Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
824 results
V8Harvest preview

V8Harvest

GitHubstar-sg/v8harvest

Curated dashboard for browsing recent V8 vulnerability patterns, parsing regression test files with linked Chromium bug reports, code reviews, and…

binary-analysiscurated-resourceseducation+2
35
5 years ago
spip-exploits preview

spip-exploits

GitHubambionics/spip-exploits

Python exploit chain for SPIP CVEs 2026-72708/72709/72710, chaining unauthenticated SQL injection to account takeover and remote code execution.

exploitationexploit-frameworkspapers-research+4
217 days ago
sec-af preview

sec-af

GitHubagent-field/sec-af

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

ai-securitycode-analysisdevsecops+7
1991 month ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubchenqin231/cve-2026-42945

Local risk assessment script for CVE-2026-42945 (nginx-rift). Checks version, vulnerable rewrite+set config, ASLR status, and compile hardening to…

binary-analysisconfiguration-auditingexploitation+3
14 months ago
file-away-exploit preview

file-away-exploit

GitHubwhattheslime/file-away-exploit

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)

exploitationinformation-gatheringpayload-development+5
11 year ago
DSpace__DSpace_CVE-2016-10726_4-4 preview

DSpace__DSpace_CVE-2016-10726_4-4

GitHubshoucheng3/dspace__dspace_cve-2016-10726_4-4

Repository containing the DSpace 4.4 source code with a focus on CVE-2016-10726, providing a reference for vulnerability analysis and educational…

code-analysiscurated-resourceseducation+2
1 year ago
CVE-2023-43876-October-CMS-Reflected-XSS---Installation preview

CVE-2023-43876-October-CMS-Reflected-XSS---Installation

GitHubsromanhu/cve-2023-43876-october-cms-reflected-xss---installation

October CMS 3.4.16 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload in…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2023-43339-CMSmadesimple-Reflected-XSS---Installation preview

CVE-2023-43339-CMSmadesimple-Reflected-XSS---Installation

GitHubsromanhu/cve-2023-43339-cmsmadesimple-reflected-xss---installation

CMSmadesimple 2.2.18 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2023-43341-Evolution-Reflected-XSS---Installation-Connection- preview

CVE-2023-43341-Evolution-Reflected-XSS---Installation-Connection-

GitHubsromanhu/cve-2023-43341-evolution-reflected-xss---installation-connection-

Evolution CMS 3.2.3 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload…

exploitationinformation-gatheringpenetration-testing+3
3 years ago
CVE-2023-44487 preview

CVE-2023-44487

GitHubimabee101/cve-2023-44487

PoC script for HTTP/2 Rapid Reset (CVE-2023-44487) that sends crafted HTTP/2 streams to trigger denial-of-service conditions on vulnerable servers,…

adversarial-attackexploitationweb-application-exploitation+1
562 years ago
CVE-2026-20896-Gitea-Authentication-Bypass preview

CVE-2026-20896-Gitea-Authentication-Bypass

GitHubjudgedbykira/cve-2026-20896-gitea-authentication-bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

authenticationeducationexploitation+5
1 month ago
CVE-2026-25632 preview

CVE-2026-25632

GitHublazarus0x1337/cve-2026-25632

CVE-2026-25632 — Fix Unsafe JSON Deserialization Leading to Remote Code Execution

code-analysiseducationexploitation+4
12 months ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubosungjinwoo/cve-2022-22965

Proof-of-concept exploit and testing scripts for Spring4Shell (CVE-2022-22965), a Spring Framework remote code execution vulnerability, with bash and…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
WIn-CVE-2021-31166 preview

WIn-CVE-2021-31166

GitHubbgsilvait/win-cve-2021-31166

Proof-of-concept for CVE-2021-31166 (http.sys RCE) with Terraform deployment on AWS, including testing scripts and a WAFv2 rule to block the exploit.

cloud-securitydevsecopsexploitation+3
5 years ago
kunglao-agent preview

kunglao-agent

GitHubamd2g2zz/kunglao-agent

The reverse-engineering expert agent: plans its own analysis path, derives every fact from raw evidence, and converges under mechanical verification…

ai-assisted-reversingandroid-securitybinary-analysis+8
4820h 15m ago
CVE-2026-7222-XSS preview

CVE-2026-7222-XSS

GitHubxmyronn/cve-2026-7222-xss

Proof-of-concept exploit for stored XSS (CWE-79) in a PHP coaching management system, demonstrating session hijacking and privilege escalation from…

educationexploitationpenetration-testing+3
5 months ago
CVE-2026-5029-Exploit preview

CVE-2026-5029-Exploit

GitHub0x00phantom-hat/cve-2026-5029-exploit

Proof-of-concept exploit for CVE-2026-5029, delivering unauthenticated remote code execution via the run-code MCP tool on exposed HTTP endpoints.…

code-analysiseducationexploitation+3
2 months ago
Pluck-CMS-Stored-XSS---Installation preview

Pluck-CMS-Stored-XSS---Installation

GitHubsromanhu/pluck-cms-stored-xss---installation

pluck CMS 4.7.18 is affected by a Multiple Stored Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a…

payload-generationpenetration-testingred-teaming+3
3 years ago
Previous123…46Next