Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
487 results
CVE-2026-66491 preview

CVE-2026-66491

GitHubtoanln-cov/cve-2026-66491

The Joomla extension PhocaCommander is vulnerable to Path Traversal in the getSource function - CVSS 8.2

exploitationinformation-gatheringpenetration-testing+3
23 days ago
CVE-2026-21013-PDF-JavaScript-Injection-via-Embedded-Script preview

CVE-2026-21013-PDF-JavaScript-Injection-via-Embedded-Script

GitHubgeorge0papasotiriou/cve-2026-21013-pdf-javascript-injection-via-embedded-script

Generates a PDF with embedded JavaScript to demonstrate CVE-2026-21013, an OpenAction injection leading to script execution in vulnerable PDF readers.

exploitationpayload-generationvulnerability-analysis+1
27 days ago
CVE-2026-66493 preview

CVE-2026-66493

GitHubtoanln-cov/cve-2026-66493

The Joomla extension PhocaCommander is vulnerable to Path Traversal in delete, copy, move actions - CVSS 6.4

data-exfiltrationexploitationpenetration-testing+3
23 days ago
CVE-2026-11784-Optimole-CSRF preview

CVE-2026-11784-Optimole-CSRF

GitHubalexmihailengineer/cve-2026-11784-optimole-csrf

Proof-of-concept exploit for CVE-2026-11784, a CSRF vulnerability in the Optimole WordPress plugin allowing arbitrary file overwrite via missing…

exploitationpenetration-testingvulnerability-analysis+2
2 months ago
CVE-2006-3392 preview

CVE-2006-3392

GitHubbrosck/cve-2006-3392

Python exploit for CVE-2006-3392, a path traversal in Webmin/Usermin allowing arbitrary file read, demonstrated by retrieving /etc/shadow.

exploitationinformation-gatheringpenetration-testing+3
31 year ago
blind-xxe-controller-CVE-2021-29447 preview

blind-xxe-controller-CVE-2021-29447

GitHubelf1337/blind-xxe-controller-cve-2021-29447

Arbitrary file read controller based on CVE-2021-29447

ctfexploitationvulnerability-analysis+2
33 years ago
CVE-2018-18820 preview

CVE-2018-18820

GitHubimpulsiveness/cve-2018-18820

Lightweight Python script to check Icecast servers for CVE-2018-18820 vulnerability, requiring only the requests library for automated detection.

exploitationinformation-gatheringpenetration-testing+2
28 months ago
CVE-2025-11988 preview

CVE-2025-11988

GitHubjfriedli/cve-2025-11988

Proof-of-concept exploit for CVE-2025-11988, demonstrating unauthenticated arbitrary JSON file deletion in WordPress Crypto plugin via crafted AJAX…

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
WPKiller preview

WPKiller

GitHubkakamband/wpkiller

CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit

exploitationpenetration-testingvulnerability-scanners+2
15 years ago
CVE-2019-20372 preview

CVE-2019-20372

GitHubmoften/cve-2019-20372

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2022-41401 preview

CVE-2022-41401

GitHubixsly/cve-2022-41401

Proof-of-concept exploit for CVE-2022-41401, a server-side request forgery (SSRF) vulnerability in OpenRefine <= v3.5.2, enabling unauthorized…

exploitationinformation-gatheringpenetration-testing+2
13 years ago
CVE-2024-56249 preview

CVE-2024-56249

GitHubnxploited/cve-2024-56249

WordPress WPMasterToolKit plugin <= 1.13.1 - Arbitrary File Upload vulnerability

exploitationpayload-generationpenetration-testing+4
11 year ago
CVE-2025-61506 preview

CVE-2025-61506

GitHubpescada-dev/cve-2025-61506

Unrestricted File Upload DoS Vulnerability discovered in MediaCrush thru 1.0.1(CVE-2025-61506)

exploitationinformation-gatheringpenetration-testing+2
17 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubiris288/cve-2021-41773

Proof-of-concept exploit for Apache HTTP Server path traversal vulnerability (CVE-2021-41773) enabling file disclosure and source code leakage…

exploitationpenetration-testingreconnaissance+2
12 years ago
CVE-2025-3515 preview

CVE-2025-3515

GitHubprofessor6t9/cve-2025-3515

CVE‑2025‑3515 — Drag and Drop Multiple File Upload for Contact Form 7

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2017-9798 preview

CVE-2017-9798

GitHubl0n3rs/cve-2017-9798

Lightweight Python script to detect CVE-2017-9798 in shared hosting environments by scanning for vulnerable .htaccess files, exiting with code 1 if…

exploitationmisconfigurationpenetration-testing+2
8 years ago
CVE-2022-24716 preview

CVE-2022-24716

GitHubgmh5225/cve-2022-24716

Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10

exploitationinformation-gatheringpenetration-testing+2
3 years ago
CVE-2006-3392 preview

CVE-2006-3392

GitHubkernel-cyber/cve-2006-3392

Exploit for CVE-2006-3392: unauthenticated local file inclusion in Webmin before 1.290 and Usermin before 1.220, bypassing path traversal filters…

exploitationinformation-gatheringpenetration-testing+2
3 years ago
Previous1…141516…28Next