Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
360 results
CVE-2017-12149 preview

CVE-2017-12149

GitHubvveakee/cve-2017-12149

Interactive exploit for CVE-2017-12149 that executes commands on vulnerable JBoss servers, supporting both Linux and Windows targets with a simple…

command-and-controlexploitationpenetration-testing+2
4 years ago
CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053- preview

CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-

GitHubhf3cyber/cms-made-simple-2.2.9-unauthenticated-sql-injection-exploit-cve-2019-9053-

Time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9 (CVE-2019-9053) that extracts username, email, password hash, and salt, with…

exploitationinformation-gatheringpassword-cracking+3
1 year ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubsariamubeen/cve-2024-10924

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

authentication-authorizationeducationexploitation+3
1 year ago
CVE-2024-10924-PoC preview

CVE-2024-10924-PoC

GitHubhunt3r850/cve-2024-10924-poc

Proof-of-concept exploit for CVE-2024-10924, an authentication bypass vulnerability in the Really Simple Security WordPress plugin, enabling MFA…

authentication-authorizationexploitationpenetration-testing+2
1 year ago
wpstorecart-exploit preview

wpstorecart-exploit

GitHubydvmtzv/wpstorecart-exploit

Simple PoC of wpstorecart before 2.5.30 plugin exploit (CVE-2012-3576) written in bash.

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2023-44061 preview

CVE-2023-44061

GitHubsoundarxploit/cve-2023-44061

CVE-2023-44061 - Simple and Nice Shopping Cart Script V1.0

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2021-46703 preview

CVE-2021-46703

GitHubbenedridge/cve-2021-46703

Simple payload builder

code-analysisexploitationpayload-generation+2
3 years ago
shellshock-shell preview

shellshock-shell

GitHubheikipikker/shellshock-shell

A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.

command-and-controlexploitationpenetration-testing+2
11 years ago
CVE-2022-3546 preview

CVE-2022-3546

GitHubthehackingverse/cve-2022-3546

Proof-of-concept exploit for CVE-2022-3546, a stored XSS vulnerability in SourceCodester Simple Cold Storage Management System 1.0 via the Create…

exploitationinformation-gatheringpenetration-testing+2
3 years ago
Next.js-CVE-2025-29927 preview

Next.js-CVE-2025-29927

GitHub0xpb1/next.js-cve-2025-29927

Minimal Next.js 12.2 application containerized with Docker, providing a simple Hello World web app and local development instructions.

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2021-26855-PoC preview

CVE-2021-26855-PoC

GitHubsrvaccount/cve-2021-26855-poc

PoC exploit code for CVE-2021-26855

email-securityexploitationinformation-gathering+3
175 years ago
CVE-2017-9101 preview

CVE-2017-9101

GitHubjasperla/cve-2017-9101

Authenticated remote code execution exploit for PlaySMS 1.4 via CSV phonebook upload. Provides single-command and interactive shell modes for…

exploitationpayload-generationpenetration-testing+3
147 years ago
CVE-2021-25094-tatsu-preauth-rce preview

CVE-2021-25094-tatsu-preauth-rce

GitHubdarkpills/cve-2021-25094-tatsu-preauth-rce

Proof-of-concept exploit for unauthenticated remote code execution in Tatsu Builder WordPress plugin (CVE-2021-25094). Supports multiple shell…

exploitationpayload-generationpenetration-testing+3
93 years ago
cve-2019-11447 preview

cve-2019-11447

GitHubthewhiteh4t/cve-2019-11447

CutePHP Cute News 2.1.2 RCE PoC

exploitationpayload-generationpenetration-testing+3
95 years ago
CVE-2025-27636-RCE-in-Apache-Camel preview

CVE-2025-27636-RCE-in-Apache-Camel

GitHubac8999/cve-2025-27636-rce-in-apache-camel

Python PoC exploiting CVE-2025-27636, an Apache Camel header injection RCE, supporting command execution, file reads, and reverse shell payloads.

exploitationpayload-generationpenetration-testing+3
18 days ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubmaximilianomeyer/cve-2026-33017

Proof-of-concept implementation for CVE-2026-33017, demonstrating the vulnerability for authorized security testing and research.

exploitationpenetration-testingvulnerability-analysis+1
17 days ago
CVE-2026-31431 preview

CVE-2026-31431

GitHubdesultory/cve-2026-31431

Demonstrates CVE-2026-31431 by poisoning the cache for a target file with attacker-controlled payload bytes, illustrating a web cache poisoning…

exploitationvulnerability-analysisweb-application-exploitation+1
75 months ago
CVE-2019-12836 preview

CVE-2019-12836

GitHub9lyph/cve-2019-12836

CVE-2019-12836

exploitationinformation-gatheringpayload-generation+3
71 year ago
Previous1…151617…20Next