Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
HAFNIUM-Microsoft-Exchange-0day preview

HAFNIUM-Microsoft-Exchange-0day

GitHubscs-labs/hafnium-microsoft-exchange-0day

CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, CVE-2021-27065

curated-resourcesexploitationincident-response+3
5
5 years ago
faraday_zap preview

faraday_zap

GitHubinfobyte/faraday_zap

Zap Extension for collaboration in Faraday

api-security-testingpenetration-testingvulnerability-scanners+2
27 months ago
CVE-2024-3400-PoC preview

CVE-2024-3400-PoC

GitHubcertushack/cve-2024-3400-poc

Sets up a Docker-based Palo Alto firewall test environment and provides an exploit script to test CVE-2024-3400, enabling safe vulnerability…

container-securityexploitationnetwork-security+3
22 years ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubimsre9/cve-2026-42945

Proof-of-concept exploit for CVE-2026-42945, a heap buffer overflow in NGINX rewrite/set directives, enabling DoS and potential RCE via crafted…

binary-exploitationeducationexploitation+3
4 months ago
nginx-cve-2026-42945-check preview

nginx-cve-2026-42945-check

GitHubbyezero/nginx-cve-2026-42945-check

Local read-only scanner for CVE-2026-42945 (NGINX Rift) that checks NGINX, OpenResty, and Tengine instances for vulnerable rewrite configurations…

configuration-auditingscripting-automationstatic-analysis+3
4 months ago
CVE-2026-36358 preview

CVE-2026-36358

GitHubyuhuamiao/cve-2026-36358

Proof-of-concept demonstrating a stored XSS vulnerability in Juzaweb CMS v5.0.0 via the banner ads HTML field, leading to arbitrary script execution…

exploitationpenetration-testingvulnerability-analysis+2
15 months ago
CVE-2022-1175 preview

CVE-2022-1175

GitHubgreenwolf/cve-2022-1175

Proof-of-concept exploit for GitLab stored XSS (CVE-2022-1175) enabling personal access token theft and account takeover via malicious issue comments.

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2022-2466---Request-Context-not-terminated-with-GraphQL preview

CVE-2022-2466---Request-Context-not-terminated-with-GraphQL

GitHubyuxblank/cve-2022-2466---request-context-not-terminated-with-graphql

Proof-of-concept for CVE-2022-2466 demonstrating unauthenticated GraphQL request context termination in Quarkus/SmallRye, bypassing authorization…

api-securityauthenticationpenetration-testing+2
14 years ago
CVE-2025-33053-Checker-PoC preview

CVE-2025-33053-Checker-PoC

GitHubthetorjancaptain/cve-2025-33053-checker-poc

CVE-2025-33053 Checker and PoC

educationexploitationpenetration-testing+2
11 year ago
Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212- preview

Creating-a-Vulnerable-Docker-Environment-CVE-2023-30212-

GitHubjasalurah/creating-a-vulnerable-docker-environment-cve-2023-30212-

Docker-based vulnerable environment for practicing CVE-2023-30212 exploitation, featuring an OURPHP web app with a reflected XSS vulnerability for…

container-securityeducationexploitation+3
3 years ago
CVE-2024-26144-test preview

CVE-2024-26144-test

GitHubgmo-ierae/cve-2024-26144-test

Test tool for CVE-2024-26144 that checks if web servers and CDNs improperly cache HTTP responses containing Set-Cookie headers, revealing cache…

misconfigurationvulnerability-analysisweb-security
2 years ago
nanwinata-CVE-2024-52301 preview

nanwinata-CVE-2024-52301

GitHubfckoo/nanwinata-cve-2024-52301

Scans for CVE-2024-52301, an argument injection vulnerability in Laravel, using subfinder and httpx to identify affected web applications.

exploitationinformation-gatheringreconnaissance+2
1 year ago
CVE-2019-14222 preview

CVE-2019-14222

GitHubmbadanoiu/cve-2019-14222

CVE-2019-14222: Default Certificate in Alfresco Community

cryptographyexploitationmisconfiguration+3
1 year ago
CVE-2024-43919 preview

CVE-2024-43919

GitHubrandomrobbiebf/cve-2024-43919

YARPP <= 5.30.10 - Missing Authorization

exploitationmisconfigurationpenetration-testing+3
1 year ago
CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7 preview

CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7

GitHubhuyvo2910/cve-2025-25749-weak-password-policy-in-hoteldruid-3.0.7

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

authenticationeducationpassword-attacks+3
1 year ago
dromara__hutool_CVE-2018-17297_4-1-1111 preview

dromara__hutool_CVE-2018-17297_4-1-1111

GitHubshoucheng3/dromara__hutool_cve-2018-17297_4-1-1111

Comprehensive Java utility library providing modules for cryptography, HTTP client, caching, JSON, scripting, and captcha generation, simplifying…

captcha-bypasscryptographyencryption-decryption-tools+3
1 year ago
chall.stypr.com preview
Archived

chall.stypr.com

GitHubstypr/chall.stypr.com

Stereotyped Challenges (2014~2023)

ctfcurated-resourceseducation+2
833 years ago
Previous123Next