Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
983 results
CVE-2025-63571 preview

CVE-2025-63571

GitHubrrespxwnss/cve-2025-63571

Proof of concept demonstrating Server-Side Request Forgery in ChatGPT, allowing attackers to force the AI to make arbitrary HTTP requests, exposing…

cloud-securityexploitationinformation-gathering+3
10 months ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Appspec YML and YAML leaks

api-securitycloud-securityinformation-gathering+4
12 years ago
CVE-2022-3294 preview

CVE-2022-3294

GitHubarbaaz29/cve-2022-3294

Privilege Escalation using nodes/proxy (create action allowed) and nodes/status (update/patch actions allowed)

cloud-securitycontainer-securityexploitation+3
8 months ago
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
0 years ago
vulnerability-remediation-cve-2013-3900 preview

vulnerability-remediation-cve-2013-3900

GitHubksgassama-lab/vulnerability-remediation-cve-2013-3900

End-to-end remediation of CVE-2013-3900 using PowerShell and Tenable. Demonstrates vulnerability identification, registry hardening, and automated…

cloud-securityconfiguration-auditingeducation+3
8 months ago
CVE-2025-34159 preview

CVE-2025-34159

GitHubeyodav/cve-2025-34159

A critical Remote Code Execution (RCE) vulnerability exists in Coolify's application deployment workflow. This flaw allows a low-privileged member to…

cloud-securitycontainer-securityexploitation+5
1 year ago
bug-bounty-reports-desai-vinayak preview

bug-bounty-reports-desai-vinayak

GitHubdesaivinayak449/bug-bounty-reports-desai-vinayak

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

cloud-securitycurated-resourcesdns-analysis+6
10 months ago
POC-for-CVE-2025-9074 preview

POC-for-CVE-2025-9074

GitHubx0da6h/poc-for-cve-2025-9074

一个容器逃逸漏洞POC

cloud-securitycontainer-escapecontainer-security+3
8 months ago
CVE-2024-10220-Kubernetes-gitRepo-Volume-Vulnerability preview

CVE-2024-10220-Kubernetes-gitRepo-Volume-Vulnerability

GitHubmrk336/cve-2024-10220-kubernetes-gitrepo-volume-vulnerability

CVE-2024-10220 reveals a critical flaw in Kubernetes’ deprecated gitRepo volume type, allowing attackers to execute arbitrary commands via malicious…

cloud-infrastructure-securitycloud-securitycontainer-security+6
1 year ago
cve-2025-9074-poc preview

cve-2025-9074-poc

GitHubxrayzen/cve-2025-9074-poc

2025年8月20日に公開されたDockerDesktopの脆弱性(対策済み)を実証する

cloud-securitycontainer-securityeducation+3
1 year ago
CVE-2026-48172---LiteSpeed-cPanel-Plugin-Version-Auditor preview

CVE-2026-48172---LiteSpeed-cPanel-Plugin-Version-Auditor

GitHubfevar54/cve-2026-48172---litespeed-cpanel-plugin-version-auditor

Auditor de version para CVE-2026-48172: verifica localmente si el plugin LiteSpeed de cPanel es vulnerable, sin explotar.

cloud-securityconfiguration-auditingvulnerability-analysis+2
3 months ago
grafana-CVE-2024-9264 preview

grafana-CVE-2024-9264

GitHubpatrickpichler/grafana-cve-2024-9264

Grafana image with DuckDB binary present vulnerable to exploit CVE-2024-9264

cloud-securitycontainer-securityeducation+2
1 year ago
imagick_secure_puppet preview

imagick_secure_puppet

GitHubjackdpeterson/imagick_secure_puppet

Puppet module to harden ImageMagick policy.xml against CVE-2016-3714 by restricting dangerous image processing directives.

cloud-securityconfiguration-auditingdevsecops+2
10 years ago
cfengine-CVE-2016-2118 preview

cfengine-CVE-2016-2118

GitHubnickanderson/cfengine-cve-2016-2118

An example detection and remediation policy.

cloud-securityconfiguration-auditingdevsecops+2
10 years ago
centos-dirty-cow-ansible preview

centos-dirty-cow-ansible

GitHubistenrot/centos-dirty-cow-ansible

Ansible playbook automating CVE-2016-5195 (Dirty COW) mitigation on CentOS/Scientific Linux using SystemTap kernel module generation.

cloud-securityconfiguration-auditingdevsecops+3
9 years ago
harbor-give-me-admin preview

harbor-give-me-admin

GitHubthelsa/harbor-give-me-admin

harbor(<1.7.6/1.8.3) privilege escalation (CVE-2019-16097)

cloud-securityexploitationpenetration-testing+3
6 years ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubim007/cve-2023-23397

PowerShell script to detect and remediate CVE-2023-23397 privilege escalation vulnerability in Microsoft Outlook and Exchange environments.

cloud-securityconfiguration-auditingemail-security+3
3 years ago
bucket-brute preview

bucket-brute

GitHubrandomrobbiebf/bucket-brute

Aws S3 Tko Tool

cloud-infrastructure-securitycloud-securitymisconfiguration+3
6 years ago
Previous1…515253…55Next