Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
178 results
source-packages preview

source-packages

GitHubmudongliang/source-packages

This repo stores source code of the vulnerable program.

code-analysiscurated-resourceseducation+2
12
7 years ago
rustproofing-linux preview

rustproofing-linux

GitHubnccgroup/rustproofing-linux

Educational examples porting Linux kernel vulnerabilities to Rust, featuring intentionally vulnerable code and exploits for learning kernel security…

binary-exploitationcode-analysiscurated-resources+4
223 years ago
rocacheck preview

rocacheck

GitHubtitanous/rocacheck

Go package that checks if RSA keys are vulnerable to ROCA / CVE-2017-15361

code-analysiscryptographyencryption-decryption-tools+2
168 years ago
CVE-2020-26259 preview

CVE-2020-26259

GitHubjas502n/cve-2020-26259

CVE-2020-26259: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has…

code-analysisexploitationpenetration-testing+2
255 years ago
vulnrepro-benchmark preview

vulnrepro-benchmark

GitHubfarhadalimohammadi-dir/vulnrepro-benchmark

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

ai-securitycode-analysisctf+7
92 months ago
Spring-Data-Mongodb-Demo preview

Spring-Data-Mongodb-Demo

GitHubli8u99/spring-data-mongodb-demo

Demo environment for CVE-2022-22980 (Spring Data MongoDB SpEL injection RCE) with vulnerable application code for security testing and education.

code-analysiseducationexploitation+2
114 years ago
CVE-2026-23008-Solidity-Assembly-Return-Data-Size-Confusion preview

CVE-2026-23008-Solidity-Assembly-Return-Data-Size-Confusion

GitHubgeorge0papasotiriou/cve-2026-23008-solidity-assembly-return-data-size-confusion

Educational PoC for Solidity assembly return-data size confusion; includes vulnerable contract, exploit simulation, and mitigation guidance for…

code-analysiseducationexploitation+1
25 days ago
JavaScript-Example preview

JavaScript-Example

GitHubseal-sec-demo-2/javascript-example

Seal Security example — vulnerable npm app (EJS CVE-2022-29078) remediated to sealed versions; GitHub Actions + Jenkins integration

code-analysisdevsecopseducation+3
27 days ago
CVE-2025-3776 preview

CVE-2025-3776

GitHubnxploited/cve-2025-3776

WordPress Verification SMS with TargetSMS Plugin <= 1.5 is vulnerable to Remote Code Execution (RCE)

code-analysiseducationexploitation+3
71 year ago
CVE-2021-21014 preview

CVE-2021-21014

GitHubhoangkien1020/cve-2021-21014

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a file upload restriction bypass. Successful…

code-analysisexploitationpenetration-testing+2
45 years ago
CVE-2020-28458 preview

CVE-2020-28458

GitHubfazilbaig1/cve-2020-28458

Affected versions of this package are vulnerable to Prototype Pollution.

code-analysisexploitationstatic-analysis+2
51 year ago
cve-2020-11023-scanner preview

cve-2020-11023-scanner

GitHubhoneyb33z/cve-2020-11023-scanner

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

code-analysiscrawlerstatic-analysis+3
41 year ago
log4j_scanner preview

log4j_scanner

GitHubdbzoo/log4j_scanner

Filesystem scanner for Log4Shell (CVE-2021-44228) and related CVEs. Detects vulnerable JAR files via hash matching and class presence. Runs…

code-analysisdevsecopsincident-response+3
44 years ago
checkmk-log4j-scanner preview

checkmk-log4j-scanner

GitHubinettgmbh/checkmk-log4j-scanner

Checkmk extension that scans JAR, WAR, EAR, and AAR files for Log4j versions vulnerable to CVE-2021-44228 by inspecting META-INF pom.properties…

code-analysislog-analysisstatic-analysis+2
42 years ago
CVE-2025-56815 preview

CVE-2025-56815

GitHubxiaoxiaoranxxx/cve-2025-56815

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

code-analysisexploitationmisconfiguration+3
511 months ago
cve-2023-34035-mitigations preview

cve-2023-34035-mitigations

GitHubjzheaux/cve-2023-34035-mitigations

Demonstrates CVE-2023-34035 vulnerability in Spring Security with vulnerable and mitigated sample applications, teaching proper servlet mapping and…

api-securitycode-analysiseducation+3
43 years ago
shellshocker-python preview

shellshocker-python

GitHubakiraaisha/shellshocker-python

This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271

code-analysisexploitationinformation-gathering+2
311 years ago
graylog-cve-2024-24824-exploit preview

graylog-cve-2024-24824-exploit

GitHubrootkited/graylog-cve-2024-24824-exploit

Proof-of-concept exploit for CVE-2024-24824 demonstrating how an arbitrary class loading primitive can be transformed into remote code execution on…

code-analysiseducationexploitation+3
2 months ago
Previous123…10Next