Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
CVE-2024-23334-PoC preview

CVE-2024-23334-PoC

GitHubbetan423/cve-2024-23334-poc

This repository is a proof of concept (POC) for CVE-2024-23334, demonstrating an attempt to replicate the bug in aiohttp that leads to Local File…

educationexploitationlabs-practice+2
1
1 year ago
CVE-2021-32708 preview

CVE-2021-32708

GitHubfazilbaig1/cve-2021-32708

Affected versions of this package are vulnerable to Race Condition. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace.…

educationexploitationpayload-generation+2
11 year ago
46635.py_CVE-2019-9053 preview

46635.py_CVE-2019-9053

GitHubd3athcod3/46635.py_cve-2019-9053

This is modified code of 46635 exploit from python2 to python3.

exploitationpayload-generationpenetration-testing+2
15 years ago
CVE-2022-32060 preview

CVE-2022-32060

GitHubbypazs/cve-2022-32060

An arbitrary file upload vulnerability in the Update Branding Settings component of Snipe-IT v6.0.2 allows attackers to execute arbitrary code via a…

exploitationpenetration-testingvulnerability-analysis+1
13 years ago
CVE-2020-3452_Cisco_ASA_PathTraversal preview

CVE-2020-3452_Cisco_ASA_PathTraversal

GitHubabrewer251/cve-2020-3452_cisco_asa_pathtraversal

Proof-of-concept exploit for CVE-2020-3452, a path traversal in Cisco ASA/FTD, enabling unauthenticated file disclosure. Automates extraction of…

educationexploitationinformation-gathering+3
11 months ago
CVE-2019-5414 preview

CVE-2019-5414

GitHubcrstaicu/cve-2019-5414

Proof-of-concept exploit for CVE-2019-5414, a remote code execution vulnerability in Ruby on Rails. Demonstrates exploitation of the file content…

exploitationvulnerability-analysisweb-application-exploitation
8 months ago
PoC_CVE-2024-28157 preview

PoC_CVE-2024-28157

GitHubshinigami-777/poc_cve-2024-28157

Proof of Concept for CVE-2024-28157

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubnika0x38/cve-2018-7600

A Rust implementation of the CVE-2018-7600 exploit targeting vulnerable Drupal 7 installations (<= 7.57)

command-and-controleducationexploitation+3
11 months ago
Vvveb-CMS-CVE-2025-8518 preview

Vvveb-CMS-CVE-2025-8518

GitHubmaestro-ant/vvveb-cms-cve-2025-8518

This repository contains a Proof of Concept (PoC) demonstrating a critical vulnerability in givanz Vvveb 1.0.5. The vulnerability allows an…

code-analysisexploitationpenetration-testing+2
11 months ago
CVE-2025-56762 preview

CVE-2025-56762

GitHubshaunak-chatterjee/cve-2025-56762

Proof of Concept for CVE-2025-56762

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
gosign-desktop-exploit-poc preview

gosign-desktop-exploit-poc

GitHubsiddolo/gosign-desktop-exploit-poc

CVE-2025-34324, CVE-2025-34327: GoSign Desktop TLS Bypass & Insecure Update Exploit Proof of Concept

binary-exploitationexploitationpenetration-testing+3
9 months ago
POC_CVE-2025-14700 preview

POC_CVE-2025-14700

GitHubsecdongle/poc_cve-2025-14700

Proof of Concept for Authenticated RCE in Crafty Controller

educationexploitationpenetration-testing+3
8 months ago
TYPO3-HTML-Sanitizer-XSS-CVE-2023-47125 preview

TYPO3-HTML-Sanitizer-XSS-CVE-2023-47125

GitHubnikn0laty/typo3-html-sanitizer-xss-cve-2023-47125

Stored XSS (exploit) in TYPO3 HTML Sanitizer (CVE-2023-47125). DOM processing instructions are not handled correctly. This allows bypassing the…

exploitationpenetration-testingvulnerability-analysis+2
7 months ago
CVE-2025-34227_Nagios-XI-Command-Injection-Configuration-Wizard preview

CVE-2025-34227_Nagios-XI-Command-Injection-Configuration-Wizard

GitHubmcorybillington/cve-2025-34227_nagios-xi-command-injection-configuration-wizard

Simple proof of concept repository for CVE-2025-34227 Nagios XI authenticated command injection in Configuration Wizard

command-and-controlexploitationpenetration-testing+2
9 months ago
CVE-2025-24054_PoC preview

CVE-2025-24054_PoC

GitHubwind010/cve-2025-24054_poc

A proof of concept for CVE-2025-24054/CVE-2025-24071

exploitationpayload-developmentpenetration-testing+2
10 months ago
Next.js_exploit_CVE-2024-34351 preview

Next.js_exploit_CVE-2024-34351

GitHubavergnaud/next.js_exploit_cve-2024-34351

Educational demo of a Server-Side Request Forgery (SSRF) vulnerability in Next.js (CVE-2024-34351), with step-by-step exploitation and mitigation…

educationlabs-practicevulnerability-analysis+2
12 years ago
CVE-2023-34836 preview

CVE-2023-34836

GitHubsahiloj/cve-2023-34836

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

educationpapers-researchpenetration-testing+2
16 months ago
CVE-2025-27636-demo preview

CVE-2025-27636-demo

GitHubcrystallen1/cve-2025-27636-demo

Demonstrates Apache Camel CVE-2025-27636 with Docker-based reproduction of header injection attacks, including bean method injection and command…

educationexploitationpenetration-testing+3
10 months ago
Previous1…979899100Next