Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
7391 results
selenium-node-takeover-kit preview

selenium-node-takeover-kit

GitHubjonstratton/selenium-node-takeover-kit

A collection of selenium tests that might aid it takeover of a selenium node

command-and-controldata-exfiltrationexploit-frameworks+6
3
9 months ago
CVE-2026-22200 preview

CVE-2026-22200

GitHubhorizon3ai/cve-2026-22200

CVE-2026-22200: Arbitrary file read + CNEXT RCE in osTicket

binary-exploitationexploitationpayload-generation+3
127 months ago
CVE-2022-24818 preview

CVE-2022-24818

GitHubmbadanoiu/cve-2022-24818

CVE-2022-24818: Java Deserialization via Unchecked JNDI Lookups in GeoServer and GeoTools

exploitationpenetration-testingvulnerability-analysis+1
2 years ago
wp2shell-poc preview

wp2shell-poc

GitHubdeadexpl0it/wp2shell-poc

wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137

ctfeducationexploitation+5
220 days ago
CVE-2022-44900-demo-lab preview

CVE-2022-44900-demo-lab

GitHub0xless/cve-2022-44900-demo-lab

Demo webapp vulnerable to CVE-2022-44900

educationexploitationlabs-practice+3
17 months ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubdnr6419/cve-2021-29447

Automated PoC for CVE-2021-29447, a WordPress XXE injection vulnerability in the media library. Includes Docker-based environment setup and…

educationexploitationpenetration-testing+3
34 years ago
CVE-2024-23897 preview

CVE-2024-23897

GitHubh4x0r-dz/cve-2024-23897

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

exploitationinformation-gatheringpenetration-testing+3
2082 years ago
cve-2021-38314 preview

cve-2021-38314

GitHubphrantom/cve-2021-38314

Python exploit for CVE-2021-38314 targeting unauthenticated information disclosure in the Gutenberg Template Library & Redux Framework WordPress…

exploitationinformation-gatheringpenetration-testing+2
64 years ago
wordpress-php-object-helper preview

wordpress-php-object-helper

GitHubrandomrobbiebf/wordpress-php-object-helper

Know a plugin has a php object exploit but need to find which lib to use?

exploit-frameworkspenetration-testingreconnaissance+3
33 years ago
JDSer-ngng preview

JDSer-ngng

GitHubnccgroup/jdser-ngng

A Burp Extender plugin, that will deserialized java objects and encode them in XML using the Xtream library.

penetration-testingvulnerability-analysisweb-application-exploitation+1
2611 years ago
AMFDSer-ngng preview

AMFDSer-ngng

GitHubnccgroup/amfdser-ngng

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
2711 years ago
CVE-2017-9841-PHPUnit-Remote-Code-Execution-PoC preview

CVE-2017-9841-PHPUnit-Remote-Code-Execution-PoC

GitHubkrisdewa/cve-2017-9841-phpunit-remote-code-execution-poc

CVE-2017-9841 is a Remote Code Execution (RCE) vulnerability in the PHPUnit library affecting versions prior to 5.6.3 and 6.x prior to 6.4.2.

educationexploitationpayload-development+3
3 months ago
CVE-2024-23222-Coruna-Exploit-Kit-Deobfuscated preview

CVE-2024-23222-Coruna-Exploit-Kit-Deobfuscated

GitHubrohitberiwala/cve-2024-23222-coruna-exploit-kit-deobfuscated

Comprehensive deobfuscated research of the Coruna iOS exploit kit targeting CVE-2024-23222. Analysis of WebKit Type Confusion, PAC Bypass, and…

binary-exploitationeducationexploitation+6
66 months ago
Log4Shell-PoC preview

Log4Shell-PoC

GitHubjosemariamicoli/log4shell-poc

**Log4Shell PoC is a high-fidelity exploitation environment designed to replicate the CVE-2021-44228 vulnerability.** It provides a containerized…

command-and-controleducationexploitation+6
7 months ago
CVE-2025-13390 preview

CVE-2025-13390

GitHubd0n601/cve-2025-13390

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

authenticationexploitationpayload-generation+4
9 months ago
mojarragadget preview

mojarragadget

GitHubsynacktiv/mojarragadget

Proof-of-concept exploit for a Java gadget chain in the Mojarra library, demonstrating deserialization vulnerability exploitation for versions 2.3…

binary-analysisexploitationpayload-development+2
154 years ago
Log4j-CVE-2021-44228 preview

Log4j-CVE-2021-44228

GitHubdark-ninja10/log4j-cve-2021-44228

On Thursday (December 9th), a 0-day exploit in the popular Java logging library log4j (version 2) was discovered that results in Remote Code…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
perl_spreadsheet_excel_rce_poc preview

perl_spreadsheet_excel_rce_poc

GitHubhaile01/perl_spreadsheet_excel_rce_poc

POC for RCE vulnerability in ParseExcel library, and ParseXLSX too, as a depending library

binary-exploitationcode-analysisexploitation+3
181 year ago
Previous12…100Next