Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
CVE-2002-0347 preview

CVE-2002-0347

GitHubalt3kx/cve-2002-0347

Directory traversal vulnerability in Cobalt RAQ 4 allows remote attackers to read password-protected files, and possibly files outside the web root,…

exploitationinformation-gatheringreconnaissance+2
8 years ago
CVE-2019-20372 preview

CVE-2019-20372

GitHubvuongnv3389-sec/cve-2019-20372

Proof-of-concept exploit for CVE-2019-20372: HTTP request smuggling via nginx error_page directive, enabling access to hidden resources.

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubjrrombaldo/cve-2017-5638

Multithreaded vulnerability validator for Apache Struts 2 (CVE-2017-5638) that scans thousands of endpoints via HTTP header injection to detect…

exploitationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2023-38545 preview

CVE-2023-38545

GitHubyang-shun-yu/cve-2023-38545

Proof-of-concept exploit for CVE-2023-38545, a curl heap buffer overflow. Includes SOCKS5 proxy and HTTP server to trigger the vulnerability and…

exploitationfuzzingnetwork-security+3
2 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubfa1c0n35/cve-2021-41773

Exploit for Apache HTTP Server 2.4.49 path traversal and remote code execution vulnerability (CVE-2021-41773), enabling LFI and RCE on vulnerable…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
POC-CVE-2025-29927- preview

POC-CVE-2025-29927-

GitHubethanol1310/poc-cve-2025-29927-

Proof-of-concept exploit for CVE-2025-29927, demonstrating a middleware authentication bypass in self-hosted Next.js applications via crafted HTTP…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2024-25175 preview

CVE-2024-25175

GitHubjet-pentest/cve-2024-25175

Proof-of-concept exploit for CVE-2024-25175: reflected XSS via HTTP response splitting in Kickidler Server before 1.107.0, with CVSS 6.1 and…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
cve-2021-41773 preview

cve-2021-41773

GitHubvuongnv3389-sec/cve-2021-41773

Dockerized proof-of-concept for Apache HTTP Server path traversal and RCE (CVE-2021-41773), including build instructions and curl-based exploitation…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubrnsss/cve-2021-42013

Exploit for Apache HTTP Server path traversal and file disclosure vulnerability CVE-2021-42013, enabling unauthorized access to files on vulnerable…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2020-3187 preview

CVE-2020-3187

GitHubsujaygr8/cve-2020-3187

Proof-of-concept exploit for CVE-2020-3187 targeting Cisco ASA/FTD session password disclosure via crafted HTTP cookie header.

exploitationpenetration-testingvulnerability-analysis+2
5 years ago
CVE-2020-25613 preview

CVE-2020-25613

GitHubmetapox/cve-2020-25613

Proof-of-concept exploit for HTTP request smuggling vulnerability CVE-2020-25613, demonstrating chunked transfer encoding parsing bypass to poison…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2024-51358 preview

CVE-2024-51358

GitHubkov404/cve-2024-51358

Proof-of-concept exploit for CVE-2024-51358, a server-side request forgery (SSRF) vulnerability in Heimdall 2.6.1, enabling remote HTTP requests to…

exploitationinformation-gatheringreconnaissance+2
1 year ago
Apache-Pluto-3.0.0--CVE-2018-1306 preview

Apache-Pluto-3.0.0--CVE-2018-1306

GitHubjjso12/apache-pluto-3.0.0--cve-2018-1306

Python exploit script for CVE-2018-1306 in Apache Pluto 3.0.0, enabling malicious file upload via HTTP method tampering to achieve remote code…

exploitationpayload-generationpenetration-testing+3
6 years ago
CVE-2018-9995_dvr_credentials preview

CVE-2018-9995_dvr_credentials

GitHubbatmoshka55/cve-2018-9995_dvr_credentials

Exploit tool for CVE-2018-9995 that retrieves DVR credentials via crafted HTTP request, targeting multiple DVR vendors for security testing.

exploitationinformation-gatheringiot-security+3
1 year ago
cve-2021-41773 preview

cve-2021-41773

GitHubmohwahyudi/cve-2021-41773

Python script that uses Shodan to discover Apache HTTP Server 2.4.49 instances vulnerable to CVE-2021-41773 path traversal and file disclosure.

exploitationinformation-gatheringosint+3
4 years ago
CVE-2024-40324 preview

CVE-2024-40324

GitHubaleksey-vi/cve-2024-40324

Proof-of-concept for CRLF injection in E-Staff v5.1, demonstrating HTTP response splitting and header manipulation for security testing.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2025-0108-Authentication-Bypass-checker preview

CVE-2025-0108-Authentication-Bypass-checker

GitHubbarcrange/cve-2025-0108-authentication-bypass-checker

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2025-29927-NextJs-Middleware-Simulation preview

CVE-2025-29927-NextJs-Middleware-Simulation

GitHubknotsecurity/cve-2025-29927-nextjs-middleware-simulation

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

educationmisconfigurationpenetration-testing+3
1 year ago
Previous1…161718…25Next