Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2024-2432-PaloAlto-GlobalProtect-EoP preview

CVE-2024-2432-PaloAlto-GlobalProtect-EoP

GitHubhagrid29/cve-2024-2432-paloalto-globalprotect-eop

Proof-of-concept exploit for CVE-2024-2432 demonstrating local privilege escalation on Windows via arbitrary file delete through symbolic link attack…

binary-exploitationexploitationpenetration-testing+2
63
2 years ago
CVE-2024-0311 preview

CVE-2024-0311

GitHubcalligraf0/cve-2024-0311

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

binary-exploitationexploitationids-ips-evasion+4
91 year ago
CVE-2026-41096 preview

CVE-2026-41096

GitHubm0n1x90/cve-2026-41096

Proof-of-concept exploit for CVE-2026-41096: heap overflow in Windows DNS Client's DnsRawTruncateMessageForUdp(). Includes rogue DNS server and…

binary-exploitationdns-analysisexploitation+3
33 months ago
zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri preview

zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

GitHubhunt-benito/zephyr-lwm2m-firmware-update-oob-read-cve-2026-10672-truncated-package-uri

Proof-of-concept exploit for CVE-2026-10672, an out-of-bounds read in Zephyr RTOS LwM2M firmware-update pull client. Includes standalone C…

binary-exploitationeducationembedded-systems-security+5
2 months ago
CVE-2023-38041-POC preview

CVE-2023-38041-POC

GitHubewilded/cve-2023-38041-poc

Ivanti Pulse Secure Client Connect Local Privilege Escalation CVE-2023-38041 Proof of Concept

binary-exploitationexploitationpenetration-testing+2
22 years ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubtaurusxin/cve-2021-44228

Educational RCE exploit for CVE-2021-44228 (Log4Shell) with RMI server and client demonstrating vulnerability recurrence via calculator popup.

binary-exploitationeducationexploitation+2
24 years ago
CVE-2023-25136-PoC preview

CVE-2023-25136-PoC

GitHublane0218/cve-2023-25136-poc

Minimal Docker-based reproduction environment for OpenSSH 9.1p1 pre-auth double-free vulnerability (CVE-2023-25136), demonstrating memory corruption…

binary-exploitationeducationexploitation+2
10 months ago
Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation preview

Ivanti-Pulse_VPN-Client_Exploit-CVE-2023-35080_Privilege-escalation

GitHubhophouse/ivanti-pulse_vpn-client_exploit-cve-2023-35080_privilege-escalation

Exploit for CVE-2023-35080 leveraging a write primitive in the Ivanti/Pulse VPN client kernel driver on Windows to achieve privilege escalation.

binary-exploitationexploitationexploit-frameworks+2
12 years ago
CVE-2024-11467 preview

CVE-2024-11467

GitHubnull-event/cve-2024-11467

VMWare Horizon client for macOS LPE due to an XPC logic flaw. Belated POC for an 0-day I responsibly disclosed to Omnissa.

binary-exploitationcode-analysisexploitation+4
7 months ago
CVE-2024-5243-pwn2own-toronto-2023 preview

CVE-2024-5243-pwn2own-toronto-2023

GitHubredpack-kr/cve-2024-5243-pwn2own-toronto-2023

Pre-authentication Remote Code Execution exploit for TP-Link Omada ER605 router via DDNS client daemon (cmxddnsd)

binary-exploitationeducationexploitation+4
7 months ago
CVE-2007-2447 preview

CVE-2007-2447

GitHubfoudadev/cve-2007-2447

Educational exploit implementation for CVE-2007-2447 Samba 3.0.20-3.0.25rc username map script command execution vulnerability with Python SMB client…

binary-exploitationcommand-and-controleducation+6
2 years ago
Safenet_SAC_CVE-2021-42056 preview

Safenet_SAC_CVE-2021-42056

GitHubz00z00z00/safenet_sac_cve-2021-42056

Safenet Authentication Client Privilege Escalation - CVE-2021-42056

binary-exploitationexploitationpenetration-testing+3
3 years ago
CVE-2022-37017 preview

CVE-2022-37017

GitHubapeppels/cve-2022-37017

Bypass for Symantec Endpoint Protection's Client User Interface Password

authentication-authorizationbinary-exploitationexploitation+4
2 years ago
Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597- preview

Point-to-Point-Protocol-Daemon-RCE-Vulnerability-CVE-2020-8597-

GitHubdilan-diaz/point-to-point-protocol-daemon-rce-vulnerability-cve-2020-8597-

University assignment documenting CVE-2020-8597, a stack buffer overflow in pppd's EAP parser, with a remote code execution exploit demonstration…

binary-exploitationeducationexploitation+3
6 years ago
CVE-2015-7547-proj-master preview

CVE-2015-7547-proj-master

GitHubbluebluelan/cve-2015-7547-proj-master

Proof-of-concept exploit for CVE-2015-7547, a glibc getaddrinfo() stack-based buffer overflow. Includes server and client components to trigger the…

binary-exploitationdns-analysisexploitation+2
9 years ago
CVE-2020-3153 preview

CVE-2020-3153

GitHubraspberry-pie/cve-2020-3153

PoC for CVE-2020-3153 Cisco AnyConnect Secure Mobility Client EoP

binary-exploitationexploitationpenetration-testing+2
6 years ago
CVE-2020-8249 preview

CVE-2020-8249

GitHubmbadanoiu/cve-2020-8249

CVE-2020-8249: Buffer Overflow in Pulse Secure VPN Linux Client

binary-exploitationexploitationpenetration-testing+2
2 years ago
CVE-2002-0991 preview

CVE-2002-0991

GitHubalt3kx/cve-2002-0991

Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier

binary-exploitationexploitationpenetration-testing+2
8 years ago
Previous12Next