Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
486 results
cve-2024-23897-jenkins-poc preview

cve-2024-23897-jenkins-poc

GitHubrivaedoardo62-boop/cve-2024-23897-jenkins-poc

Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.

educationexploitationpapers-research+3
2 months ago
CVE-2026-45806 preview

CVE-2026-45806

GitHub0xmrma/cve-2026-45806

Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because…

educationexploitationpapers-research+3
2 months ago
drupal-openai-provider-ssrf-cve-2026-13233 preview

drupal-openai-provider-ssrf-cve-2026-13233

GitHubkuninogu/drupal-openai-provider-ssrf-cve-2026-13233

CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe…

educationvulnerability-analysisweb-security
1 month ago
CVE-2026-14894 preview

CVE-2026-14894

GitHubshinthink/cve-2026-14894

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

educationexploitationinformation-gathering+6
11 month ago
CVE-2018-18778 preview

CVE-2018-18778

GitHubk3ystr0k3r/cve-2018-18778

CVE-2018-18778 - ACME mini_httpd Arbitrary File Read

educationexploitationinformation-gathering+3
12 months ago
CVE-2021-29447-PoC preview

CVE-2021-29447-PoC

GitHubrdana55/cve-2021-29447-poc

Proof-of-concept exploit for CVE-2021-29447, an XXE injection vulnerability in WordPress 5.6–5.7 via malicious WAV file upload, enabling arbitrary…

educationexploitationpenetration-testing+3
3 months ago
CVE-2024-8949-POC preview

CVE-2024-8949-POC

GitHubgh-ost00/cve-2024-8949-poc

SourceCodester Online Eyewear Shop Remote File Inclusion Vulnerability

information-gatheringpenetration-testingvulnerability-analysis+2
21 year ago
CVE-2022-41352 preview

CVE-2022-41352

GitHubrxerium/cve-2022-41352

Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability

vulnerability-scannersweb-securityweb-vulnerability-scanners
210 months ago
S3-from-csp preview

S3-from-csp

GitHubrandomrobbiebf/s3-from-csp

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

cloud-infrastructure-securitycloud-securityinformation-gathering+2
13 years ago
CVE-2026-1657 preview

CVE-2026-1657

GitHubd3kc4rt1/cve-2026-1657

Unauthenticated Arbitrary File Upload in EventPrime Plugin

code-analysiseducationexploitation+3
4 months ago
CVE-2026-27621 preview

CVE-2026-27621

GitHublukasz-rybak/cve-2026-27621

CVE-2026-27621 - TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload

educationpapers-researchvulnerability-analysis+2
4 months ago
FuguHub-8.1-Reflected-SVG-XSS-CVE-2025-65790 preview

FuguHub-8.1-Reflected-SVG-XSS-CVE-2025-65790

GitHubhunterxxx/fuguhub-8.1-reflected-svg-xss-cve-2025-65790

Documentation of CVE-2025-65790: Reflected XSS vulnerability in FuguHub 8.1 via unsanitized SVG rendering in the file manager interface, with PoC and…

educationexploitationpenetration-testing+3
18 months ago
evilMP4 preview

evilMP4

GitHubdumbbutt0/evilmp4

Explore CVE-2022-41741 with the Evil MP4 repository. It offers educational PoCs,and documentation on securing nginx against MP4 file vulnerabilities.…

educationexploitationfuzzing+3
12 years ago
CVE-2025-61183 preview

CVE-2025-61183

GitHubthawphone/cve-2025-61183

Detailed disclosure of a stored XSS vulnerability in VaahCMS via unsafe SVG file upload handling, including exploitation flow, affected endpoints,…

educationexploitationpenetration-testing+3
6 months ago
CVE-2025-60787-Detection-motionEye-RCE-via-Config-Injection preview

CVE-2025-60787-Detection-motionEye-RCE-via-Config-Injection

GitHubgarethmsheldon/cve-2025-60787-detection-motioneye-rce-via-config-injection

Detection rules and YARA/KQL signatures for CVE-2025-60787, an unauthenticated RCE in motionEye via config injection, with process execution and file…

container-securityexploitationintrusion-detection+5
6 months ago
React-Router-CVE-2025-61686- preview

React-Router-CVE-2025-61686-

GitHubkai-one001/react-router-cve-2025-61686-

Detailed analysis of CVE-2025-61686, a path traversal vulnerability in React Router's file session storage, including root cause, attack scenarios,…

code-analysiseducationexploitation+3
7 months ago
perwendel__spark_CVE-2018-9159_2_7_2_fixed preview

perwendel__spark_CVE-2018-9159_2_7_2_fixed

GitHubshoucheng3/perwendel__spark_cve-2018-9159_2_7_2_fixed

Lightweight Java 8 web framework for building REST APIs and web applications, with built-in routing, static file serving, and template engine support.

api-security-testingeducationgeneral-purpose-utilities+3
11 months ago
perwendel__spark_CVE-2018-9159_2-7-1 preview

perwendel__spark_CVE-2018-9159_2-7-1

GitHubshoucheng3/perwendel__spark_cve-2018-9159_2-7-1

Lightweight Java 8 web framework with routing, filters, and static file serving. Includes security advisory for older versions and CRUD API examples.

api-security-testingeducationgeneral-purpose-utilities+3
1 year ago
Previous1…24252627Next