Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
488 results
CVE-2024-10508 preview

CVE-2024-10508

GitHubjenderal92/cve-2024-10508

This tool scans WordPress sites for vulnerabilities in the "RegistrationMagic" plugin (CVE-2024-10508). It checks for the presence of a specific…

information-gatheringvulnerability-analysisvulnerability-scanners+2
1
3 months ago
cve-2021-41773-docker-lab preview

cve-2021-41773-docker-lab

GitHubtwseptian/cve-2021-41773-docker-lab

Docker container lab to play/learn with CVE-2021-41773

container-securityeducationexploitation+3
4 years ago
log4shell-poc-lab preview

log4shell-poc-lab

GitHubobscuritylabs/log4shell-poc-lab

A lab demonstration of the log4shell vulnerability: CVE-2021-44228

container-securityeducationexploitation+3
94 years ago
CVE-2024-0406-POC preview

CVE-2024-0406-POC

GitHubwalidpyh/cve-2024-0406-poc

CVE-2024-0406 POC using symlinks

binary-exploitationeducationexploitation+3
51 year ago
CVE-2026-37064 preview

CVE-2026-37064

GitHubjfs-jfs/cve-2026-37064

Proof-of-concept exploit for CVE-2026-37064: unauthenticated user enumeration in Veno File Manager 4.4.9 via crafted POST request to…

exploitationinformation-gatheringreconnaissance+2
2 months ago
CVE-2022-32114 preview

CVE-2022-32114

GitHubbypazs/cve-2022-32114

An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted…

exploitationpenetration-testingvulnerability-analysis+2
14 years ago
CVE-2022-40490 preview

CVE-2022-40490

GitHubwhitej3rry/cve-2022-40490

Tiny File Manager v2.4.7 and below are vulnerable to Cross Site Scripting

exploitationmisconfigurationvulnerability-analysis+2
13 years ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubrnsss/cve-2021-42013

Exploit for Apache HTTP Server path traversal and file disclosure vulnerability CVE-2021-42013, enabling unauthorized access to files on vulnerable…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2026-39363 preview

CVE-2026-39363

GitHubf4s1on/cve-2026-39363

Batch vulnerability scanner for CVE-2026-39363 in Vite dev server, exploiting WebSocket origin validation bypass to read arbitrary files via…

exploitationpenetration-testingvulnerability-scanners+2
3 months ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub0xblackash/cve-2026-32475

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

educationpenetration-testingvulnerability-analysis+2
9 days ago
CVE-2024-33231 preview

CVE-2024-33231

GitHubfdzdev/cve-2024-33231

XSS Vulnerability via File Upload in Ferozo Webmail Application

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2024-27665 preview

CVE-2024-27665

GitHubthirukrishnan/cve-2024-27665

Proof-of-concept exploit for CVE-2024-27665, demonstrating stored XSS in Unifiedtransform's Syllabus file upload, with reproduction steps.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
oopso preview

oopso

GitHubb3rito/oopso

An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

information-gatheringosintreconnaissance+2
41 month ago
Mitigation-Apache-CVE-2021-41773- preview

Mitigation-Apache-CVE-2021-41773-

GitHubekamsinghwalia/mitigation-apache-cve-2021-41773-

Mitigation/fix of CVE-2021-41773 A Path Traversal And File Disclosure Vulnerability In Apache

configuration-auditingmisconfigurationscripting-automation+2
4 years ago
vbrute preview

vbrute

GitHubnccgroup/vbrute

Virtual host brute forcer

information-gatheringnetwork-mappingreconnaissance+1
2212 years ago
tomcat-cve-2020-1938-check preview

tomcat-cve-2020-1938-check

GitHubfatal0/tomcat-cve-2020-1938-check

Go-based scanner for Apache Tomcat AJP file read/inclusion vulnerability (CVE-2020-1938). Detects and exploits Ghostcat to read arbitrary files or…

exploitationnetwork-securityvulnerability-scanners+1
76 years ago
CVE-2026-13157 preview

CVE-2026-13157

GitHubminhhk68/cve-2026-13157

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

code-analysisexploitationpayload-development+4
1 month ago
CVE-2026-37067 preview

CVE-2026-37067

GitHubjfs-jfs/cve-2026-37067

Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract…

exploitationinformation-gatheringmisconfiguration+2
2 months ago
Previous1…111213…28Next