Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36364 results
KasperMeow preview

KasperMeow

GitHubmein-0/kaspermeow

Proof-of-concept that exploits a Kaspersky driver vulnerability to leak kernel pointers and bypass KASLR on Windows, enabling kernel exploit chain…

vulnerability-analysisexploitationreverse-engineering+1
7
2 days ago
ctf-tracker preview

ctf-tracker

GitHubxxdndxx/ctf-tracker

Offline-first dashboard for tracking CTF machines and labs, with attack lifecycle management, dynamic reverse shell builder, and embedded writeup…

privilege-escalationreconnaissanceexploitation+6
22 days ago
sast-scan-action preview

sast-scan-action

GitHuboffensive360/sast-scan-action

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

vulnerability-scannersstatic-code-analysiscode-analysis+4
1 month ago
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

static-code-analysisvulnerability-analysiscode-analysis+3
1 month ago
CVE-2026-73309 preview

CVE-2026-73309

GitHubbombobombone/cve-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

authentication-authorizationvulnerability-analysisexploitation+2
11h 55m ago
CVE-2026-73310 preview

CVE-2026-73310

GitHubbombobombone/cve-2026-73310

Proof of concept and technical write-up for CVE-2026-73310, an OAuth2 authorization code redirect URI binding flaw in XenForo before 2.3.13,…

vulnerability-analysisexploitationweb-application-exploitation+2
11h 55m ago
CVE-2026-73311 preview

CVE-2026-73311

GitHubbombobombone/cve-2026-73311

Proof-of-concept exploit demonstrating OAuth2 authorization code reuse in XenForo before 2.3.13, allowing token replay and multiple token families.

vulnerability-analysisexploitationweb-application-exploitation+2
11h 55m ago
CVE-2026-73312 preview

CVE-2026-73312

GitHubbombobombone/cve-2026-73312

Proof-of-concept and technical write-up for CVE-2026-73312, an OAuth2 refresh token replay vulnerability in XenForo before 2.3.13. Includes a Python…

vulnerability-analysisexploitationweb-security+2
11h 55m ago
CVE-2026-73313 preview

CVE-2026-73313

GitHubbombobombone/cve-2026-73313

Proof-of-concept exploit for CVE-2026-73313, an MFA bypass in XenForo's passkey TFA provider allowing account takeover after password compromise.

vulnerability-analysisexploitationweb-security+2
11h 55m ago
CVE-2026-73314 preview

CVE-2026-73314

GitHubbombobombone/cve-2026-73314

Proof-of-concept exploit for CVE-2026-73314, a PayPal REST webhook signature verification bypass in XenForo before 2.3.13, allowing unauthorized…

vulnerability-analysisexploitationweb-application-exploitation+1
11h 55m ago
CVE-2026-73315 preview

CVE-2026-73315

GitHubbombobombone/cve-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

vulnerability-analysisexploitationweb-application-exploitation+1
11h 54m ago
CVE-2026-73316 preview

CVE-2026-73316

GitHubbombobombone/cve-2026-73316

Proof-of-concept and technical write-up for CVE-2026-73316, a PayPal REST webhook replay vulnerability in XenForo before 2.3.13, including…

vulnerability-analysisexploitationweb-application-exploitation+2
11h 54m ago
CVE-2026-73317 preview

CVE-2026-73317

GitHubbombobombone/cve-2026-73317

Proof-of-concept exploit and technical write-up for CVE-2026-73317, an authorization bypass in XenForo allowing limited admins to approve content as…

authentication-authorizationvulnerability-analysisexploitation+3
11h 54m ago
CVE-2026-73318 preview

CVE-2026-73318

GitHubbombobombone/cve-2026-73318

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…

authentication-authorizationvulnerability-analysisexploitation+3
11h 54m ago
CVE-2026-73319 preview

CVE-2026-73319

GitHubbombobombone/cve-2026-73319

Proof-of-concept exploit and technical write-up for CVE-2026-73319, a same-host javascript: URI XSS in XenForo before 2.3.13, including reproduction…

vulnerability-analysisexploitationweb-application-exploitation+2
11h 54m ago
CVE-2026-73320 preview

CVE-2026-73320

GitHubbombobombone/cve-2026-73320

Proof-of-concept and technical write-up for an unauthenticated information disclosure vulnerability in XenForo's unfurl endpoint, including a Python…

vulnerability-analysisexploitationinformation-gathering+2
11h 54m ago
CVE-2026-73321 preview

CVE-2026-73321

GitHubbombobombone/cve-2026-73321

Proof-of-concept and technical write-up for CVE-2026-73321, a denial-of-service vulnerability in XenForo caused by deeply nested BBCode that exhausts…

vulnerability-analysisexploitationweb-security
11h 54m ago
CVE-2026-74239 preview

CVE-2026-74239

GitHubbombobombone/cve-2026-74239

Proof of concept and technical write-up for CVE-2026-74239, a path traversal vulnerability in XenForo style archive imports on Windows, allowing file…

vulnerability-analysisexploitationweb-application-exploitation+2
11h 54m ago
Previous12…100Next