysiseducationexploitation+3
16 years ago
THM---Solar-exploiting-Log-4j preview

THM---Solar-exploiting-Log-4j

GitHubsaru1718/thm---solar-exploiting-log-4j

This room is based on exploiting the notorious Log4j vulnerability ( CVE-2021-44228), also referred to as the Log4Shell. The weakness enables…

educationexploitationids-ips-evasion+7
5 months ago
POC_CVE-2015-9235 preview

POC_CVE-2015-9235

GitHubtierchampion/poc_cve-2015-9235

Demo of the algorithm confusion attack on various JWT libraries

authenticationctfeducation+3
6 months ago
wordpress-rce-vapt-cve-2020-25213 preview

wordpress-rce-vapt-cve-2020-25213

GitHubcmadhushanka/wordpress-rce-vapt-cve-2020-25213

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

educationexploitationlabs-practice+6
4 months ago
CVE-2025-30921 preview

CVE-2025-30921

GitHubdottak/cve-2025-30921

PoC of CVE-2025-30921

code-analysisexploitationpenetration-testing+3
11 year ago
cve-2021-26084-confluence preview

cve-2021-26084-confluence

GitHubglennpegden2/cve-2021-26084-confluence

A quick and dirty PoC of cve-2021-26084 as none of the existing ones worked for me.

command-and-controlexploitationpenetration-testing+2
15 years ago
dlink-dir-819-dos preview

dlink-dir-819-dos

GitHubwhokilleddb/dlink-dir-819-dos

Unauthenticated Denial of Service in DLink consumer DIR 819 A1 router

exploitationpenetration-testingvulnerability-analysis+1
13 years ago
agent_tesla_panel_rce preview

agent_tesla_panel_rce

GitHubmekhalleh/agent_tesla_panel_rce

This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

exploitationpenetration-testingweb-application-exploitation
16 years ago
Sandbox-Challenge-Spring4Shell-CVE-2022-22965- preview

Sandbox-Challenge-Spring4Shell-CVE-2022-22965-

GitHubfelisha-elmer/sandbox-challenge-spring4shell-cve-2022-22965-

Step-by-step walkthrough of exploiting CVE-2022-22965 (Spring4Shell) with Metasploit, deploying a C2 listener, and mitigating the vulnerability by…

command-and-controlctfeducation+6
3 months ago
Global-Protect_VPN_Vuln preview

Global-Protect_VPN_Vuln

GitHubp4rc3l/global-protect_vpn_vuln

Testing a List of IP address incase they are vulnerable to CVE-2024-3400

exploitationpenetration-testingreconnaissance+2
3 months ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
spring-data-rest-CVE-2017-8046 preview

spring-data-rest-CVE-2017-8046

GitHubsj/spring-data-rest-cve-2017-8046

Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)

code-analysisexploitationpenetration-testing+2
14 years ago
Previous1…949596…100Next