Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
643 results
poc-CVE-2026-23489 preview

poc-CVE-2026-23489

GitHubeorll-lgtm/poc-cve-2026-23489

Proof of concept (POC) for CVE-2026-23489 GLPI "Fields" plugin <= 1.23.2

exploitationpenetration-testingweb-application-exploitation
15 days ago
craftcms-cve-2025-32432-rce preview

craftcms-cve-2025-32432-rce

GitHubpsyguy007-sys/craftcms-cve-2025-32432-rce

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

exploitationpenetration-testingweb-application-exploitation
15 days ago
Clickjacking-Exploit-Detector preview

Clickjacking-Exploit-Detector

GitHubjenderal92/clickjacking-exploit-detector

The Clickjacking Exploit Detector uses webpage scanning techniques to identify potential vulnerabilities and provide analysis of those elements.

penetration-testingweb-application-exploitationweb-security+1
32 months ago
CVE-2026-3891 preview

CVE-2026-3891

GitHubch4120n/cve-2026-3891

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

exploitationpenetration-testingweb-application-exploitation
217 days ago
Apache-Flink-Dashboard-rec preview

Apache-Flink-Dashboard-rec

GitHubianxtianxt/apache-flink-dashboard-rec

Apache Flink Dashboard未授权访问-远程代码命令执行

exploitationpenetration-testingweb-application-exploitation+1
36 years ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubzsecur1ty/xss2shell-cve-2026-64638

Exploits CVE-2026-64638 to convert cross-site scripting into shell access on vulnerable web applications, automating payload delivery and…

exploitationpenetration-testingweb-application-exploitation
113 days ago
CVE-2019-10392_EXP preview

CVE-2019-10392_EXP

GitHubforthekahzmodan/cve-2019-10392_exp

Jenkins Git Client RCE CVE-2019-10392_Exp

exploitationpenetration-testingweb-application-exploitation
36 years ago
ssrfnginx preview

ssrfnginx

GitHubknqyf263/ssrfnginx
exploitationpenetration-testingweb-application-exploitation+1
16 years ago
Unrestricted-File-Upload-on-SiteMagic-CMS-4.4.2 preview

Unrestricted-File-Upload-on-SiteMagic-CMS-4.4.2

GitHubv1n1v131r4/unrestricted-file-upload-on-sitemagic-cms-4.4.2

This repo describe how to exploit unrestricted file upload vulnerability on SiteMagic CMS 4.4.2

penetration-testingvulnerability-analysisweb-application-exploitation
25 years ago
agent_tesla_panel_rce preview

agent_tesla_panel_rce

GitHubmekhalleh/agent_tesla_panel_rce

This is Metasploit module who exploit the command injection vulnerability in control center of the agent Tesla.

exploitationpenetration-testingweb-application-exploitation
16 years ago
aem-xss preview

aem-xss

GitHubcappricio-securities/aem-xss

Adobe Experience Manager Childlist Selector - Cross-Site Scripting

penetration-testingweb-application-exploitationweb-vulnerability-scanners
12 years ago
LearnDash preview

LearnDash

GitHubrandomrobbiebf/learndash

Rubbish SQLI that requires Admin

penetration-testingvulnerability-analysisweb-application-exploitation
6 months ago
CVE-2014-4688-NodeJs-Exploit preview

CVE-2014-4688-NodeJs-Exploit

GitHubnote0577/cve-2014-4688-nodejs-exploit

Authenticated Remote Command Execution – pfSense <= 2.1.3

exploitationpenetration-testingweb-application-exploitation
1 year ago
Stored-xss preview

Stored-xss

GitHubsoundarxploit/stored-xss

Got My CVE Published CVE-2023-41575

penetration-testingvulnerability-analysisweb-application-exploitation+1
2 years ago
CVE-2020-24913-exploit preview

CVE-2020-24913-exploit

GitHubshpaw415/cve-2020-24913-exploit

automated SQL injection for QCubed profile.php file

penetration-testingvulnerability-analysisweb-application-exploitation
1 year ago
CVE-2024-35511 preview

CVE-2024-35511

GitHubefekaanakkar/cve-2024-35511

Men Salon Management System Using PHP and MySQL

penetration-testingvulnerability-analysisweb-application-exploitation+1
2 years ago
CVE-2025-29448 preview

CVE-2025-29448

GitHubabdullah4eb/cve-2025-29448

unauthenticated booking logic flaw in Easy!Appointments v1.5.1 causing denial of service.

penetration-testingvulnerability-analysisweb-application-exploitation+1
1 year ago
CVE-2025-70559 preview

CVE-2025-70559

GitHubisukasanuj/cve-2025-70559

Python exploit for CVE-2025-70559 targeting an upload directory bypass/remote code execution; run with LHOST and LPORT to establish a reverse shell.

exploitationpenetration-testingweb-application-exploitation
6 days ago
Previous1…456…36Next