Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
gobuster preview

gobuster

GitHuboj/gobuster

Directory/File, DNS and VHost busting tool written in Go

cloud-securitydns-subdomain-enumerationfuzzing+3
14.0k7 months ago
HostileSubBruteforcer preview

HostileSubBruteforcer

GitHubnahamsec/hostilesubbruteforcer

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

cloud-securitydns-subdomain-enumerationinformation-gathering+3
4839 years ago
XCP_ng_CVE-2026-43284_tester preview

XCP_ng_CVE-2026-43284_tester

GitHubgrabesec/xcp_ng_cve-2026-43284_tester

Diagnostic tool to test XCP-ng dom0 exposure to CVE-2026-43284 (Dirty Frag) local privilege escalation via xfrm-ESP kernel subsystem, with automated…

binary-exploitationcloud-securityeducation+4
3 months ago
CVE-2025-9074-Docker-Exploit preview

CVE-2025-9074-Docker-Exploit

GitHubshaoshi17/cve-2025-9074-docker-exploit

Exploit tool for CVE-2025-9074, enabling unauthorized Docker API access for container escape, host file read/write, and arbitrary command execution…

cloud-securitycontainer-escapecontainer-security+4
128 months ago
CVE-2026-25604-PoC preview

CVE-2026-25604-PoC

GitHubjohn-jung/cve-2026-25604-poc

Proof-of-concept demonstrating Host Header Injection leading to SAML authentication bypass in Apache Airflow's AWS Auth Manager, with token theft and…

authentication-authorizationcloud-securityeducation+4
4 months ago
Januscape preview

Januscape

GitHubv4bel/januscape

KVM/x86 guest-to-host escape exploit (CVE-2026-53359) leveraging a use-after-free in shadow MMU emulation. Includes PoC for triggering host kernel…

binary-exploitationcloud-securityexploitation+4
54618 days ago
Zapscape preview

Zapscape

GitHubv4bel/zapscape

PoC exploit for CVE-2026-64561, a KVM/x86 shadow MMU use-after-free enabling guest-to-host escape with kernel root code execution on the host.

binary-exploitationcloud-securityexploitation+3
15818 days ago
CVE-2021-1056 preview

CVE-2021-1056

GitHubpokerfacesad/cve-2021-1056

Proof-of-concept demonstrating GPU container escape via character device file creation, enabling host GPU access in multi-tenant Kubernetes and HPC…

cloud-securitycontainer-securityexploitation+3
165 years ago
CVE-2019-5736 preview

CVE-2019-5736

GitHubjas502n/cve-2019-5736

Exploit for CVE-2019-5736: runc container escape that overwrites host docker-runc binary with a payload, triggered via docker exec.

cloud-infrastructure-securitycloud-securitycontainer-escape+3
147 years ago
CVE-2024-0132 preview

CVE-2024-0132

GitHubr0binak/cve-2024-0132

Proof-of-concept exploit for CVE-2024-0132 demonstrating TOCTOU-based container escape via NVIDIA Container Toolkit's library mounting mechanism,…

cloud-securitycontainer-escapecontainer-security+3
61 year ago
CVE-2024-21626 preview

CVE-2024-21626

GitHubcdxiaodong/cve-2024-21626

Proof-of-concept exploit for CVE-2024-21626 runc container breakout via leaked file descriptors and process.cwd manipulation, enabling host…

cloud-securitycontainer-escapecontainer-security+3
52 years ago
poc-cve-2024-0132 preview

poc-cve-2024-0132

GitHubssst0n3/poc-cve-2024-0132

Proof-of-concept exploit for CVE-2024-0132 enabling container escape via NVIDIA container toolkit, allowing host filesystem access and Docker daemon…

cloud-securitycontainer-escapecontainer-security+3
51 year ago
CVE-2025-9074 preview

CVE-2025-9074

GitHubc0gnit00/cve-2025-9074

PHP-based proof-of-concept exploit for CVE-2025-9074, enabling unauthenticated remote code execution via Docker Engine API with container escape,…

cloud-securitycommand-and-controlcontainer-escape+8
2 months ago
kata-cve-2020-2023-poc preview

kata-cve-2020-2023-poc

GitHubssst0n3/kata-cve-2020-2023-poc

Proof-of-concept exploit for Kata Containers container escape (CVE-2020-2023) using mknod to modify guest filesystem and overwrite system binaries…

cloud-securitycontainer-escapecontainer-security+3
33 years ago
CVE-2026-53359 preview

CVE-2026-53359

GitHubndouglas-cloudsmith/cve-2026-53359

A 16-year-old bug in the Linux kernel lets a rented VM break out and attack the host it runs on. Intel and AMD alike. Januscape is a use-after-free…

cloud-securitycontainer-escapeexploitation+1
1 month ago
CVE-2026-44881_exploit preview

CVE-2026-44881_exploit

GitHub0xdak/cve-2026-44881_exploit

Single-script exploit for CVE-2026-44881 that chains .git credential leakage, Portainer Git-symlink injection, arbitrary host file read, and SSH…

cloud-securitycontainer-securityctf+7
2 months ago
CVE-2024-21626 preview

CVE-2024-21626

GitHubzhangguanzhang/cve-2024-21626

Proof-of-concept exploit for CVE-2024-21626, a runc container escape vulnerability allowing host file system access via crafted working directory in…

cloud-securitycontainer-escapecontainer-security+3
42 years ago
CVE-2024-21626 preview

CVE-2024-21626

GitHubsk3pper/cve-2024-21626

Proof-of-concept exploits for CVE-2024-21626, a Docker/runc container escape vulnerability, demonstrating multiple attack vectors to access and…

cloud-securitycontainer-escapecontainer-security+3
21 year ago
Previous12Next