Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
CVE-2023-38545-libcurl-SOCKS5-heap-buffer-overflow preview

CVE-2023-38545-libcurl-SOCKS5-heap-buffer-overflow

GitHubfatmo666/cve-2023-38545-libcurl-socks5-heap-buffer-overflow

Proof-of-concept exploit for CVE-2023-38545, a heap buffer overflow in libcurl's SOCKS5 proxy handshake triggered via a malicious HTTP 301 redirect…

binary-exploitationexploitationfuzzing+2
6
2 years ago
CVE-2018-8065 preview

CVE-2018-8065

GitHubegebalci/cve-2018-8065

Flexense HTTP Server <= 10.6.24 - Denial Of Service Exploit

exploitationpenetration-testingvulnerability-analysis+1
68 years ago
CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit preview

CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit

GitHubadityabhatt3010/cve-2025-61882-oracle-e-business-suite-pre-auth-rce-exploit

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

exploitationforensicsincident-response+4
1211 months ago
CVE-2026-23918-test preview

CVE-2026-23918-test

GitHub12lie20/cve-2026-23918-test

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66…

binary-exploitationexploitationfuzzing+3
44 months ago
CVE-2016-2569 preview

CVE-2016-2569

GitHubamit-raut/cve-2016-2569

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of…

exploitationvulnerability-analysisweb-security
68 years ago
CVE-2025-55315-detection-playground preview

CVE-2025-55315-detection-playground

GitHubnickcopi/cve-2025-55315-detection-playground

Playground to experiment with different behavior on patched/unpatched Kestrel for the CVE-2025-55315 HTTP smuggling vulnerability

exploitationpenetration-testingvulnerability-analysis+1
711 months ago
CVE-2026-73315 preview

CVE-2026-73315

GitHubbombobombone/cve-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

exploitationvulnerability-analysisweb-application-exploitation+1
7 days ago
Qlik-View-12.60-Including-SR-Stored-Cross-Site-Scripting-CVE-2022-42248 preview

Qlik-View-12.60-Including-SR-Stored-Cross-Site-Scripting-CVE-2022-42248

GitHubozozuz/qlik-view-12.60-including-sr-stored-cross-site-scripting-cve-2022-42248

Proof-of-concept exploit for CVE-2022-42248, a stored cross-site scripting vulnerability in QlikView Ajax Client allowing remote attackers to execute…

exploitationinformation-gatheringpenetration-testing+3
54 months ago
CVE-2024-40275_Scanner preview

CVE-2024-40275_Scanner

GitHubburjoy/cve-2024-40275_scanner

Scanner for CVE-2024-40725 Apache HTTP Server source-code disclosure; probes direct and subrequest paths, fingerprints affected versions, and outputs…

misconfigurationvulnerability-analysisvulnerability-scanners+2
29 days ago
log4shell-cve-lab preview

log4shell-cve-lab

GitHubvaibhav91one/log4shell-cve-lab

Intentionally vulnerable Log4j 2.14.1 HTTP service for hands-on practice with CVE-2021-44228 (Log4Shell) in an isolated sandbox environment.

educationexploitationlabs-practice+2
16 days ago
CVE-2019-10092_Docker preview

CVE-2019-10092_Docker

GitHubmotikan2010/cve-2019-10092_docker

CVE-2019-10092 Docker - Apache HTTP Server

exploitationpenetration-testingvulnerability-analysis+2
46 years ago
CVE-2021-32099 preview

CVE-2021-32099

GitHubzjicmdarkwing/cve-2021-32099

Proof-of-concept exploit for CVE-2021-32099, a SQL injection vulnerability in Pandora FMS, demonstrating session hijacking via crafted HTTP requests.

exploitationpenetration-testingvulnerability-analysis+2
54 years ago
CVE-2021-41773-Apache-Lab preview

CVE-2021-41773-Apache-Lab

GitHubs-amnajafri/cve-2021-41773-apache-lab

Docker-based lab for reproducing CVE-2021-41773 (Apache HTTP Server 2.4.49) through controlled path traversal and file disclosure using a custom…

educationexploitationlabs-practice+4
1 month ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubgeniuszly/cve-2024-24919

Proof-of-concept exploit script for CVE-2024-24919 that scans target URLs via HTTP POST requests, analyzes responses for unauthorized access or data…

exploitationpayload-generationpenetration-testing+3
61 year ago
CVE-2021-40438 preview

CVE-2021-40438

GitHubxiaojiangxl/cve-2021-40438

Proof-of-concept exploit for Apache HTTP Server mod_proxy SSRF vulnerability (CVE-2021-40438) affecting versions <= 2.4.48, enabling server-side…

exploitationpenetration-testingreconnaissance+2
54 years ago
CVE-2017-7529-POC preview

CVE-2017-7529-POC

GitHubmaxsecurity/cve-2017-7529-poc

Proof-of-concept exploit for CVE-2017-7529, an integer overflow in Nginx cache that leaks backend server IPs and sensitive information via crafted…

exploitationinformation-gatheringpenetration-testing+2
47 years ago
CVE-2020-11547--PRTG-Network-Monitor-Information-Disclosure preview

CVE-2020-11547--PRTG-Network-Monitor-Information-Disclosure

GitHubch-rigu/cve-2020-11547--prtg-network-monitor-information-disclosure

Exploit for CVE-2020-11547: unauthenticated information disclosure in PRTG Network Monitor via crafted HTTP requests to /public/login.htm or…

exploitationinformation-gatheringreconnaissance+2
45 years ago
Apache-Commons-Text-CVE-2022-42889 preview

Apache-Commons-Text-CVE-2022-42889

GitHub0xmaximus/apache-commons-text-cve-2022-42889

Burp Bounty profile for detecting Apache Text4Shell (CVE-2022-42889), an RCE in Commons Text 1.5-1.9, by scanning HTTP requests.

api-security-testingexploitationpenetration-testing+3
43 years ago
Previous1…91011…25Next