Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
125 results
alter-zero preview

alter-zero

GitHublinuztx/alter-zero

RAM efficient terminal agent harness for coding, cybersecurity, and automation.

ai-securitycode-analysiscommand-and-control+6
244 days ago
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

code-analysisconfiguration-auditingdefensive-tools+4
91 year ago
ipaforge preview

ipaforge

GitHubvighnesh91/ipaforge

Dependency-free Python CLI to unpack, inspect, edit, and rebuild iOS .ipa archives, converting plists and strings to XML while preserving Mach-O…

binary-analysiscode-analysisios-security+6
119 days ago
CVE-2026-4813 preview

CVE-2026-4813

GitHubtrachinus/cve-2026-4813

Proof-of-concept exploit for authenticated remote code execution via XSLT injection in Lutece Core, demonstrating command execution through crafted…

code-analysisexploitationpenetration-testing+2
1 month ago
CVE-2026-39902 preview

CVE-2026-39902

GitHubkx00007/cve-2026-39902

Proof-of-concept exploit for authenticated OS command injection (CWE-78) in Cacti ≤1.2.30, achieving remote code execution with CVSS 7.2.

code-analysisexploitationpenetration-testing+2
1 month ago
CVE-2026-25053 preview

CVE-2026-25053

GitHubyadhukrishnam/cve-2026-25053

Vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or…

code-analysisexploitationpenetration-testing+2
27 months ago
CVE-2025-60787 preview

CVE-2025-60787

GitHubprabhatverma47/cve-2025-60787

Proof-of-concept for CVE-2025-60787, demonstrating remote code execution in MotionEye <= 0.43.1b4 via client-side validation bypass and command…

code-analysisexploitationpenetration-testing+3
1 year ago
CVE-2026-22686-RemoteCodeExecution-RCE-PoC preview

CVE-2026-22686-RemoteCodeExecution-RCE-PoC

GitHubmoltengama/cve-2026-22686-remotecodeexecution-rce-poc

Proof-of-concept exploit for CVE-2026-22686, demonstrating remote code execution in Node.js ESM sandboxes via process.getBuiltinModule to bypass…

code-analysisexploitationpayload-development+2
27 months ago
CVE-2026-25546-godot-mcp-0.1.1-OS-Command-Injection preview

CVE-2026-25546-godot-mcp-0.1.1-OS-Command-Injection

GitHubmbanyamer/cve-2026-25546-godot-mcp-0.1.1-os-command-injection

Proof-of-concept exploit for CVE-2026-25546, demonstrating OS command injection in godot-mcp via malicious projectPath parameter, with Python PoC and…

code-analysisexploitationpenetration-testing+2
8 months ago
wheelaudit preview

wheelaudit

GitHubkriskimmerle/wheelaudit

Python Wheel File Security Scanner — scan .whl files for security issues before installation. Detects path traversal (CVE-2026-24049), RECORD…

code-analysisconfiguration-auditingdevsecops+5
37 months ago
CVE-2026-26720-Twenty-RCE preview

CVE-2026-26720-Twenty-RCE

GitHubdillonkirsch/cve-2026-26720-twenty-rce

Proof-of-concept for authenticated remote code execution in Twenty CRM via unsandboxed serverless workflow functions, allowing arbitrary Node.js…

cloud-securitycode-analysisexploitation+3
9 months ago
CVE-2026-0766 preview

CVE-2026-0766

GitHubbitt0n/cve-2026-0766

Proof-of-concept exploit for CVE-2026-0766, a remote code execution vulnerability in OpenWebUI via tool code injection. Includes command execution,…

code-analysiseducationexploitation+3
6 months ago
CVE-2026-22785 preview

CVE-2026-22785

GitHublangbyyi/cve-2026-22785

Exploit tool for CVE-2026-22785, a critical code injection in orval < 7.18.0. Provides shell command execution and file scanning to demonstrate the…

code-analysiseducationexploitation+2
18 months ago
CVE-2026-52617 preview

CVE-2026-52617

GitHubs1ko/cve-2026-52617

Advisory and proof-of-concept for OS command injection in an MCP ffmpeg helper, with root-cause analysis, detector guidance, and mitigations for an…

code-analysisexploitationsupply-chain-security+1
1 month ago
teller preview

teller

GitHubtellerops/teller

Cloud native secrets management for developers - never leave your command line for secrets.

cloud-infrastructure-securitycloud-securitycode-analysis+2
3.2k8 months ago
static-code-analysis-helper preview

static-code-analysis-helper

GitHubosmankandemir/static-code-analysis-helper

Scans project source code across 16 languages to flag dangerous functions linked to SQLi, XSS, SSRF, command injection, weak crypto, and other web…

code-analysisstatic-code-analysisvulnerability-analysis+1
337 months ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
96513 days ago
CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape preview

CVE-2026-1337-AI-Coding-Assistant-Prompt-Injection-to-Sandbox-Escape

GitHubgeorge0papasotiriou/cve-2026-1337-ai-coding-assistant-prompt-injection-to-sandbox-escape

A prompt injection in a code‑review bot that executes AI‑generated fixes in a sandbox. The sandbox uses a blacklist to prevent dangerous commands,…

adversarial-attackai-securitycode-analysis+4
2 months ago
Previous1234567Next