Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
549 results
CVE-2026-65320-fastcore preview

CVE-2026-65320-fastcore

GitHubrahulreddykarne/cve-2026-65320-fastcore

Documents CVE-2026-65320, a tar-slip path traversal in fastcore's untar_dir(), with a harmless proof-of-concept demonstrating arbitrary file write…

code-analysiseducationexploitation+3
2 days ago
JavaSecLab preview

JavaSecLab

GitHubwhgojp/javaseclab

Comprehensive Java vulnerability lab with vulnerable and fixed code, attack scenarios, source/sink audit notes, and secure coding guidance for…

code-analysisctfdevsecops+6
8813 months ago
Veridiff preview

Veridiff

GitHubveridiff/veridiff

Dynamic branch-divergence finder for native code -- traces two Frida executions and finds the exact instruction where they diverge.

binary-analysisbinary-exploitationcode-analysis+7
411 days ago
shiro preview

shiro

GitHubsassoftware/shiro

CVE-2026-49268 — Analysis and Remediation of an LDAP Injection Authentication Bypass Vulnerability

authenticationcode-analysiseducation+3
119 days ago
log4shell-CVE-2021-44228 preview

log4shell-CVE-2021-44228

GitHubrh-rahulshetty/log4shell-cve-2021-44228

Deliberately vulnerable Java/Maven fixture for testing Log4Shell (CVE-2021-44228) detection, code-impact classification, and remediation guidance in…

code-analysisdevsecopseducation+4
14 days ago
CVE-2026-0303 preview

CVE-2026-0303

GitHubyonliud/cve-2026-0303

Checkov PoC: arbitrary code execution through auto-loaded configuration and unsigned external Python checks.

code-analysisdevsecopseducation+5
18 days ago
obsidian-note-toolbar-PoC preview

obsidian-note-toolbar-PoC

GitHubsqueeze440/obsidian-note-toolbar-poc

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

code-analysiseducationexploitation+5
17 days ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubzoly-zoly/cve-2025-3248

Educational analysis and proof-of-concept exploit for CVE-2025-3248, a critical unauthenticated code injection vulnerability in Langflow, including…

code-analysiseducationexploitation+3
117 days ago
FreePBX-SQLi-Exploit-Privilege-escalation preview

FreePBX-SQLi-Exploit-Privilege-escalation

GitHubitsc1sco/freepbx-sqli-exploit-privilege-escalation

This walkthrough documents the complete compromise of the HTB machine Connected.

code-analysisctfeducation+5
11 month ago
SAFE preview

SAFE

GitHubnanda-rani/safe

A contextual security auditing system for research artifacts

ai-securitycode-analysiseducation+2
1 month ago
npm-demo preview

npm-demo

GitHubalonnavon/npm-demo

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

code-analysiseducationvulnerability-analysis+2
7 months ago
CVE-2026-10036-speechbrain-rce preview

CVE-2026-10036-speechbrain-rce

GitHubsaiteja-erukude/cve-2026-10036-speechbrain-rce

SpeechBrain < 1.1.1 checkpoint metadata RCE via unsafe PyYAML parsing of CKPT.yaml.

code-analysiseducationexploitation+2
1 month ago
CVE-2026-2964-Lab preview

CVE-2026-2964-Lab

GitHubthegenetic/cve-2026-2964-lab

Educational lab demonstrating CVE-2026-2964, a prototype pollution vulnerability in web-audio-recorder-js leading to RCE. Includes vulnerable and…

code-analysiseducationexploitation+4
6 months ago
CVE-2026-22038 preview

CVE-2026-22038

GitHubsivaadityacoder/cve-2026-22038

Detailed analysis of CVE-2026-22038, a high-severity vulnerability in AutoGPT Stagehand blocks that logs API keys in plaintext, including root cause,…

code-analysiseducationlog-analysis+2
5 months ago
CVE-2026-26198-analysis preview

CVE-2026-26198-analysis

GitHubsergicortesabadia/cve-2026-26198-analysis

Deep dive into a critical SQL injection in Python's Ormar ORM — reproduction, fix, and tests

code-analysiseducationpapers-research+2
6 months ago
CVE-2026-33154 preview

CVE-2026-33154

GitHubredyank/cve-2026-33154

Proof-of-concept exploit for CVE-2026-33154, demonstrating remote code execution via SSTI in Dynaconf's Jinja resolver, with analysis and mitigation…

code-analysiseducationexploitation+2
5 months ago
deephas-1.0.7-Prototype-Pollution-PoC-CVE-2026-25047- preview

deephas-1.0.7-Prototype-Pollution-PoC-CVE-2026-25047-

GitHubmbanyamer/deephas-1.0.7-prototype-pollution-poc-cve-2026-25047-

Proof-of-concept demonstrating prototype pollution in deephas <=1.0.7 (CVE-2026-25047) leading to arbitrary code execution and denial of service,…

code-analysiseducationexploitation+2
7 months ago
CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE preview

CVE-2026-26030-Microsoft-Semantic-Kernel-1.39.4-RCE

GitHubmbanyamer/cve-2026-26030-microsoft-semantic-kernel-1.39.4-rce

Proof-of-concept exploit for CVE-2026-26030, demonstrating remote code execution via unsafe filter expressions in Microsoft Semantic Kernel's…

code-analysiseducationexploitation+2
17 months ago
Previous12…31Next