Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
CVE-2018-20463 preview

CVE-2018-20463

GitHubhenry4e36/cve-2018-20463

WordPress JSmol2WP Plugin 1.07版本中存在安全漏洞。攻击者可利用该漏洞读取任意文件。

exploitationinformation-gatheringvulnerability-analysis+2
2
4 years ago
CVE-2024-50379-PoC preview

CVE-2024-50379-PoC

GitHubisee857/cve-2024-50379-poc

Batch detection script for Apache Tomcat CVE-2024-50379 race condition remote code execution vulnerability. Supports single and mass scanning via…

exploitationpenetration-testingvulnerability-analysis+3
241 year ago
CVE-2023-27163 preview

CVE-2023-27163

GitHubdavuxvi/cve-2023-27163

Proof-of-concept exploit for CVE-2023-27163, a Server-Side Request Forgery (SSRF) vulnerability in request-baskets up to v1.2.1. Includes automated…

exploitationlabs-practicepenetration-testing+3
13 years ago
W3TotalChache preview

W3TotalChache

GitHubspyata123/w3totalchache

Testing for CVE-2019-6715 (Arbitrary File Read)/ CVE-2024-12365 (SSRF/Info Disclosure)

exploitationinformation-gatheringpenetration-testing+3
1 year ago
EagleEye preview

EagleEye

GitHubwhalebone7/eagleeye

To filter the actual vulnerable URLs from the screenshots, you can use the ee.sh script. Simply run ./ee.sh -f "path/to/index_screenshot.txt" -k…

information-gatheringpenetration-testingreconnaissance+3
73 years ago
CVE-2025-0108-PoC preview

CVE-2025-0108-PoC

GitHubisee857/cve-2025-0108-poc

Palo Alto Networks PAN-OS 身份验证绕过漏洞批量检测脚本(CVE-2025-0108)

authentication-authorizationexploitationids-ips-evasion+3
321 year ago
CVE-2023-29923 preview

CVE-2023-29923

GitHub1820112015/cve-2023-29923

CVE-2023-29922 Batch detection script

exploitationinformation-gatheringpenetration-testing+2
153 years ago
CVE-2022-24990-POC preview

CVE-2022-24990-POC

GitHubvveakee/cve-2022-24990-poc

仅仅是poc,并不是exp

exploitationpenetration-testingvulnerability-analysis+2
44 years ago
CVE-2024-27956 preview

CVE-2024-27956

GitHubtruonghuuphuc/cve-2024-27956

CVE-2024-27956 WordPress Automatic < 3.92.1 - Unauthenticated SQL Injection

exploitationpenetration-testingvulnerability-analysis+2
32 years ago
CVE-2019-8449 preview

CVE-2019-8449

GitHubr0lh/cve-2019-8449

User Enumeration Proof Of Concept Exploit for CVE-2019-8449

exploitationinformation-gatheringpenetration-testing+2
26 years ago
CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC preview

CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC

GitHubcyfare/cve-2026-23918-apache-http-server-doublefree-poc

Proof-of-concept exploit for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server, demonstrating remote crash via crafted requests.

exploitationpenetration-testingvulnerability-analysis+2
4 months ago
CVE-2018-9995-POC preview

CVE-2018-9995-POC

GitHubb510/cve-2018-9995-poc

CVE-2018-9995 POC

exploitationinformation-gatheringreconnaissance+2
16 years ago
HeartBleed preview

HeartBleed

GitHubsaymeis/heartbleed

CVE-2014-0160

container-securityeducationexploitation+2
17 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubisee857/cve-2025-29927

Python-based proof-of-concept exploit for CVE-2025-29927, a Next.js privilege bypass vulnerability. Supports single-target and batch scanning with…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-30208-PoC preview

CVE-2025-30208-PoC

GitHubisee857/cve-2025-30208-poc

Multi-threaded Python scanner for CVE-2025-30208 Vite path traversal vulnerability with custom payload support, batch scanning, and proxy debugging.

exploitationinformation-gatheringpenetration-testing+3
1 year ago