Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
Magneto-PolyShell preview

Magneto-PolyShell

GitHubjenderal92/magneto-polyshell

Magento 2 Unauthenticated RCE Exploit – Uploads a PHP webshell via GraphQL product lookup + guest cart custom options. Multi‑threaded, auto‑detects…

exploitationpayload-generationpenetration-testing+3
3 months ago
CVE-2024-7954 preview

CVE-2024-7954

GitHubr0otk3r/cve-2024-7954

Unauthenticated remote command execution exploit for SPIP CMS 4.2.8 (CVE-2024-7954) with proxy support and live output retrieval.

educationexploitationpenetration-testing+3
1 year ago
XM_ONVIF_auth_bypass preview

XM_ONVIF_auth_bypass

GitHubkostasereksonas/xm_onvif_auth_bypass

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

exploitationhardware-iot-securityiot-security+3
26 months ago
CVE-2025-66955 preview

CVE-2025-66955

GitHubthewoodenbench/cve-2025-66955

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the…

exploitationinformation-gatheringpenetration-testing+2
8 months ago
CVE-2025-51400 preview

CVE-2025-51400

GitHubthewhiteevil/cve-2025-51400

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages # Date: 09/06/2025

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-51398 preview

CVE-2025-51398

GitHubthewhiteevil/cve-2025-51398

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-51397 preview

CVE-2025-51397

GitHubthewhiteevil/cve-2025-51397

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Surname

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-51396 preview

CVE-2025-51396

GitHubthewhiteevil/cve-2025-51396

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

exploitationinformation-gatheringpenetration-testing+3
11 year ago
Hikvision-City-Hunter preview

Hikvision-City-Hunter

GitHubvoidsshadows/hikvision-city-hunter

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

exploitationinformation-gatheringiot-security+5
199 months ago
CVE-2026-33267-PoC preview

CVE-2026-33267-PoC

GitHubboreas37/cve-2026-33267-poc

CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

exploitationvulnerability-analysisweb-application-exploitation+1
421 days ago
shannon preview

shannon

GitHubkeygraphhq/shannon

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

ai-securityapi-security-testingcode-analysis+5
47.6k9h 21m ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
61 month ago
CVE-2025-45960 preview

CVE-2025-45960

GitHubpracharapol/cve-2025-45960

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in tawk.to Live Chat 1.6.1, demonstrating JavaScript injection via unsanitized…

exploitationpenetration-testingvulnerability-analysis+2
51 year ago
CVE-2019-15233 preview

CVE-2019-15233

GitHubl0nax/cve-2019-15233

Proof-of-concept exploit for CVE-2019-15233: Cross-Site Scripting (XSS) vulnerability in Live Input Macros for Confluence, enabling session hijacking…

exploitationpenetration-testingvulnerability-analysis+2
6 years ago
CVE-2020-9758 preview

CVE-2020-9758

GitHubari034/cve-2020-9758

Form submission for vulnerability in livezilla

exploitationinformation-gatheringpenetration-testing+3
36 years ago
GhostStrike preview

GhostStrike

GitHubmylo-2001/ghoststrike

Fully automated Spring4Shell (CVE-2022-22965) + GitLab RCE framework

exploitationpayload-generationpenetration-testing+3
19 months ago
CVE-2025-51401 preview

CVE-2025-51401

GitHubthewhiteevil/cve-2025-51401

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Chat Name Field Triggers on Chat Owner Transfer

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2018-12598 preview

CVE-2018-12598

GitHubalt3kx/cve-2018-12598

CVE-2018-12598

exploitationinformation-gatheringpenetration-testing+2
8 years ago
Previous12Next