Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
186 results
parameth preview
Archived

parameth

GitHubmak-/parameth

This tool can be used to brute discover GET and POST parameters

information-gatheringpenetration-testingreconnaissance+3
1.4k
7 years ago
exploit_cve-2021-29447 preview

exploit_cve-2021-29447

GitHubmega8bit/exploit_cve-2021-29447

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…

educationexploitationpenetration-testing+2
73 years ago
poc-cve-2026-32255 preview

poc-cve-2026-32255

GitHubkoadt/poc-cve-2026-32255

This repository contains a proof of concept (POC) for CVE-2026-32255, a high-severity Server-Side Request Forgery (SSRF) vulnerability in Kan, an…

educationexploitationpenetration-testing+3
26 months ago
CVE-2020-17144 preview

CVE-2020-17144

GitHubzcgonvh/cve-2020-17144

weaponized tool for CVE-2020-17144

command-and-controlexploitationpayload-generation+2
1585 years ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
13 days ago
CVE-2021-31761 preview

CVE-2021-31761

GitHubmesh3l911/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

exploitationpenetration-testingremote-access-tool+2
55 years ago
CVE-2024-12856 preview

CVE-2024-12856

GitHubnu113d/cve-2024-12856

An exploit for Four-Faith routers to get a reverse shell

exploitationpenetration-testingremote-access-tool+2
31 year ago
CVE-2022-46169 preview

CVE-2022-46169

GitHub0xn7y/cve-2022-46169

Exploit for CVE-2022-46169

authentication-authorizationcommand-and-controlexploitation+3
12 years ago
backcookie preview

backcookie

GitHubjofpin/backcookie

Small backdoor using cookie.

command-and-controlpayload-generationpenetration-testing+3
639 years ago
CVE-2024-10924-Exploit preview

CVE-2024-10924-Exploit

GitHubnxploited/cve-2024-10924-exploit

Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 - 9.1.1.1 - Authentication Bypass

authentication-authorizationeducationexploitation+3
21 year ago
G0BurpSQLmaPI preview

G0BurpSQLmaPI

GitHubnu11secur1ty/g0burpsqlmapi

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

exploitationpayload-generationpenetration-testing+2
36 days ago
CVE-2017-8056 preview

CVE-2017-8056

GitHubitzexploit/cve-2017-8056

Python-based exploit for CVE-2017-8056 targeting XML-RPC denial-of-service vulnerability in web applications.

exploitationpenetration-testingvulnerability-analysis+1
1 year ago
golang preview

golang

GitHubdrset/golang

test for CVE-2018-6574: go get RCE pentesterlab

exploitationpenetration-testingremote-access-tool+2
6 years ago
CVE-2020-14882 preview

CVE-2020-14882

GitHubdanny-lli/cve-2020-14882

This script allows for remote code execution (RCE) on Oracle WebLogic Server

exploitationpenetration-testingremote-access-tool+2
23 years ago
cve-2025-50946 preview

cve-2025-50946

GitHubrunt1me/cve-2025-50946

Exploit script for CVE-2025-50946

exploitationpenetration-testingred-teaming+3
4 months ago
CVE-2009-4623 preview

CVE-2009-4623

GitHubsammonsempes/cve-2009-4623

Remote shell on CVE-2009-4623

exploitationpenetration-testingremote-access-tool+2
3 years ago
put2win preview

put2win

GitHubdevploit/put2win

Script to automate PUT HTTP method exploitation to get shell

exploitationpenetration-testingshellcode-generation+1
1266 years ago
CVE-2006-3392 preview

CVE-2006-3392

GitHubivanglinkin/cve-2006-3392

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…

exploitationinformation-gatheringpenetration-testing+3
143 years ago
Previous12…11Next