Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
61 results
CVE-2024-42992 preview

CVE-2024-42992

GitHubthanhh23/cve-2024-42992

CVE-2024-42992

data-exfiltrationexploitationpenetration-testing+2
2
2 years ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
311 days ago
CVE-2018-7600 preview
Archived

CVE-2018-7600

GitHubfirefart/cve-2018-7600

Python exploit for CVE-2018-7600 enabling unauthenticated remote code execution on Drupal 7.x versions below 7.58.

exploitationpenetration-testingred-teaming+2
718 years ago
CVE-2018-8581 preview

CVE-2018-8581

GitHubwyatu/cve-2018-8581

CVE-2018-8581 | Microsoft Exchange Server Elevation of Privilege Vulnerability

email-securityexploitationlateral-movement+4
3317 years ago
CVE-2021-4191_Exploits preview

CVE-2021-4191_Exploits

GitHubadelittle/cve-2021-4191_exploits

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

api-security-testingexploitationinformation-gathering+3
3 years ago
CVE-2026-21440-POC-EXP preview

CVE-2026-21440-POC-EXP

GitHubtibbersv6/cve-2026-21440-poc-exp

Proof-of-concept exploit for CVE-2026-21440, enabling file upload and remote command execution on Windows web servers with built-in sensitive path…

exploitationpayload-developmentpenetration-testing+3
7 months ago
CVE-2019-19919 preview

CVE-2019-19919

GitHubfazilbaig1/cve-2019-19919

Handlebars Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Vulnerability

command-and-controlexploitationpayload-generation+2
61 year ago
CVE-2017-9841 preview

CVE-2017-9841

GitHubdream434/cve-2017-9841

Exploit script for CVE-2017-9841 targeting PHP unit test remote code execution. Includes a local test environment via Docker for educational security…

educationexploitationpenetration-testing+2
11 year ago
CVE-2024-29269 preview

CVE-2024-29269

GitHubdream434/cve-2024-29269

An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.

command-and-controleducationexploitation+2
1 year ago
CVE-2023-27372 preview

CVE-2023-27372

GitHubdream434/cve-2023-27372

Exploit script for CVE-2023-27372 targeting SPIP CMS, enabling remote code execution for authorized security testing and educational purposes.

educationexploitationpenetration-testing+2
1 year ago
CVE-2024-31819 preview

CVE-2024-31819

GitHubdream434/cve-2024-31819

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the…

educationexploitationpenetration-testing+2
1 year ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubsl4cky/cve-2018-7600

Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)

exploitationinformation-gatheringpenetration-testing+2
48 years ago
n8n-RCE preview

n8n-RCE

GitHubabdulrkb/n8n-rce

Remote Code Execution via n8n Workflows (Based on CVE-2025-68613)

educationexploitationpenetration-testing+3
8 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubinzegosec/cve-2026-23744

Exploit for MCPJam Inspector <=1.4.2 that triggers remote code execution via crafted HTTP requests, enabling unauthorized installation of MCP servers…

exploitationpenetration-testingremote-access-trojan+2
15 months ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.7k3 days ago
CVE-2024-6205 preview

CVE-2024-6205

GitHubj3r1ch0123/cve-2024-6205

This is a python written PoC of a recent vulnerability in a wordpress plugin. More information on that here

exploitationpayload-generationpenetration-testing+2
12 years ago
CVE-2023-30990 preview

CVE-2023-30990

GitHubsilentsignal/cve-2023-30990

CVE-2023-30990 exploits

command-and-controlexploitationpayload-development+3
60 years ago
CVE-2021-23369 preview

CVE-2021-23369

GitHubfazilbaig1/cve-2021-23369

Python exploit script for CVE-2021-23369, a Remote Code Execution vulnerability in Handlebars template engine versions before 4.7.7. Accepts a target…

code-analysisexploitationremote-access-tool+2
21 year ago
Previous1234Next