Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
Optimum preview

Optimum

GitHubr3fr4kt/optimum

Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain…

educationexploitationinformation-gathering+7
6 months ago
Web-Penetration-Test preview

Web-Penetration-Test

GitHubsalimelh94/web-penetration-test

Exploiting WordPress vulnerabilities (CVE-2025-34077), authentication bypass via cookie injection, and privilege escalation to root. Part of my…

authenticationctfeducation+6
5 months ago
MegaQuagga_Pentesting_Report preview

MegaQuagga_Pentesting_Report

GitHubaktia1/megaquagga_pentesting_report

Web application penetration testing project targeting a WordPress environment. Includes exploitation of CVE-2019-9978, reverse shell execution,…

educationexploitationpenetration-testing+5
4 months ago
CVE-2019-18935-exploit-study preview

CVE-2019-18935-exploit-study

GitHubquyt0/cve-2019-18935-exploit-study

In-depth study of CVE-2019-18935 affecting Telerik UI for ASP.NET AJAX. Covers .NET deserialization vulnerability, RadAsyncUpload handler, gadget…

code-analysiseducationexploitation+3
10 years ago
CVE-2021-21220 preview

CVE-2021-21220

GitHubborahll/cve-2021-21220

Educational presentation detailing the exploitation of CVE-2021-21220, a V8 JIT type confusion leading to OOB access and RCE via WebAssembly, with…

binary-exploitationeducationexploitation+3
4 months ago
cve-2025-29927-nextjs preview

cve-2025-29927-nextjs

GitHubgitgudkrish/cve-2025-29927-nextjs

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

authenticationeducationpenetration-testing+3
3 months ago
cve-2021-41773-exploration preview

cve-2021-41773-exploration

GitHubklmntbelgium/cve-2021-41773-exploration

Recreation and analysis of a curious logic error in Apache 2.4.49 that escalated to remote code execution

educationexploitationlabs-practice+3
14 months ago
CVE-2026-23498 preview

CVE-2026-23498

GitHublukasz-rybak/cve-2026-23498

CVE-2026-23498 - Shopware Has Improper Control of Generation of Code in Twig rendered views

code-analysiseducationpapers-research+2
4 months ago
CVE-2019-25137-Version-Research preview

CVE-2019-25137-Version-Research

GitHubickarah/cve-2019-25137-version-research

A writeup investigating the full extent of CVE-2019-25137

code-analysiseducationexploitation+3
13 years ago
cve-2023-50164 preview

cve-2023-50164

GitHubaaronm-sysdig/cve-2023-50164

Demonstrates detection of CVE-2023-50164 (Apache Struts RCE) with a simple Java app, intended for security testing and educational purposes.

educationexploitationpenetration-testing+2
12 years ago
SimpleCTF-THM-Walkthrough preview

SimpleCTF-THM-Walkthrough

GitHubpaulameg/simplectf-thm-walkthrough

First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web…

ctfeducationpassword-cracking+5
13 months ago
CVE-2026-52614 preview

CVE-2026-52614

GitHubchinesespeople/cve-2026-52614

There is a SQL injection vulnerability in the backend of Ruoyi v4.8.3

exploitationpassword-crackingpenetration-testing+2
1 month ago
CVE-2025-33053_PoC preview

CVE-2025-33053_PoC

GitHub4n4s4zi/cve-2025-33053_poc

POC exploit for CVE-2025-33053 (external control of file execution path in URL file)

command-and-controlexploitationlateral-movement+3
11 year ago
CVE-2026-29519-Lucee-Reflected-XSS preview

CVE-2026-29519-Lucee-Reflected-XSS

GitHubl4v4d0/cve-2026-29519-lucee-reflected-xss

Proof of Concept for Reflected XSS in Lucee CFML (CVE-2026-29519)

educationexploitationpenetration-testing+3
1 month ago
cve-2025-14325-full-repro preview

cve-2025-14325-full-repro

GitHubwostgit/cve-2025-14325-full-repro

Reproduction of CVE-2025-14325, providing a full proof-of-concept to demonstrate and analyze the vulnerability.

exploitationpenetration-testingreconnaissance+2
5 months ago
CVE-2024-12381-PoC preview

CVE-2024-12381-PoC

GitHubfatfishio/cve-2024-12381-poc

Proof-of-concept exploit for CVE-2024-12381, demonstrating exploitation of a specific vulnerability for security testing and validation.

exploitationpenetration-testingreconnaissance+2
3 months ago
day08-CISCO-fmc-sim preview

day08-CISCO-fmc-sim

GitHubamalpvatayam67/day08-cisco-fmc-sim

This is a minimal, educational simulation that demonstrates the _impact_ class of a management-plane parsing RCE (inspired by CVE-2025-20265). It…

binary-exploitationeducationexploitation+3
111 months ago
CVE-2026-20841-PoC preview

CVE-2026-20841-PoC

GitHubhackfaiz/cve-2026-20841-poc

Proof of concept demonstrating command execution in Microsoft Notepad via crafted files, enabling arbitrary code execution and system compromise.

command-and-controlexploitationpayload-development+2
16 months ago
Previous1…959697…100Next