Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2023-38041-POC preview

CVE-2023-38041-POC

GitHubewilded/cve-2023-38041-poc

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

binary-exploitationexploitationpenetration-testing+2
2
2 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubtaurusxin/cve-2021-44228

Educational RCE exploit for CVE-2021-44228 (Log4Shell) with RMI server and client demonstrating vulnerability recurrence via calculator popup.

binary-exploitationeducationexploitation+2
24 years ago
zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri preview

zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

GitHubhunt-benito/zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

binary-exploitationeducationembedded-systems-security+5
2 months ago
CVE-2024-0311 preview

CVE-2024-0311

GitHubcalligraf0/cve-2024-0311

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

binary-exploitationexploitationids-ips-evasion+4
91 year ago
CVE-2013-2977 preview

CVE-2013-2977

GitHubdefrancescojp/cve-2013-2977

Proof-of-concept exploit for CVE-2013-2977: IBM Lotus Notes PNG integer overflow leading to arbitrary code execution when a malicious email is opened…

binary-exploitationemail-securityexploitation+1
5 years ago
vucsa preview

vucsa

GitHubwarxim/vucsa

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

binary-exploitationctfeducation+3
1023 years ago
uboatdemo preview

uboatdemo

GitHubpqsec/uboatdemo

A demo server for CVE-2016-3955 (UBOAT)

binary-exploitationembedded-systems-securityexploitation+2
59 years ago
CVE-2026-41096 preview

CVE-2026-41096

GitHubm0n1x90/cve-2026-41096

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

binary-exploitationdns-analysisexploitation+3
33 months ago
CVE-2026-33317 preview

CVE-2026-33317

GitHub0xbbdd/cve-2026-33317

Proof-of-concept for CVE-2026-33317, an out-of-bounds write in OP-TEE PKCS#11 TA, demonstrating Secure World heap corruption via a malformed…

binary-exploitationembedded-systems-securityexploitation+3
4 months ago
CVE-2015-7547-proj-master preview

CVE-2015-7547-proj-master

GitHubbluebluelan/cve-2015-7547-proj-master

Proof-of-concept exploit for CVE-2015-7547, a glibc getaddrinfo() stack-based buffer overflow. Includes server and client components to trigger the…

binary-exploitationdns-analysisexploitation+2
9 years ago
CVE-2022-37017 preview

CVE-2022-37017

GitHubapeppels/cve-2022-37017

Bypass for Symantec Endpoint Protection's Client User Interface Password

authentication-authorizationbinary-exploitationexploitation+4
2 years ago
Libssh-server-CVE-2018-10933 preview

Libssh-server-CVE-2018-10933

GitHubcyberharsh/libssh-server-cve-2018-10933

Proof-of-concept exploit for CVE-2018-10933, demonstrating SSH authentication bypass via MSG_USERAUTH_SUCCESS injection. Includes Docker setup and…

authenticationbinary-exploitationexploitation+3
6 years ago
CVE-2024-11467 preview

CVE-2024-11467

GitHubnull-event/cve-2024-11467

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

binary-exploitationcode-analysisexploitation+4
7 months ago
CVE-2024-2432-PaloAlto-GlobalProtect-EoP preview

CVE-2024-2432-PaloAlto-GlobalProtect-EoP

GitHubhagrid29/cve-2024-2432-paloalto-globalprotect-eop

Proof-of-concept exploit for CVE-2024-2432 demonstrating local privilege escalation on Windows via arbitrary file delete through symbolic link attack…

binary-exploitationexploitationpenetration-testing+2
632 years ago
CVE-2024-55968 preview

CVE-2024-55968

GitHubwi1dn00b/cve-2024-55968

Exploit POC Code for CVE-2024-55968

binary-exploitationexploitationpenetration-testing+2
21 year ago
Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation preview

Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation

GitHubhophouse/ivanti-pulse_vpn-client_exploit-cve-2023-35080_privilege-escalation

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

binary-exploitationexploitationexploit-frameworks+2
12 years ago
CVE-2024-5243-pwn2own-toronto-2023 preview

CVE-2024-5243-pwn2own-toronto-2023

GitHubredpack-kr/cve-2024-5243-pwn2own-toronto-2023

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

binary-exploitationeducationexploitation+4
7 months ago
Safenet_SAC_CVE-2021-42056 preview

Safenet_SAC_CVE-2021-42056

GitHubz00z00z00/safenet_sac_cve-2021-42056

Safenet Authentication Client Privilege Escalation - CVE-2021-42056

binary-exploitationexploitationpenetration-testing+3
3 years ago
Previous12Next