Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
cve-2024-49113-ldap_nightmare_reproduction preview

cve-2024-49113-ldap_nightmare_reproduction

GitHubrazureink/cve-2024-49113-ldap_nightmare_reproduction

Reproduction of cve-2024-49113-ldap_nightmare_reproduction

binary-exploitationeducationexploitation+4
1 month ago
zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri preview

zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

GitHubhunt-benito/zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

binary-exploitationeducationembedded-systems-security+5
2 months ago
CVE-2026-41096 preview

CVE-2026-41096

GitHubm0n1x90/cve-2026-41096

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

binary-exploitationdns-analysisexploitation+3
33 months ago
CVE-2026-33317 preview

CVE-2026-33317

GitHub0xbbdd/cve-2026-33317

Proof-of-concept for CVE-2026-33317, an out-of-bounds write in OP-TEE PKCS#11 TA, demonstrating Secure World heap corruption via a malformed…

binary-exploitationembedded-systems-securityexploitation+3
4 months ago
CVE-2025-29824 preview

CVE-2025-29824

GitHubuname1able/cve-2025-29824

Proof-of-concept exploit for CVE-2025-29824, a Windows kernel privilege escalation vulnerability targeting win10_21h2 and win11_23h2 x64 systems with…

binary-exploitationexploitationprivilege-escalation+1
16 months ago
CVE-2024-5243-pwn2own-toronto-2023 preview

CVE-2024-5243-pwn2own-toronto-2023

GitHubredpack-kr/cve-2024-5243-pwn2own-toronto-2023

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

binary-exploitationeducationexploitation+4
7 months ago
CVE-2024-11467 preview

CVE-2024-11467

GitHubnull-event/cve-2024-11467

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

binary-exploitationcode-analysisexploitation+4
7 months ago
CVE-2020-5752 preview

CVE-2020-5752

GitHubx0rbeexd/cve-2020-5752

Local Priviledge Escalation for Druva

binary-exploitationeducationexploitation+3
18 months ago
CVE-2023-25136-PoC preview

CVE-2023-25136-PoC

GitHublane0218/cve-2023-25136-poc

Minimal Docker-based reproduction environment for OpenSSH 9.1p1 pre-auth double-free vulnerability (CVE-2023-25136), demonstrating memory corruption…

binary-exploitationeducationexploitation+2
10 months ago
CVE-2024-55968 preview

CVE-2024-55968

GitHubwi1dn00b/cve-2024-55968

Exploit POC Code for CVE-2024-55968

binary-exploitationexploitationpenetration-testing+2
21 year ago
CVE-2024-0311 preview

CVE-2024-0311

GitHubcalligraf0/cve-2024-0311

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

binary-exploitationexploitationids-ips-evasion+4
91 year ago
CVE-2022-37017 preview

CVE-2022-37017

GitHubapeppels/cve-2022-37017

Bypass for Symantec Endpoint Protection's Client User Interface Password

authentication-authorizationbinary-exploitationexploitation+4
2 years ago
CVE-2007-2447 preview

CVE-2007-2447

GitHubfoudadev/cve-2007-2447

Educational exploit implementation for CVE-2007-2447 Samba 3.0.20-3.0.25rc username map script command execution vulnerability with Python SMB client…

binary-exploitationcommand-and-controleducation+6
2 years ago
CVE-2024-2432-PaloAlto-GlobalProtect-EoP preview

CVE-2024-2432-PaloAlto-GlobalProtect-EoP

GitHubhagrid29/cve-2024-2432-paloalto-globalprotect-eop

Proof-of-concept exploit for CVE-2024-2432 demonstrating local privilege escalation on Windows via arbitrary file delete through symbolic link attack…

binary-exploitationexploitationpenetration-testing+2
632 years ago
CVE-2023-38041-POC preview

CVE-2023-38041-POC

GitHubewilded/cve-2023-38041-poc

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

binary-exploitationexploitationpenetration-testing+2
22 years ago
Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation preview

Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation

GitHubhophouse/ivanti-pulse_vpn-client_exploit-cve-2023-35080_privilege-escalation

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

binary-exploitationexploitationexploit-frameworks+2
12 years ago
CVE-2020-8249 preview

CVE-2020-8249

GitHubmbadanoiu/cve-2020-8249

CVE-2020-8249: Buffer Overflow in Pulse Secure VPN Linux Client

binary-exploitationexploitationpenetration-testing+2
2 years ago
vucsa preview

vucsa

GitHubwarxim/vucsa

Deliberately vulnerable client-server application for learning penetration testing of non-HTTP thick clients. Includes challenges for SQL injection,…

binary-exploitationctfeducation+3
1023 years ago
Previous12Next