Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
80 results
XCP_ng_CVE-2026-31431_tester preview

XCP_ng_CVE-2026-31431_tester

GitHubgrabesec/xcp_ng_cve-2026-31431_tester

Non-destructive detector for CVE-2026-31431 (Copy Fail) local privilege escalation in XCP-ng 8.3 Dom0, validating kernel vulnerability via page-cache…

cloud-securityexploitationpenetration-testing+1
3 months ago
CVE-2026-29954 preview

CVE-2026-29954

GitHubb0b0haha/cve-2026-29954

Proof-of-concept demonstrating SSRF and HTTP header injection in KubePlus ResourceComposition, enabling cloud metadata access and IAM credential…

cloud-securityexploitationpenetration-testing+2
5 months ago
spinnaker-poc preview

spinnaker-poc

GitHubzeropathai/spinnaker-poc

POCs for CVE-2026-32604 and CVE-2026-32613 which allow post-auth RCE and credential theft in Spinnaker

cloud-securityexploitationpenetration-testing+3
4 months ago
CVE-2026-24306 preview

CVE-2026-24306

GitHubexploreunknowed/cve-2026-24306

Proof-of-concept exploit for Azure Front Door privilege escalation (CVE-2026-24306) enabling routing rule injection, backend pool modification, and…

cloud-securityexploitationpenetration-testing+3
7 months ago
CVE-2021-25741 preview

CVE-2021-25741

GitHubbetep0k/cve-2021-25741

Exploit for CVE-2021-25741 Kubernetes vulnerability allowing host filesystem mount into pods via race condition, with deployment scripts and…

cloud-securitycontainer-escapeexploitation+2
304 years ago
cve-2021-43858 preview

cve-2021-43858

GitHub0rx1/cve-2021-43858

Exploit for MinIO privilege escalation vulnerability CVE-2021-43858, allowing unauthorized access to cloud storage. Written in Go, run with 'go run…

cloud-securityexploitationpenetration-testing+2
34 years ago
CVE-2025-62506 preview

CVE-2025-62506

GitHubyoshino-s/cve-2025-62506

Verification script for CVE-2025-62506, a privilege escalation vulnerability in MinIO service accounts, testing if restricted accounts can bypass…

cloud-securityexploitationpenetration-testing+2
10 months ago
CVE-2026-69836-EXP preview

CVE-2026-69836-EXP

GitHubsentinel-aidefense/cve-2026-69836-exp

CVE-2026-69836 — Unauthenticated RCE via Entra ID deserialization

cloud-securityexploitationpenetration-testing+2
19 days ago
pentestcode preview

pentestcode

GitHubs0ld13rr/pentestcode

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

ai-securitycloud-securityctf+9
51410 days ago
bentoml_CVE-2025-54381 preview

bentoml_CVE-2025-54381

GitHubrockmelodies/bentoml_cve-2025-54381

Ai相关

cloud-securityexploitationpenetration-testing+2
1 year ago
CVE-2026-64849 preview

CVE-2026-64849

GitHubbiutrap/cve-2026-64849

Proof-of-concept exploit for CVE-2026-64849: triggers SSRF in MLflow webhook API via crafted POST, fetching cloud instance metadata from…

api-securitycloud-securityexploitation+4
12 days ago
google-osconfig-privesc preview

google-osconfig-privesc

GitHubirsl/google-osconfig-privesc

Proof of concept about the privilege escalation flaw identified in Google's Osconfig

cloud-securityexploitationpenetration-testing+4
105 years ago
harbor-give-me-admin preview

harbor-give-me-admin

GitHubthelsa/harbor-give-me-admin

harbor(<1.7.6/1.8.3) privilege escalation (CVE-2019-16097)

cloud-securityexploitationpenetration-testing+3
6 years ago
CVE-2024-6678 preview

CVE-2024-6678

GitHubfallenskill1/cve-2024-6678

PoC for CVE-2024-6678

cloud-securitydevsecopsexploitation+3
43 months ago
outpost preview

outpost

GitHubustayready/outpost

AWS Testing and Reporting Management Tool

cloud-infrastructure-securitycloud-securityconfiguration-auditing+3
203 years ago
tunnelx preview

tunnelx

GitHubprojectdiscovery/tunnelx

TunnelX is a lightweight ingress tunneling tool designed to create a secure SOCKS5 proxy server for routing network traffic.

authenticationcloud-securitynetwork-security+3
23 days ago
flask_appengine_redirector preview

flask_appengine_redirector

GitHubkillswitch-gui/flask_appengine_redirector

Google App Engine Flask C2 redirector

cloud-securitycommand-and-controlpenetration-testing+2
89 years ago
flask_heroku_redirector preview

flask_heroku_redirector

GitHubkillswitch-gui/flask_heroku_redirector

flask heroku C2 redirector template

cloud-securitycommand-and-controlpenetration-testing+3
119 years ago
Previous12345Next