Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
CVE-2026-33718 preview

CVE-2026-33718

GitHubhorkimhab/cve-2026-33718

Proof-of-concept exploit for CVE-2026-33718 demonstrating command injection in OpenHands' Git Diff Handler. Educational resource for vulnerability…

educationlabs-practicepenetration-testing+2
1 month ago
CVE-2026-59941 preview

CVE-2026-59941

GitHubfar00t01/cve-2026-59941

Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps

educationexploitationpayload-generation+3
26 days ago
CVE-2026-29954 preview

CVE-2026-29954

GitHubb0b0haha/cve-2026-29954

Proof-of-concept demonstrating SSRF and HTTP header injection in KubePlus ResourceComposition, enabling cloud metadata access and IAM credential…

cloud-securityexploitationpenetration-testing+2
5 months ago
Spring-CVE preview

Spring-CVE

GitHubkh4sh3i/spring-cve

This includes CVE-2022-22963, a Spring SpEL / Expression Resource Access Vulnerability, as well as CVE-2022-22965, the spring-webmvc/spring-webflux…

code-analysisexploitationpayload-development+3
144 years ago
CVE-2021-35492 preview

CVE-2021-35492

GitHubn4nj0/cve-2021-35492

Denial of Service tool for Wowza Streaming Engine <= 4.8.11+5 - Uncontrolled Resource Consumption (CVE-2021-35492)

exploitationpenetration-testingvulnerability-analysis+1
4 years ago
CVE-2024-34222 preview

CVE-2024-34222

GitHubdovankha/cve-2024-34222

Proof-of-concept for SQL injection vulnerability in SourceCodester Human Resource Management System 1.0, demonstrating arbitrary SQL command…

database-securityexploitationpenetration-testing+2
2 years ago
Metasploit-Exploits-CVE-2023-6710 preview

Metasploit-Exploits-CVE-2023-6710

GitHubdedsec-47/metasploit-exploits-cve-2023-6710

Welcome to the Metasploit Exploits Repository, your go-to resource for a comprehensive collection of cutting-edge exploits designed for penetration…

educationexploit-frameworkspayload-development+4
12 years ago
magnus_billing_7.3.0_RCE_CVE-2023-30258 preview

magnus_billing_7.3.0_RCE_CVE-2023-30258

GitHubkayl22/magnus_billing_7.3.0_rce_cve-2023-30258

Exploit for CVE-2023-30258: remote code execution in MagnusBilling 7.3.0 via unsanitized 'democ' parameter in icepay.php, enabling command injection…

command-and-controlexploitationpayload-generation+3
8 months ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

authenticationexploitationpenetration-testing+3
12 years ago
cve-2024-38819-lab preview

cve-2024-38819-lab

GitHubtrevorputbrese/cve-2024-38819-lab

Hands-on lab demonstrating CVE-2024-38819 Spring Framework path traversal vulnerability with vulnerable and patched Spring Boot deployments for…

educationlabs-practicemisconfiguration+3
2 months ago
CVE-2026-50338 preview

CVE-2026-50338

GitHubjohanneslks/cve-2026-50338

Proof-of-concept exploit for CVE-2026-50338: cross-issuer authentication bypass in Spring Cloud Azure B2C resource servers. Demonstrates token…

authentication-authorizationeducationexploitation+3
1 month ago
CVE-2023-47564 preview

CVE-2023-47564

GitHubc411e/cve-2023-47564

CVE-2023-47564

authentication-authorizationinformation-gatheringpenetration-testing+2
2 years ago
fuzzdb preview

fuzzdb

GitHubfuzzdb-project/fuzzdb

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

curated-resourcesdns-fuzzingfuzzing+4
9.0k6 years ago
sonar.js preview

sonar.js

GitHubmandatoryprogrammer/sonar.js

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

exploitationinformation-gatheringpenetration-testing+3
55210 years ago
fastjson-jsontype-rce-lab preview

fastjson-jsontype-rce-lab

GitHubdinosn/fastjson-jsontype-rce-lab

Docker labs + defensive scanner for fastjson remote-class-load RCE. fastjson 1.2.66-1.2.83: @JSONType resource probe (CVE-2026-16723). fastjson2…

dynamic-analysis-sandboxingeducationexploitation+5
2051 month ago
Bug-Bounty preview

Bug-Bounty

GitHubzapstiko/bug-bounty

Here Are Some Bug Bounty Resource From Twitter

curated-resourceseducationpenetration-testing+3
13318 days ago
CVE-2021-26855 preview

CVE-2021-26855

GitHubh4x0r-dz/cve-2021-26855

PoC exploit for CVE-2021-26855 (Exchange Server SSRF) with user enumeration, mail header reading, and vulnerability detection. Supports…

exploitationinformation-gatheringpenetration-testing+3
985 years ago
XSSight preview

XSSight

GitHubnu11secur1ty/xssight

Educational resource on Cross-site Scripting (XSS) attack techniques, covering non-persistent, persistent, and DOM-based vectors with practical…

educationinformation-gatheringpenetration-testing+3
105 months ago
Previous12Next