Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
537 results
CVE-2023-30092 preview

CVE-2023-30092

GitHubnawed20002/cve-2023-30092

Proof-of-concept exploit for SQL injection in Sourcecodester Online Pizza Ordering System 1.0. Demonstrates remote code execution and denial of…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
-CVE-2023-46450 preview

-CVE-2023-46450

GitHubyte121/-cve-2023-46450

Proof-of-concept for CVE-2023-46450: authenticated stored cross-site scripting (XSS) vulnerability in the Add Supplier function of Sourcecodester…

educationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2023-46449 preview

CVE-2023-46449

GitHubsajaljat/cve-2023-46449

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…

authenticationeducationmisconfiguration+3
2 years ago
CVE-2025-64027 preview

CVE-2025-64027

GitHubcybercrewinc/cve-2025-64027

Reflected Cross-Site Scripting in Snipe-IT CSV Import Workflow

exploitationinformation-gatheringpenetration-testing+3
9 months ago
CVE-2019-19633 preview

CVE-2019-19633

GitHubjra89/cve-2019-19633

lib/G/functions.php in Chevereto 1.0.0 through 1.1.4 Free, and through 3.13.5 Core, allows an attacker to perform bruteforce attacks without…

ids-ips-evasioninformation-gatheringpassword-attacks+2
6 years ago
ATSCAN preview

ATSCAN

GitHubalisamtechnology/atscan

Advanced dork Search & Mass Exploit Scanner

crawlerdns-subdomain-enumerationemail-harvesting+7
1.6k2 years ago
webhandler preview

webhandler

GitHublnxg33k/webhandler

Bash simulator to control a server using PHP system functions.

command-and-controlids-ips-evasionpayload-generation+3
1005 years ago
b374k preview

b374k

GitHubb374k/b374k

Single-file PHP webshell providing remote file management, command execution, bind/reverse shell, database connectivity, and process control for…

command-and-controldatabase-securitypenetration-testing+2
2.7k3 years ago
Wordpress-XMLRPC-Brute-Force-Exploit preview

Wordpress-XMLRPC-Brute-Force-Exploit

GitHub1n3/wordpress-xmlrpc-brute-force-exploit

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

exploitationinformation-gatheringpassword-attacks+3
4981 year ago
xcat preview

xcat

GitHuborf/xcat

Automated blind XPath injection exploitation tool with optimized data retrieval, built-in OOB HTTP server, and interactive REPL shell for file system…

exploitationinformation-gatheringvulnerability-analysis+2
4103 years ago
CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera preview

CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera

GitHubpuliczek/cve-2022-0337-poc-google-chrome-microsoft-edge-opera

🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak -…

data-exfiltrationeducationexploitation+2
3414 years ago
CVE-2018-0296 preview

CVE-2018-0296

GitHubyassineaboukir/cve-2018-0296

Exploit script for Cisco ASA path traversal (CVE-2018-0296) that extracts system information, active sessions, and valid usernames from vulnerable…

exploitationinformation-gatheringnetwork-security+3
2052 years ago
acunetix_0day preview

acunetix_0day

GitHubdzonerzy/acunetix_0day

Standalone RCE exploit for Acunetix WVS 10 that delivers a Meterpreter reverse shell with SYSTEM privileges via staged payload download and execution.

exploitationpenetration-testingprivilege-escalation+1
19210 years ago
CVE-2021-21123-PoC-Google-Chrome preview

CVE-2021-21123-PoC-Google-Chrome

GitHubpuliczek/cve-2021-21123-poc-google-chrome

🐱‍💻 👍 Google Chrome - File System Access API - vulnerabilities reported by Maciej Pulikowski | Total Bug Bounty Reward: $5.000 | CVE-2021-21123…

educationexploitationphishing-tools+3
1755 years ago
Predator preview

Predator

GitHubs0md3v/predator

Prototype anti-automation system demonstrating bot detection, malformed HTML traps, invisible links, and signature-reversing honeypot techniques for…

anti-botcrawlerids-ips-evasion+3
1275 years ago
wp-file-manager-CVE-2020-25213 preview

wp-file-manager-CVE-2020-25213

GitHubmansoorr123/wp-file-manager-cve-2020-25213

Shell script exploit for CVE-2020-25213 targeting unauthenticated arbitrary file upload in WordPress File Manager plugin (<6.9), enabling full system…

exploitationpenetration-testingvulnerability-analysis+2
585 years ago
CVE-2023-48788 preview

CVE-2023-48788

GitHubhorizon3ai/cve-2023-48788

Proof-of-concept exploit for Fortinet FortiClient EMS SQL injection vulnerability (CVE-2023-48788). Demonstrates unauthenticated SQL injection to…

exploitationpenetration-testingvulnerability-analysis+1
542 years ago
CVE-2023-43261 preview

CVE-2023-43261

GitHubwin3zz/cve-2023-43261

Proof-of-concept exploit for CVE-2023-43261 targeting Milesight industrial routers. Demonstrates credential leakage via unprotected system logs and…

exploitationiot-securitymisconfiguration+3
572 years ago
Previous12…30Next