Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
99 results
CVE-2021-38647 preview

CVE-2021-38647

GitHubalteredsecurity/cve-2021-38647

CVE-2021-38647 - POC to exploit unauthenticated RCE #OMIGOD

cloud-securityeducationexploitation+3
67
4 years ago
hatiyar preview

hatiyar

GitHubajutamangdev/hatiyar

Modular penetration testing framework with a Metasploit-like interactive shell, pre-built CVE exploit modules, and cloud/network reconnaissance…

cloud-securityeducationexploit-frameworks+5
239 months ago
CVE-2026-44578 preview

CVE-2026-44578

GitHubdinosn/cve-2026-44578

CVE-2026-44578: Next.js WebSocket Upgrade SSRF — pre-auth credential theft via localhost:80. Lab + exploit + audit.

cloud-securityeducationexploitation+3
93 months ago
CVE-2017-10617 preview

CVE-2017-10617

GitHubgteissier/cve-2017-10617

Proof-of-concept exploit for Juniper Contrail XXE vulnerability (CVE-2017-10617) with Docker-based lab environment demonstrating local file…

cloud-securityeducationexploitation+3
57 years ago
CVE-2026-23007-Serverless-Cold-Start-Memory-Remanence-Data-Leakage- preview

CVE-2026-23007-Serverless-Cold-Start-Memory-Remanence-Data-Leakage-

GitHubgeorge0papasotiriou/cve-2026-23007-serverless-cold-start-memory-remanence-data-leakage-

Simulates CVE-2026-23007 serverless cold-start memory remanence; demonstrates how persistent global state across Lambda invocations can leak secrets…

cloud-securityeducationexploitation+2
28 days ago
CVE-2021-38647-POC-and-Demo-environment preview

CVE-2021-38647-POC-and-Demo-environment

GitHubsimenbai/cve-2021-38647-poc-and-demo-environment

OMIGod / CVE-2021-38647 POC and Demo environment

cloud-securityeducationexploitation+3
34 years ago
POC_CVE-2026-42880 preview

POC_CVE-2026-42880

GitHubhaerin-l/poc_cve-2026-42880

Reproduces CVE-2026-42880, a critical ArgoCD vulnerability exposing Kubernetes Secrets via ServerSideDiff. Includes automated lab setup, trigger…

cloud-securityeducationexploitation+4
3 months ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 months ago
mitigate-cve-2026-23869-react-server-component-loops preview

mitigate-cve-2026-23869-react-server-component-loops

GitHubshaheryar773/mitigate-cve-2026-23869-react-server-component-loops

Technical troubleshooting repository for fixing infinite rendering vulnerability loops and resource exhaustion threats under CVE-2026-23869 cleanly.

cloud-securityeducationmisconfiguration+2
2 months ago
omigod-lab preview

omigod-lab

GitHubcraig-m-unsw/omigod-lab

A Vagrant VM test lab to learn about CVE-2021-38647 in the Open Management Infrastructure agent (aka "omigod").

cloud-securityeducationexploitation+3
14 years ago
CVE-2026-40175 preview

CVE-2026-40175

GitHub0xblackash/cve-2026-40175

CVE-2026-40175

cloud-securityeducationexploitation+3
4 months ago
CVE-2026-33340 preview

CVE-2026-33340

GitHubregaan/cve-2026-33340

CVE-2026-33340: Critical SSRF in lollms-webui /api/proxy - Unauthenticated arbitrary request forgery (CVSS 9.1)

cloud-securityeducationexploitation+3
4 months ago
cve-2024-34351-demo preview

cve-2024-34351-demo

GitHubjinlei-chen-uwo/cve-2024-34351-demo

Minimal Next.js 14.0.0 demo app for CVE-2024-34351 SSRF vulnerability. Includes exploit setup, interactsh confirmation, Burp interception, and AWS…

cloud-securityeducationexploitation+3
4 months ago
CVE-2025-60012-POC preview

CVE-2025-60012-POC

GitHubsid6224/cve-2025-60012-poc

A POC for the Apache Livy Unauthorized File Access Vunerability

cloud-securityeducationexploitation+3
5 months ago
CVE-2026-32794 preview

CVE-2026-32794

GitHubsnailsploit/cve-2026-32794

CVE-2026-32794: TLS Certificate Verification Bypass in Apache Airflow Databricks Provider

cloud-securityeducationmisconfiguration+3
3 months ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
4 months ago
HTB-Facts-Writeup preview

HTB-Facts-Writeup

GitHubkarimelsheikh1/htb-facts-writeup

HackTheBox Facts machine writeup — CVE-2025-2304, MinIO S3 enumeration, SSH key cracking, and facter privilege escalation.

cloud-securityctfeducation+7
4 months ago
CVE-2026-54420-LiteSpeed-Symlink-Exploit preview

CVE-2026-54420-LiteSpeed-Symlink-Exploit

GitHubfevar54/cve-2026-54420-litespeed-symlink-exploit

PoC de CVE-2026-54420: explotacion via symlink en el plugin LiteSpeed de cPanel/WHM.

cloud-securityeducationexploitation+3
2 months ago
Previous123456Next