Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
CVE-2020-5902 preview

CVE-2020-5902

GitHubar0dd/cve-2020-5902

POC code for checking for this vulnerability. Since the code has been released, I decided to release this one as well. Patch Immediately!

exploitationinformation-gatheringpenetration-testing+2
12
6 years ago
Zimbra-CVE-2022-30333 preview

Zimbra-CVE-2022-30333

GitHubaslitsecurity/zimbra-cve-2022-30333

Zimbra unrar vulnerability. Now there are already POC available, it is safe to release our POC.

exploitationpayload-generationpenetration-testing+2
74 years ago
CVE-2019-10685 preview

CVE-2019-10685

GitHubalt3kx/cve-2019-10685

A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Print Archive System v2015 release 2.6

exploitationpenetration-testingvulnerability-analysis+2
27 years ago
CVE-2026-9806 preview

CVE-2026-9806

GitHubaj2108/cve-2026-9806

CVE-2026-9806 is a Stored Cross-Site Scripting (Stored XSS) vulnerability affecting CTI Transmute versions prior to the patched release.

educationvulnerability-analysisweb-application-exploitation+1
1 month ago
CVE-2025-52204 preview

CVE-2025-52204

GitHubj0qq3r/cve-2025-52204

Coordinated disclosure of CVE-2025-52204: reflected XSS and HTML injection in Znuny OTRS customer.pl endpoint. Includes technical summary, affected…

educationpapers-researchvulnerability-analysis+2
5 months ago
PwnAdventure3 preview

PwnAdventure3

GitHubliveoverflow/pwnadventure3

PwnAdventure3 Server

binary-exploitationctfeducation+5
6848 years ago
morpheus preview

morpheus

GitHubr00t-3xp10it/morpheus

Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool)

exploitationids-ips-evasioninformation-gathering+7
8837 years ago
pentest-mcp preview

pentest-mcp

GitHubdmontgomery40/pentest-mcp

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

exploitationfuzzingnetwork-mapping+8
1455 months ago
ysoserial-cve-2018-2628 preview

ysoserial-cve-2018-2628

GitHubtdy218/ysoserial-cve-2018-2628

Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch

exploitationpayload-developmentpenetration-testing+2
1148 years ago
cc-ddos preview

cc-ddos

GitHubnayumidev/cc-ddos

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

penetration-testingred-teamingweb-application-exploitation
831 year ago
CVE-2026-66066-POC preview

CVE-2026-66066-POC

GitHubzer0sumgam3/cve-2026-66066-poc

PoC for CVE-2026-66066 in Ruby on Rails

educationexploitationlabs-practice+3
231 month ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubgodylockz/cve-2024-23897

Proof-of-concept exploit for CVE-2024-23897 enabling unauthenticated arbitrary file read on Jenkins servers. Supports authenticated sessions, proxy,…

exploitationinformation-gatheringpenetration-testing+2
449 months ago
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

data-exfiltrationemail-securityexploitation+6
29 days ago
CVE-2021-29156 preview

CVE-2021-29156

GitHubguidepointsecurity/cve-2021-29156

Proof-of-concept exploit for CVE-2021-29156, an LDAP injection vulnerability in ForgeRock OpenAM v13.0.0, enabling character-by-character brute force…

exploitationinformation-gatheringpenetration-testing+2
43 years ago
cve-2019-13720 preview

cve-2019-13720

GitHubcve-2019-13720/cve-2019-13720

Proof-of-concept exploit for CVE-2019-13720, a Chrome browser vulnerability. Includes a demonstration video and a released exploitation tool for…

exploitationpayload-developmentpenetration-testing+2
36 years ago
CVE-2023-22527 preview

CVE-2023-22527

GitHubprivia-security/cve-2023-22527

CVE-2023-22527

exploitationpayload-developmentpenetration-testing+3
52 years ago
CVE-2026-8037-POC preview

CVE-2026-8037-POC

GitHubcaster-chen/cve-2026-8037-poc

包括能执行的命令探测和一键getshell(需要服务器部署服务)

command-and-controlexploitationpayload-generation+3
2 months ago
CVE-2026-67620-poc preview

CVE-2026-67620-poc

GitHubabdugafforov-bobur/cve-2026-67620-poc

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

cloud-securityexploitationinformation-gathering+4
11 month ago
Previous12Next