Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
43 results
CVE-2025-23048-POC preview

CVE-2025-23048-POC

GitHubabsholi7ly/cve-2025-23048-poc

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

authenticationexploitationpenetration-testing+3
4
10 months ago
CVE-2021-41773-PoC preview

CVE-2021-41773-PoC

GitHubzephrfish/cve-2021-41773-poc
exploitationpenetration-testingreconnaissance+2
1721 days ago
Log4Shell preview

Log4Shell

GitHubr00thunter/log4shell

Generic Scanner for Apache log4j RCE CVE-2021-44228

exploitationfuzzingpayload-generation+3
74 years ago
CVE-2025-34028-PoC-Commvault-RCE preview

CVE-2025-34028-PoC-Commvault-RCE

GitHubmattb709/cve-2025-34028-poc-commvault-rce

Proof-of-Concept (PoC) for CVE-2025-34028, a Remote Code Execution vulnerability in Commvault Command Center. This Python script scans single or…

exploitationpenetration-testingred-teaming+3
21 year ago
text4shell-scan preview

text4shell-scan

GitHubkiralab/text4shell-scan

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

exploitationfuzzingpenetration-testing+3
3 years ago
Log4j_scan_Advance preview

Log4j_scan_Advance

GitHubrk-000/log4j_scan_advance

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

exploitationfuzzingvulnerability-scanners+3
14 years ago
CVE-2025-29306-PoC-FoxCMS-RCE preview

CVE-2025-29306-PoC-FoxCMS-RCE

GitHubmattb709/cve-2025-29306-poc-foxcms-rce

Proof-of-Concept (PoC) for CVE-2025-29306, a Remote Code Execution vulnerability in FoxCMS. This Python script scans single or multiple targets,…

educationexploitationpenetration-testing+3
51 year ago
log4shell-docker-lab preview

log4shell-docker-lab

GitHubaxelcurmi/log4shell-docker-lab

Log4Shell (CVE-2021-44228) docker lab

container-securityeducationexploitation+3
4 years ago
svg-cheatsheet preview

svg-cheatsheet

GitHuballanlw/svg-cheatsheet

A cheatsheet for exploiting server-side SVG processors.

curated-resourceseducationinformation-gathering+4
8026 years ago
CVE-2020-5902-Scanner preview

CVE-2020-5902-Scanner

GitHubaqhmal/cve-2020-5902-scanner

Automated script for F5 BIG-IP scanner (CVE-2020-5902) using hosts retrieved from Shodan API.

exploitationinformation-gatheringpenetration-testing+3
553 years ago
CVE-2024-3273 preview

CVE-2024-3273

GitHubadhikara13/cve-2024-3273

Exploit for CVE-2024-3273, supports single and multiple hosts

command-and-controlexploitationpenetration-testing+3
132 years ago
pulse-exploit preview

pulse-exploit

GitHubandripwn/pulse-exploit

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

exploitationosintpenetration-testing+3
16 years ago
CVE-2025-53690-POC preview

CVE-2025-53690-POC

GitHuberiklearningsec/cve-2025-53690-poc

CVE-2025-53690 POC

defensive-toolsexploitationpenetration-testing+3
89 months ago
CVE-2020-8165 preview

CVE-2020-8165

GitHubhybryx/cve-2020-8165
command-and-controlexploitationpayload-generation+3
45 years ago
sonar.js preview

sonar.js

GitHubmandatoryprogrammer/sonar.js

A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and…

exploitationinformation-gatheringpenetration-testing+3
55210 years ago
pulsexploit preview

pulsexploit

GitHubaqhmal/pulsexploit

Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this…

exploitationinformation-gatheringpenetration-testing+3
96 years ago
CVE-2021-43798-Exploit-for-Windows-and-Linux preview

CVE-2021-43798-Exploit-for-Windows-and-Linux

GitHubravi5hanka/cve-2021-43798-exploit-for-windows-and-linux

Modified exploit for CVE-2021-43798 compatible with both Windows and Linux hosts.

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2025-8550 preview
Archived

CVE-2025-8550

GitHubbytereaper77/cve-2025-8550

XSS exploit for CVE-2025-8550 in atjiu pybbs ≤6.0.0

exploitationpayload-generationpenetration-testing+3
311 months ago
Previous123Next