Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2729 results
CVE-2020-9496 preview

CVE-2020-9496

GitHubcyber-niz/cve-2020-9496

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

exploitationpayload-generationpenetration-testing+2
5 years ago
globalprotect-ca-cert-ipc preview

globalprotect-ca-cert-ipc

GitHubs3c/globalprotect-ca-cert-ipc

Proof-of-concept exploit for CVE-2025-0117 in GlobalProtect, achieving privilege escalation to SYSTEM via a backdoored installer and DLL injection.

binary-exploitationexploitationmalware-analysis+3
1 year ago
Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE preview

Elementor-Pro-Unauthenticated-Arbitrary-File-Upload-to-RCE

GitHubabsholi7ly/elementor-pro-unauthenticated-arbitrary-file-upload-to-rce

CVE-2026-32475 The Elementor Pro Forms File Upload field handles validation and file processing in two separate loops with different handling of…

exploitationpayload-generationvulnerability-analysis+2
54 days ago
ThreadlessInject preview

ThreadlessInject

GitHubccob/threadlessinject

Threadless Process Injection using remote function hooking.

adversarial-attackpayload-developmentpayload-generation+4
8251 year ago
ShellcodeFluctuation preview

ShellcodeFluctuation

GitHubmgeeky/shellcodefluctuation

An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents

adversarial-attackpayload-developmentpayload-generation+4
1.1k4 years ago
CVE-2025-69212-for-myself preview

CVE-2025-69212-for-myself

GitHubliaomilk/cve-2025-69212-for-myself

just record for myself

exploitationpayload-generationpenetration-testing+2
8 days ago
CVE-2023-23638-Tools preview

CVE-2023-23638-Tools

GitHubp4x1s/cve-2023-23638-tools

Exploit tool for CVE-2023-23638, providing automated exploitation and payload generation for targeted vulnerability assessment and penetration…

exploitationpayload-generationpenetration-testing+2
3 years ago
x200-cve-2026-43499 preview

x200-cve-2026-43499

GitHubcxyofficial/x200-cve-2026-43499

Exploit tool targeting CVE-2026-43499 with automated payload delivery and vulnerability verification for penetration testing engagements.

exploitationexploit-frameworkspayload-development+3
1 month ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubyyqxi/cve-2022-26134

CVE-2022-26134poc

exploitationpayload-generationpenetration-testing+2
3 years ago
CVE-2017-0199 preview

CVE-2017-0199

GitHubviethdgit/cve-2017-0199

Exploit for CVE-2017-0199, a Microsoft Office/Word remote code execution vulnerability, enabling payload delivery and security testing.

exploitationpayload-generationpenetration-testing+2
8 years ago
test1 preview

test1

GitHubtanw923/test1

https://github.com/Yt1g3r/CVE-2019-3396_EXP.git

exploitationpayload-generationpenetration-testing+2
7 years ago
Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis preview

Dropper-GCleaner-C2-Infrastructure-Kernel-Driver-PowerShell-Conhost-Payload-Analysis

GitHubkaandemir993/dropper-gcleaner-c2-infrastructure-kernel-driver-powershell-conhost-payload-analysis

Reverse engineering analysis of Dropper GCleaner, a malware that uses a resilient C2 infrastructure, kernel driver loading, PowerShell/Conhost…

binary-analysiscommand-and-controldata-exfiltration+6
16 days ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

educationexploitationlabs-practice+4
7 days ago
CVE-2026-47858 preview

CVE-2026-47858

GitHubrealstatus/cve-2026-47858

Proof-of-concept exploit for unauthenticated JMX RCE in Spring Tools live information mode, using MLet remote class loading to execute arbitrary…

exploitationpayload-generationpenetration-testing+1
6 days ago
SpringPeace preview

SpringPeace

GitHubvirtualesp/springpeace

(Hopefully) A tool to root for (most) Android devices through CVE-2026-43499

android-securitybinary-analysisexploitation+4
1 month ago
slot2 preview

slot2

GitHubcenobyte-vincit/slot2

UEFI GRUB2 bootkit that installs a pre-boot networked implant via NVRAM boot option, chainloads a UKI, executes a dracut payload, and kexecs the…

cloud-securitycommand-and-controldata-exfiltration+5
6 days ago
CVE-2026-19501-poc preview

CVE-2026-19501-poc

GitHubtypedefabcd1234ntd/cve-2026-19501-poc

Proof-of-concept for unauthenticated CSV formula injection in SureForms, showing crafted form submissions trigger spreadsheet formulas when exported…

exploitationpayload-generationpenetration-testing+3
6 days ago
CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization preview

CVE-2026-34486---unauthenticated-RCE-via-Java-deserialization

GitHubcypherhippie/cve-2026-34486---unauthenticated-rce-via-java-deserialization

EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.

exploitationpayload-generationpenetration-testing+2
7 days ago
Previous12…100Next