Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
CVE-2026-36958 preview

CVE-2026-36958

GitHubkirubel-cve/cve-2026-36958

Proof-of-concept for CVE-2026-36958, a denial-of-service vulnerability in U-SPEED Router firmware that exhausts resources via concurrent HTTP…

exploitationnetwork-securitypenetration-testing+2
4 months ago
CVE-2022-2414-POC preview

CVE-2022-2414-POC

GitHubsuperhac/cve-2022-2414-poc

Proof-of-concept exploit for CVE-2022-2414, an XML external entity (XXE) vulnerability in FreeIPA, enabling remote file retrieval via crafted HTTP…

exploitationinformation-gatheringpenetration-testing+2
14 years ago
CVE-2026-51416 preview

CVE-2026-51416

GitHubrenio-wow/cve-2026-51416

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

code-analysisstatic-analysisvulnerability-analysis+1
4 months ago
CVE-2026-23918-Passive-Audit preview

CVE-2026-23918-Passive-Audit

GitHubaa022/cve-2026-23918-passive-audit

Passive HTTP metadata auditor for CVE-2026-23918 exposure triage

information-gatheringreconnaissancevulnerability-scanners+1
4 months ago
CVE-2021-42697 preview

CVE-2021-42697

GitHubcxosmo/cve-2021-42697

Proof of concept exploit for CVE-2021-42697: Akka HTTP 10.1.x before 10.1.15 and 10.2.x before 10.2.7 can encounter stack exhaustion while parsing…

exploitationpenetration-testingvulnerability-analysis+1
14 years ago
CVE-2025-55315 preview

CVE-2025-55315

GitHubmartinfabianionut/cve-2025-55315

Proof-of-concept exploit for CVE-2025-55315 (.NET HTTP Request Smuggling). Demonstrates how improperly parsed chunked encoding lets attackers smuggle…

educationexploitationpenetration-testing+3
19 months ago
CVE-2024-4323 preview

CVE-2024-4323

GitHubd0rb/cve-2024-4323

Critical heap buffer overflow vulnerability in the handle_trace_request and parse_trace_request functions of the Fluent Bit HTTP server.

binary-exploitationcode-analysisexploitation+3
12 years ago
CVE-2026-21962-o preview

CVE-2026-21962-o

GitHubgregk4sec/cve-2026-21962-o

Proof-of-concept for CVE-2026-21962, a critical unauthenticated remote vulnerability in Oracle HTTP Server and WebLogic Proxy Plug-in, demonstrating…

exploitationpenetration-testingvulnerability-analysis+2
7 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubfaizdotid/cve-2021-41773

Path Traversal Apache HTTP Server 2.4.49/2.4.50

exploitationpenetration-testingvulnerability-analysis+2
9 months ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubrubbxalc/cve-2025-29927

Functional exploit for CVE-2025-29927, a critical Next.js middleware authorization bypass. Sends crafted HTTP requests with the…

authentication-authorizationexploitationpenetration-testing+3
11 year ago
CVE-2018-8004 preview

CVE-2018-8004

GitHubmosesrenegade/cve-2018-8004

CVE Repository for HTTP DeSynchronization Attacks

exploitationpenetration-testingvulnerability-analysis+2
16 years ago
cve-2022-21907-http.sys preview

cve-2022-21907-http.sys

GitHubiveresk/cve-2022-21907-http.sys

An unauthenticated attacker can send an HTTP request with an "Accept-Encoding" HTTP request header triggering a double free in the unknown…

binary-exploitationexploitationpenetration-testing+2
14 years ago
CVE-2025-62168 preview

CVE-2025-62168

GitHubshahroodcert/cve-2025-62168

Proof-of-concept scanner for CVE-2025-62168, a Squid Proxy information disclosure vulnerability that exposes HTTP authentication credentials,…

exploitationinformation-gatheringpenetration-testing+2
110 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubiris288/cve-2021-41773

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability (CVE-2021-41773) enabling file disclosure and source code leakage…

exploitationpenetration-testingreconnaissance+2
12 years ago
CVE-2024-28995-Nuclei-Template preview

CVE-2024-28995-Nuclei-Template

GitHubhuseyinstif/cve-2024-28995-nuclei-template

Nuclei template for detecting CVE-2024-28995, a directory traversal vulnerability in Serv-U FTP server, enabling file read via crafted HTTP requests.

exploitationpenetration-testingvulnerability-analysis+3
12 years ago
CVE-2025-58179-Check preview

CVE-2025-58179-Check

GitHubshitodcy/cve-2025-58179-check

Python script to verify SSRF and content spoofing vulnerabilities (CVE-2025-58179) in Astro's `/_image` endpoint, with automated PoC URL generation…

educationexploitationpenetration-testing+3
110 months ago
CVE-2024-9466 preview

CVE-2024-9466

GitHubholypryx/cve-2024-9466

Proof-of-concept script to detect CVE-2024-9466 by checking HTTP responses for a specific debug file path on target URLs.

exploitationpenetration-testingreconnaissance+2
11 year ago
CVE-2025-23167 preview

CVE-2025-23167

GitHubabhisek3122/cve-2025-23167

Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2

exploitationlabs-practicepenetration-testing+3
11 year ago
Previous1…131415…25Next