Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
CVE-2026-73570 preview

CVE-2026-73570

GitHubjishino567/cve-2026-73570

Python PoC for CVE-2026-73570, an SMTP command injection in Zimbra. Sends malformed RCPT TO payloads to trigger shell command execution via…

email-securityexploitationpenetration-testing+3
2
1 month ago
CVE-2023-27163-InternalProber preview

CVE-2023-27163-InternalProber

GitHubsamh4cks/cve-2023-27163-internalprober

A tool to perform port scanning using vulnerable Request-Baskets

exploitationpenetration-testingport-scanning+3
53 years ago
CVE-2023-27163-exploit preview

CVE-2023-27163-exploit

GitHubjeanback1/cve-2023-27163-exploit

SSRF exploit for CVE-2023-27163 in request-baskets, enabling internal port scanning, cloud metadata probing, and service discovery via malicious…

cloud-securityexploitationport-scanning+3
4 months ago
CVE-2024-23692-RCE preview

CVE-2024-23692-RCE

GitHubwanlichangchengwanlichang/cve-2024-23692-rce

Exploit for CVE-2024-23692, a remote code execution vulnerability in Rejetto HTTP File Server (HFS) 2.3 and below. Includes mass scanning with zmap…

exploitationport-scanningreconnaissance+2
2 years ago
Moodle-CVE-2018-1042 preview

Moodle-CVE-2018-1042

GitHubudpsycho/moodle-cve-2018-1042

Script to exploit CVE-2018-1042 in order to do internal port scans.

exploitationpenetration-testingport-scanning+2
24 years ago
CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner preview

CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner

GitHubcyberdudebivash/cyberdudebivash-fortisiem-cve-2025-64155-scanner

Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and…

command-and-controlexploitationpenetration-testing+3
18 months ago
Exploit_CVE-2023-27163 preview

Exploit_CVE-2023-27163

GitHubj0ey17/exploit_cve-2023-27163

Proof of Concept exploit for Server Side Request Forgery vulnerability in Requests Basket v1.2.1 and before.

exploitationpenetration-testingport-scanning+3
11 year ago
CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer preview

CVE-2023-27163-Request-Baskets-Local-Ports-Bruteforcer

GitHubtheopaid/cve-2023-27163-request-baskets-local-ports-bruteforcer

PoC and internal port brute-forcer for CVE-2023-27163

exploitationport-scanningreconnaissance+2
11 year ago
CVE-2023-27163-ssrf-to-port-scanning preview

CVE-2023-27163-ssrf-to-port-scanning

GitHubrishabh-kumar-cyber-sec/cve-2023-27163-ssrf-to-port-scanning

It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU'…

ctfpenetration-testingport-scanning+2
2 years ago
sunflower_exp preview

sunflower_exp

GitHubbaimaobg/sunflower_exp

Sunflower CVE-2022-10270 vulnerability exploitation tool

exploitationpenetration-testingport-scanning+3
43 years ago
SSRFX preview

SSRFX

GitHubnonenotnull/ssrfx

CVE-2014-4210+Redis未授权访问

exploitationpenetration-testingport-scanning+3
989 years ago
Blind-SSRF-CVE-2020-15002 preview

Blind-SSRF-CVE-2020-15002

GitHubskr0x1c0/blind-ssrf-cve-2020-15002

https://hackerone.com/reports/865652

exploitationport-scanningreconnaissance+2
5 years ago
POC-IngressNightmare-CVE-2025-1974 preview

POC-IngressNightmare-CVE-2025-1974

GitHubbiitts/poc-ingressnightmare-cve-2025-1974

Builds a shell.so reverse shell payload for CVE-2025-1974 (IngressNightmare) using Alpine Linux in Docker, with hardcoded IP and port configuration.

container-securityexploitationpayload-development+3
1 year ago
CVE-2019-13956 preview

CVE-2019-13956

GitHubrhbb/cve-2019-13956

Dockerized proof-of-concept exploit for CVE-2019-13956, targeting a web application vulnerability accessible via HTTP on port 8090.

container-securityexploitationpenetration-testing+2
6 years ago
JavaPayload preview

JavaPayload

GitHubschierlm/javapayload

JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not…

exploitationmisconfigurationpayload-development+3
1281 year ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubnsflabs/cve-2020-5902

Python scanner to detect CVE-2020-5902 RCE vulnerability in F5 BIG-IP TMUI. Tests unauthenticated remote systems for arbitrary command execution via…

exploitationpenetration-testingremote-access-tool+2
86 years ago
CVE-2024-23113 preview

CVE-2024-23113

GitHubpuckiestyle/cve-2024-23113

Detects CVE-2024-23113 format string vulnerability in FortiGate FGFM service via SSL connection on port 541, sending crafted payloads to verify RCE…

exploitationnetwork-securitypenetration-testing+2
11 year ago