Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
Serdyuk-DO-homework-CVE-2021-41773 preview

Serdyuk-DO-homework-CVE-2021-41773

GitHubdserdyk3-arch/serdyuk-do-homework-cve-2021-41773

Proof-of-concept exploit script for CVE-2021-41773, a path traversal vulnerability in Apache HTTP Server 2.4.49, enabling directory traversal and…

exploitationinformation-gatheringpenetration-testing+2
7 months ago
mac0352-ep4 preview

mac0352-ep4

GitHublcfpadilha/mac0352-ep4

Apache HTTP Server 2.4.23 vulnerability study (CVE-2016-8740)

educationexploitationpenetration-testing+2
18 years ago
apache-vulnerable preview

apache-vulnerable

GitHubpsibot/apache-vulnerable

Detects Apache HTTP Server path traversal vulnerabilities (CVE-2021-41773, CVE-2021-42013) by checking for exposure of /etc/passwd through…

exploitationpenetration-testingvulnerability-analysis+3
11 year ago
CVE-2025-63571 preview

CVE-2025-63571

GitHubrrespxwnss/cve-2025-63571

Proof of concept demonstrating Server-Side Request Forgery in ChatGPT, allowing attackers to force the AI to make arbitrary HTTP requests, exposing…

cloud-securityexploitationinformation-gathering+3
10 months ago
CVE-2021-40346 preview

CVE-2021-40346

GitHubboianeduard/cve-2021-40346

HTTP Request Smuggling

educationexploitationpenetration-testing+3
6 months ago
CVE-2024-40898 preview

CVE-2024-40898

GitHubanilpatel199n/cve-2024-40898

This Python script checks for the presence of CVE-2024-40898, a critical vulnerability in Apache HTTP Server that may allow SSL/TLS certificate…

educationexploitationpenetration-testing+2
11 year ago
Apache-Authentication-Flaw-Research-CVE-2024-38476- preview

Apache-Authentication-Flaw-Research-CVE-2024-38476-

GitHubabanop22333/apache-authentication-flaw-research-cve-2024-38476-

Technical research paper analyzing CVE-2024-38476, a critical Apache HTTP Server vulnerability enabling SSRF, information disclosure, and potential…

educationincident-responsepapers-research+3
7 months ago
CVE-2025-4476-Exploit preview

CVE-2025-4476-Exploit

GitHubsoltanali0/cve-2025-4476-exploit

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

educationexploitationvulnerability-analysis+1
11 months ago
cve-2023-2745 preview

cve-2023-2745

GitHubfofovicfof-ai/cve-2023-2745

Python script to check for CVE-2023-2745 vulnerability by sending crafted HTTP requests to a target URL and analyzing responses.

exploitationinformation-gatheringpenetration-testing+2
10 months ago
CVE-2025-65681 preview

CVE-2025-65681

GitHubrivek619/cve-2025-65681

An issue was discoverd in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive…

educationinformation-gatheringpapers-research+2
9 months ago
RustTLSX preview

RustTLSX

GitHubd0rb/rusttlsx

🦀 Stealth HTTP client for Rust . mimics real browser TLS fingerprints for undetectable requests. Fast, type-safe, and built for precision networking.

anti-botcrawlerfingerprint-spoofing+5
10 months ago
CVE-2023-36643 preview

CVE-2023-36643

GitHubcaffeinated-labs/cve-2023-36643

Proof-of-concept for CVE-2023-36643: an incorrect access control vulnerability in ITB-GmbH TradePro v9.5 that allows remote attackers to enumerate…

information-gatheringmisconfigurationpenetration-testing+2
2 years ago
tomcat_CVE-2018-1304_testing preview

tomcat_CVE-2018-1304_testing

GitHubthariyarox/tomcat_cve-2018-1304_testing

Proof-of-concept exploit for Apache Tomcat CVE-2018-1304, demonstrating remote code execution via crafted HTTP requests for security testing and…

exploitationpenetration-testingvulnerability-analysis+2
8 years ago
log4j preview

log4j

GitHubhassaanahmad813/log4j

Multithreaded Python scanner that detects Log4Shell (CVE-2021-44228) by sending crafted HTTP requests with JNDI payloads and monitoring DNS callbacks…

dns-analysisexploitationinformation-gathering+2
4 years ago
CVE-2017-15715 preview

CVE-2017-15715

GitHubwhisp1830/cve-2017-15715

Proof-of-concept exploit for CVE-2017-15715, an Apache HTTP Server vulnerability allowing file upload bypass via crafted Content-Disposition headers.

exploitationpenetration-testingvulnerability-analysis+2
7 years ago
undertow-io__undertow_CVE-2014-7816_1-0-16-Final preview

undertow-io__undertow_CVE-2014-7816_1-0-16-Final

GitHubshoucheng3/undertow-io__undertow_cve-2014-7816_1-0-16-final

Proof-of-concept exploit for CVE-2014-7816 targeting Undertow Java web server, demonstrating a directory traversal vulnerability in the HTTP server's…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
apache_audit_cve-2026-23918 preview

apache_audit_cve-2026-23918

GitHubsibersan/apache_audit_cve-2026-23918

Python toolkit to audit Apache HTTP Server against CVE-2026-23918 (HTTP/2 double-free RCE) and 4 related CVEs. Passive scanner with ALPN verification…

configuration-auditingdefensive-toolsincident-response+3
4 months ago
Cisco_CVE-2023-20198 preview

Cisco_CVE-2023-20198

GitHubreket99/cisco_cve-2023-20198

Python script to scan networks for Cisco IOS XE devices vulnerable to CVE-2023-20198, detecting implants via HTTP status and response analysis.

exploitationnetwork-securitypenetration-testing+3
2 years ago
Previous1…141516…25Next