Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
CVE-2025-26198 preview

CVE-2025-26198

GitHubwailyacoubi9/cve-2025-26198

Educational reproduction of CVE-2025-26198 SQL injection in CloudClassroom-PHP-Project, demonstrating four exploitation techniques (boolean, union,…

authenticationdatabase-securityeducation+3
7 months ago
cve-2025-9933 preview

cve-2025-9933

GitHubtitanmaster96/cve-2025-9933

A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknown functionality of the file…

educationexploitationpenetration-testing+2
7 months ago
CVE-2025-61183 preview

CVE-2025-61183

GitHubthawphone/cve-2025-61183

Detailed disclosure of a stored XSS vulnerability in VaahCMS via unsafe SVG file upload handling, including exploitation flow, affected endpoints,…

educationexploitationpenetration-testing+3
6 months ago
CVE-2025-66683 preview

CVE-2025-66683

GitHubscap3sh4rk/cve-2025-66683

A Cross-Site Request Forgery (CSRF) vulnerability exists in the administrator profile update functionality of CarRentalMS v2.0. The affected endpoint…

exploitationpenetration-testingvulnerability-analysis+2
7 months ago
ktor-xxe-poc preview

ktor-xxe-poc

GitHubrazvanclaudiu/ktor-xxe-poc

This repository provides a Proof of Concept for CVE-2023-45612, demonstrating an XML External Entity (XXE) injection vulnerability in JetBrains Ktor…

educationexploitationpenetration-testing+3
10 months ago
CVE_2024_20356 preview

CVE_2024_20356

GitHubsherllyneo/cve_2024_20356

A oxidized version of https://github.com/nettitude/CVE-2024-20356/blob/main/CVE-2024-20356.py

command-and-controlexploitationpenetration-testing+3
12 years ago
CVE-2025-14700-poc preview

CVE-2025-14700-poc

GitHubnosiume/cve-2025-14700-poc

Proof of Concept for Authenticated RCE in Crafty Controller <= 4.6.1

exploitationpayload-generationpenetration-testing+3
18 months ago
cve-2022-26134 preview

cve-2022-26134

GitHubreubensammut/cve-2022-26134

Implementation of CVE-2022-26134

command-and-controlexploitationpenetration-testing+2
14 years ago
CVE-2018-19859 preview

CVE-2018-19859

GitHubwhiteoaksecurity/cve-2018-19859

CVE-2018-19859 Remote Code Execution Proof of Concept

exploitationpayload-developmentpenetration-testing+2
15 years ago
CVE-2025-53770-SharePoint-Deserialization-RCE-PoC preview

CVE-2025-53770-SharePoint-Deserialization-RCE-PoC

GitHubharryhaxor/cve-2025-53770-sharepoint-deserialization-rce-poc

A critical vulnerability in Microsoft SharePoint Server allows unauthenticated remote code execution via deserialization of untrusted data. Microsoft…

exploitationpenetration-testingred-teaming+3
11 year ago
CVE-2026-21876 preview

CVE-2026-21876

GitHubdaytriftnewgen/cve-2026-21876

Proof-of-concept exploit for CVE-2026-21876 demonstrating multipart charset bypass of OWASP CRS WAF in Flask, ASP.NET, and Spring Boot applications.

ids-ips-evasionpenetration-testingvulnerability-analysis+3
2 months ago
poc-cve-2024-32002 preview

poc-cve-2024-32002

GitHubfadhilthomas/poc-cve-2024-32002

poc of git rce using cve-2024-32002

exploitationpenetration-testingred-teaming+2
12 years ago
analysis-and-poc-n8n-CVE-2025-68613 preview

analysis-and-poc-n8n-CVE-2025-68613

GitHubreleaseown/analysis-and-poc-n8n-cve-2025-68613

Technical study of the CVE-2025-68613 vulnerability in n8n, covering affected versions, laboratory exploration scenario, offensive and defensive…

code-analysiseducationexploitation+5
18 months ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubbhanunamikaze/cve-2024-42009

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

data-exfiltrationeducationexploitation+5
11 year ago
CVE-2024-50677 preview

CVE-2024-50677

GitHubzumiyumi/cve-2024-50677

This repository presents a proof-of-concept of CVE-2024-50677

exploitationpenetration-testingphishing-tools+3
11 year ago
CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065 preview

CTT-Exchange-RCE-v1.0---Microsoft-Exchange-Exploit-CVSS-10.0-CRITICAL-CVE-2021-26855-CVE-2021-27065

GitHubsimoesctt/ctt-exchange-rce-v1.0---microsoft-exchange-exploit-cvss-10.0-critical-cve-2021-26855-cve-2021-27065

CTT-enhanced version of the Microsoft Exchange Server SSRF to RCE exploit (ProxyShell/ProxyLogon), another CVSS 10.0 critical vulnerability that…

command-and-controlexploitationexploit-frameworks+7
17 months ago
Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954- preview

Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-

GitHubshivanshkuntal/exploitation-of-a-remote-code-execution-vulnerability--cve-2024-7954-

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

educationexploitationinformation-gathering+8
18 months ago
CVE-2021-44228-docker-example preview

CVE-2021-44228-docker-example

GitHubdicanio/cve-2021-44228-docker-example

Docker-based demonstration of CVE-2021-44228 (Log4Shell) exploitation, featuring a vulnerable Java server, malicious LDAP server, and data…

data-exfiltrationeducationexploitation+3
14 years ago
Previous1…9899100Next