Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
wordpress-cve-2021-29447 preview

wordpress-cve-2021-29447

GitHubm3l0npan/wordpress-cve-2021-29447

Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.

educationexploitationpenetration-testing+3
4
3 years ago
CVE-2019-9670 preview

CVE-2019-9670

GitHubcappricio-securities/cve-2019-9670

mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
CVE-2017-9096-iText-XXE preview

CVE-2017-9096-iText-XXE

GitHubjakabakos/cve-2017-9096-itext-xxe

Proof-of-concept exploit for CVE-2017-9096 demonstrating XML External Entity (XXE) injection in iText PDF library via malicious XMP metadata and form…

exploitationfuzzingpenetration-testing+2
134 years ago
CVE-2019-8997 preview

CVE-2019-8997

GitHubnxkennedy/cve-2019-8997

An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could…

exploitationinformation-gatheringpenetration-testing+2
26 years ago
CVE-2018-8033 preview

CVE-2018-8033

GitHubcappricio-securities/cve-2018-8033

Apache OFBiz 16.11.04 is susceptible to XML external entity injection (XXE injection)

exploitationpenetration-testingvulnerability-scanners+2
22 years ago
CVE-2024-51132-POC preview

CVE-2024-51132-POC

GitHubjacklosingheart/cve-2024-51132-poc

Proof-of-concept exploit for CVE-2024-51132, an XML External Entity (XXE) injection vulnerability in HAPI FHIR core libraries, enabling SSRF and…

code-analysisexploitationinformation-gathering+3
11 year ago
CVE-2025-49493 preview

CVE-2025-49493

GitHubsh4den/cve-2025-49493

This is a Python-based exploit for CVE-2025-49493, which affects Akamai CloudTest versions before 60 2025.06.02 (12988). The vulnerability allows for…

exploitationinformation-gatheringpenetration-testing+3
13 months ago
ktor-xxe-poc preview

ktor-xxe-poc

GitHubrazvanclaudiu/ktor-xxe-poc

This repository provides a Proof of Concept for CVE-2023-45612, demonstrating an XML External Entity (XXE) injection vulnerability in JetBrains Ktor…

educationexploitationpenetration-testing+3
11 months ago
CVE-2020-4463 preview

CVE-2020-4463

GitHubibonok/cve-2020-4463

IBM Maximo Asset Management is vulnerable to Information Disclosure via XXE Vulnerability (CVE-2020-4463)

exploitationinformation-gatheringpenetration-testing+3
513 years ago
CVE-2021-29447-PoC preview

CVE-2021-29447-PoC

GitHubrdana55/cve-2021-29447-poc

Proof-of-concept exploit for CVE-2021-29447, an XXE injection vulnerability in WordPress 5.6–5.7 via malicious WAV file upload, enabling arbitrary…

educationexploitationpenetration-testing+3
4 months ago
cosmicsting-cve-2024-34102-exploit preview

cosmicsting-cve-2024-34102-exploit

GitHubrussellwork2021-lgtm/cosmicsting-cve-2024-34102-exploit

Complete CosmicSting (CVE-2024-34102) exploit suite for Magento/Adobe Commerce XXE vulnerability

exploitationinformation-gatheringpenetration-testing+3
4 months ago
CVE-2025-58360-GeoServer-XXE preview

CVE-2025-58360-GeoServer-XXE

GitHubjoker-wiggin/cve-2025-58360-geoserver-xxe

Docker-based lab demonstrating CVE-2025-58360, a critical unauthenticated XXE injection in GeoServer WMS/OWS services. Includes exploit script for…

educationexploitationlabs-practice+3
9 months ago
CVE-2025-66516-POC preview

CVE-2025-66516-POC

GitHubsid6224/cve-2025-66516-poc

A POC for the CVE-2025-66516 Apache Tika Vulnerability for educational purposes only

educationexploitationpayload-generation+3
69 months ago
CVE-2023-20052 preview

CVE-2023-20052

GitHubmohitsinghpapola/cve-2023-20052

Fixed Docker build for CVE-2023-20052 ClamAV XXE exploit. Resolves OpenSSL 3.0 compilation errors using Ubuntu 18.04 with OpenSSL 1.0 for…

binary-analysisexploitationfuzzing+3
7 months ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubdanilo1992-sys/cve-2021-29447

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

educationexploitationlabs-practice+3
6 months ago
Tika-CVE-2025-66516-Lab preview

Tika-CVE-2025-66516-Lab

GitHubintsheep/tika-cve-2025-66516-lab

Minimal verification lab for CVE-2025-66516 (Apache Tika XXE). Generates malicious PDF payloads and validates the vulnerability by reading sensitive…

educationexploitationlabs-practice+3
9 months ago
XXERipper preview

XXERipper

GitHubkamalx06/xxeripper

Black-box XXE scanner detecting in-band, error-based, and blind out-of-band injection via statistical baselining, parser fingerprinting, and OOB…

api-security-testingdata-exfiltrationexploitation+9
5 days ago
poc-yaws-dav-xxe preview

poc-yaws-dav-xxe

GitHubvulnbe/poc-yaws-dav-xxe

Yaws web server XML external entity injection POC

exploitationpenetration-testingvulnerability-analysis+1
6 years ago
Previous12Next