Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1752 results
CVE-2021-31800-Impacket-SMB-Server-Arbitrary-file-read-write preview

CVE-2021-31800-Impacket-SMB-Server-Arbitrary-file-read-write

GitHubp0dalirius/cve-2021-31800-impacket-smb-server-arbitrary-file-read-write

A path traversal in smbserver.py allows an attacker to read/write arbitrary files on the server.

data-exfiltrationexploitationpenetration-testing+2
11
3 years ago
CVE-2021-43008-AdminerRead preview

CVE-2021-43008-AdminerRead

GitHubp0dalirius/cve-2021-43008-adminerread

Exploit tool for CVE-2021-43008 Adminer 1.0 up to 4.6.2 Arbitrary File Read vulnerability

exploitationinformation-gatheringpenetration-testing+3
852 years ago
xxexploiter preview

xxexploiter

GitHubluisfontes19/xxexploiter

Tool to help exploit XXE vulnerabilities

exploitationfuzzingpayload-generation+2
6174 years ago
fuxploider preview

fuxploider

GitHubalmandin/fuxploider

File upload vulnerability scanner and exploitation tool.

exploitationpenetration-testingvulnerability-scanners+1
3.3k1 year ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
9974 months ago
ESFileExplorerOpenPortVuln preview

ESFileExplorerOpenPortVuln

GitHubfs0c131y/esfileexploreropenportvuln

ES File Explorer Open Port Vulnerability - CVE-2019-6447

android-securitydata-exfiltrationexploitation+5
6797 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubjas502n/cve-2020-5902

Proof-of-concept exploit for CVE-2020-5902, a directory traversal and remote code execution vulnerability in F5 BIG-IP TMUI. Includes file read,…

command-and-controlexploitationpenetration-testing+3
3744 years ago
CVE-2017-0199 preview

CVE-2017-0199

GitHubbhdresh/cve-2017-0199

Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test…

educationexploitationmalware-analysis+3
7258 years ago
Grafana-CVE-2021-43798 preview

Grafana-CVE-2021-43798

GitHubjas502n/grafana-cve-2021-43798

Grafana Unauthorized arbitrary file reading vulnerability

data-exfiltrationexploitationinformation-gathering+3
3693 years ago
CVE-2022-29464 preview

CVE-2022-29464

GitHubhakivvi/cve-2022-29464

Python exploit for CVE-2022-29464, an unauthenticated arbitrary file upload vulnerability in WSO2 servers, enabling remote code execution via…

exploitationpayload-generationpenetration-testing+3
3774 years ago
ProxyShell preview

ProxyShell

GitHubktecv2000/proxyshell

Proof-of-concept exploit for Microsoft Exchange Server Remote Code Execution via ACL bypass, privilege escalation, and arbitrary file write…

exploitationpenetration-testingvulnerability-analysis+1
3245 years ago
EmbedInHTML preview

EmbedInHTML

GitHubarno0x/embedinhtml

Embed and hide any file in an HTML file

payload-generationphishing-toolssocial-engineering+1
4899 years ago
BobTheSmuggler preview

BobTheSmuggler

GitHubthecyb3ralpha/bobthesmuggler

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

educationencryption-decryption-toolspayload-development+4
5971 year ago
PyShell preview

PyShell

GitHubjoelgmsec/pyshell

Multi-platform Python webshell providing remote shell access on web servers with command history, file upload/download, and directory traversal…

payload-generationpenetration-testingremote-access-tool+1
3191 month ago
CVE-2022-39952 preview

CVE-2022-39952

GitHubhorizon3ai/cve-2022-39952

Proof-of-concept exploit for CVE-2022-39952 targeting Fortinet FortiNAC. Abuses keyUpload.jsp endpoint for arbitrary file write to deploy cron-based…

exploitationpayload-developmentpenetration-testing+3
2653 years ago
CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC preview

CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC

GitHubduc-nt/cve-2022-44268-imagemagick-arbitrary-file-read-poc

PoC payload generator for CVE-2022-44268 ImageMagick arbitrary file read vulnerability. Demonstrates exploitation via crafted PNG files for…

educationexploitationpayload-generation+3
2753 years ago
RAU_crypto preview

RAU_crypto

GitHubbao7uo/rau_crypto

Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)

encryption-decryption-toolsexploitationpayload-generation+3
1806 years ago
hiphp preview

hiphp

GitHubyasserbdj96/hiphp

PHP-based backdoor tool for remote website control via HTTP/HTTPS. Enables file management, command execution, and Tor connectivity with…

command-and-controlpayload-generationremote-access-tool+1
22011 days ago
Previous12…98Next