Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
213 results
CVE-2023-20198 preview

CVE-2023-20198

GitHubkacem-expereo/cve-2023-20198

Check a target IP for CVE-2023-20198 vulnerability in Cisco IOS XE web UI. Simple Python script for rapid exploitation verification.

exploitationpenetration-testingreconnaissance+2
1
2 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubz3n70/cve-2020-5902

BIGIP CVE-2020-5902 Exploit POC and automation scanning vulnerability

exploitationpenetration-testingvulnerability-analysis+1
24 years ago
POC-CVE-2021-41773 preview

POC-CVE-2021-41773

GitHubhattan515/poc-cve-2021-41773

Simple Python exploit script for Apache HTTPd 2.4.49 path traversal vulnerability (CVE-2021-41773). Supports single IP and file-based scanning.

exploitationpenetration-testingvulnerability-analysis+2
5 years ago
CVE-2022-1388-RCE-checker-and-POC-Exploit preview

CVE-2022-1388-RCE-checker-and-POC-Exploit

GitHubblind-intruder/cve-2022-1388-rce-checker-and-poc-exploit

Bash script to check and exploit CVE-2022-1388 RCE in F5 BIG-IP, with a curl-based POC for command execution.

exploitationpenetration-testingred-teaming+2
84 years ago
CVE-2024-22120-RCE-with-gopher preview

CVE-2024-22120-RCE-with-gopher

GitHubispique/cve-2024-22120-rce-with-gopher

This is my exploit for CVE-2024-22120, which involves an SSRF vulnerability inside an XXE with a Gopher payload.

command-and-controlexploitationpenetration-testing+2
32 years ago
ultrasploiter preview

ultrasploiter

GitLabvqkro/ultrasploiter

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

command-and-controlexploitationexploit-frameworks+9
6 days ago
CVE-2017-7921-Writeup-2026 preview

CVE-2017-7921-Writeup-2026

GitHubmk-ultra-project-monarch/cve-2017-7921-writeup-2026

Vulnerability research write-up on CVE-2017-7921 — a critical unauthenticated auth bypass in Hikvision IP cameras/DVRs/NVRs, covering root cause,…

educationexploitationiot-security+3
12 months ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubyassineaboukir/cve-2020-5902

Proof of concept for CVE-2020-5902

exploitationpenetration-testingred-teaming+2
706 years ago
CVE-2025-61304 preview

CVE-2025-61304

GitHubpentastic-be/cve-2025-61304

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address

exploitationpayload-generationpost-exploitation+3
211 months ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubamitlttwo/cve-2020-5902

In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface…

exploitationinformation-gatheringpenetration-testing+2
13 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubdnerzker/cve-2020-5902

Proof-of-concept exploit for CVE-2020-5902, a remote code execution vulnerability in F5 BIG-IP TMUI, with file read and command execution payloads…

exploitationinformation-gatheringreconnaissance+2
6 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubtim-hoekstra/cve-2024-24919

Multi-threaded exploit script for CVE-2024-24919 that scans a list of IP addresses and outputs results, intended for educational use.

educationexploitationpenetration-testing+2
2 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubmurataydemir/cve-2020-5902

[CVE-2020-5902] F5 BIG-IP Remote Code Execution (RCE)

exploitationexploit-frameworkspenetration-testing+3
26 years ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubtvdat20004/cve-2020-0688

CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys

exploitationpayload-generationpenetration-testing+3
1 year ago
php-cgi-cve-2024-4577 preview

php-cgi-cve-2024-4577

GitHubtpdlshdmlrkfmcla/php-cgi-cve-2024-4577

php-cgi-cve-2024-4577

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2025-57457 preview

CVE-2025-57457

GitHubrestdone/cve-2025-57457

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

command-and-controlexploitationpenetration-testing+2
1 year ago
XM_ONVIF_auth_bypass preview

XM_ONVIF_auth_bypass

GitHubkostasereksonas/xm_onvif_auth_bypass

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

exploitationhardware-iot-securityiot-security+3
38 months ago
DahuaLoginBypass preview

DahuaLoginBypass

GitHubbp2008/dahualoginbypass

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

authentication-authorizationexploitationiot-security+3
1993 months ago
Previous12…12Next