Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
159 results
CVE-2026-82329-poc preview

CVE-2026-82329-poc

GitHubgagaltotal/cve-2026-82329-poc

PoC and validation tool for CVE-2026-82329 in JFrog Artifactory. Forges JWT with empty signing key to obtain admin token, verifies access, and…

authenticationcloud-securityexploitation+3
1 month ago
vault-cve-2026-5006-audit preview

vault-cve-2026-5006-audit

GitHubtcollins-hashicorp/vault-cve-2026-5006-audit

Audit and educational toolkit for CVE-2026-5006, a Vault templated-policy slash-injection vulnerability. Includes a read-only audit script generating…

cloud-securityconfiguration-auditingcurated-resources+2
1 month ago
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

cloud-securitycontainer-securityeducation+7
11 month ago
block-copyfail preview

block-copyfail

GitHubmrunalp/block-copyfail

BPF LSM blocker for CVE-2026-31431 (Copy Fail) - zero-reboot remediation for OpenShift 4

cloud-securitycontainer-securitydefensive-tools+2
15 months ago
cve-2026-31431 preview

cve-2026-31431

GitHubnisec-eric/cve-2026-31431

Linux kernel local privilege escalation exploit for CVE-2026-31431, providing a reliable single-shot PoC with multiple language implementations,…

binary-exploitationcloud-securitycontainer-security+7
25 months ago
cve-2026-24514-Kubernetes-Dos preview

cve-2026-24514-Kubernetes-Dos

GitHubmbanyamer/cve-2026-24514-kubernetes-dos

Proof-of-concept exploit for CVE-2026-24514, a memory exhaustion denial-of-service in ingress-nginx validating admission webhook, allowing…

cloud-securitycontainer-securityexploitation+2
7 months ago
CVE-2026-4660-PoC preview

CVE-2026-4660-PoC

GitHubgouldnicholas/cve-2026-4660-poc

PoC for CVE-2026-4660: arbitrary file read via git checkout in hashicorp/go-getter

cloud-securitydevsecopsexploitation+3
15 months ago
CVE-2026-21994 preview

CVE-2026-21994

GitHubg0w6y/cve-2026-21994

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

authenticationcloud-securityexploitation+3
6 months ago
CVE-2026-26720-Twenty-RCE preview

CVE-2026-26720-Twenty-RCE

GitHubdillonkirsch/cve-2026-26720-twenty-rce

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

cloud-securitycode-analysisexploitation+3
8 months ago
CVE-2026-29955 preview

CVE-2026-29955

GitHubb0b0haha/cve-2026-29955

Proof-of-concept for CVE-2026-29955, a command injection vulnerability in KubePlus kubeconfiggenerator allowing remote code execution and…

cloud-securitycontainer-securityexploitation+3
6 months ago
patch-CVE-2026-07219 preview

patch-CVE-2026-07219

GitHubgduma-phdata/patch-cve-2026-07219

Deploys a critical patch for F5 BIG-IP iControl REST vulnerability CVE-2026-07219, with validation and deployment tracking for production…

cloud-securityconfiguration-auditingdevsecops+2
1 month ago
fleet preview

fleet

GitHubfleetdm/fleet

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

cloud-securityconfiguration-auditingdefensive-tools+4
6.9k13h 39m ago
appsec-forge preview

appsec-forge

GitLabappsec-forge/appsec-forge

Structured security knowledge base with production-inspired cases: vulnerability analysis, exploit explanation, remediation, and DevSecOps for…

ai-securitycloud-securitycontainer-security+7
1 month ago
CVE-2022-29170 preview

CVE-2022-29170

GitHubyijikeji/cve-2022-29170

Grafana is an open-source platform for monitoring and observability. In Grafana Enterprise, the Request security feature allows list allows to…

cloud-securityexploitationmisconfiguration+2
3 years ago
vibe-coding-security preview

vibe-coding-security

GitHubboxed-dev/vibe-coding-security

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

ai-securityapi-securityauthentication+9
151 month ago
Awesome-CloudSec-Labs preview

Awesome-CloudSec-Labs

GitHubiknowjason/awesome-cloudsec-labs

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

cloud-securitycontainer-securityctf+7
2.2k1 year ago
CVE-2026-64640 preview

CVE-2026-64640

GitHuboscerd/cve-2026-64640

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

api-securitycloud-securitydata-exfiltration+5
1 month ago
advisories preview

advisories

GitHub0xdea/advisories

A collection of my public security advisories.

cloud-securitycurated-resourceseducation+5
2810 months ago
Previous12…9Next