Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
CVE-2024-37054-PoC preview

CVE-2024-37054-PoC

GitHubclearlotus-git/cve-2024-37054-poc

Proof-of-concept and research repository for CVE-2024-37054, an unsafe deserialization flaw in MLflow PyFunc model loading that can lead to remote…

ai-securitydefensive-toolseducation+4
9 days ago
CVE-2026-30741 preview

CVE-2026-30741

GitHubnamed1ess/cve-2026-30741

Proof-of-concept demonstrating remote code execution via request-side prompt injection in OpenClaw Agent Platform, exploiting lack of integrity…

ai-securityexploitationvulnerability-analysis+1
36 months ago
CVE-2025-62593-PoC preview

CVE-2025-62593-PoC

GitHubboreas37/cve-2025-62593-poc

PoC for CVE-2025-62593: unauthenticated RCE in Ray (CISA KEV). Stdlib-only Python.

ai-securityexploitationpenetration-testing+2
21 month ago
CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape preview

CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape

GitHubgeorge0papasotiriou/cve-2026-1337-ai-coding-assistant-prompt-injection-to-sandbox-escape

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

adversarial-attackai-securitycode-analysis+4
1 month ago
CVE-2024-5452 preview

CVE-2024-5452

GitHubskrkcb2/cve-2024-5452

Detailed technical analysis of CVE-2024-5452, a remote code execution vulnerability in PyTorch Lightning via DeepDiff delta property pollution, with…

ai-securitycode-analysiseducation+3
1 year ago
vulnerable-mcp-servers-lab preview

vulnerable-mcp-servers-lab

GitHubappsecco/vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

ai-securitycode-analysiseducation+7
2769 months ago
sk-cve-2026-26030-lab preview

sk-cve-2026-26030-lab

GitHubinertfluid/sk-cve-2026-26030-lab

Ethical, network-isolated Docker lab reproducing CVE-2026-26030 — Semantic Kernel in-memory vector store filter eval() RCE (patched in 1.39.4)

ai-securitybinary-exploitationeducation+5
13 months ago
CVE-2026-27966 preview

CVE-2026-27966

GitHubshinthink/cve-2026-27966

Pre-auth RCE scanner for Langflow < 1.8.0 — Route Injection + Vertex Injection → Code Execution (CVSS 9.8)

ai-securitycommand-and-controlexploitation+5
22 months ago
WantasticCore preview

WantasticCore

GitHubwantasticapp/wantasticcore

AIO Cloud Managment Server

ai-securityauthenticationcloud-security+6
152 months ago
CyberStrike preview

CyberStrike

GitHubcyberstrikeus/cyberstrike

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

ai-securitycloud-securityeducation+9
2.9k1 day ago
o3_finds_cve-2025-37899 preview

o3_finds_cve-2025-37899

GitHubccss17/o3_finds_cve-2025-37899

Artefacts for blog post on finding CVE-2025-37899 with o3

ai-securityeducationexploitation+3
11 months ago
CVE-2025-3248 preview

CVE-2025-3248

GitHub0xgh057r3c0n/cve-2025-3248

Exploit for Langflow AI Remote Code Execution (Unauthenticated)

ai-securityeducationexploitation+3
1 year ago