Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2078 results
CVE-2020-1947 preview

CVE-2020-1947

GitHubjas502n/cve-2020-1947

Apache ShardingSphere UI YAML解析远程代码执行漏洞

code-analysisexploitationpenetration-testing+3
31
6 years ago
wrongsecrets-binaries preview

wrongsecrets-binaries

GitHubowasp/wrongsecrets-binaries

Source code for the Binaries of OWASP WrongSecrets

binary-analysiscode-analysisctf+6
127 days ago
BlockChainSec preview

BlockChainSec

GitHubal1ex/blockchainsec

BlockChain Security

code-analysiscryptographyctf+5
285 years ago
CVE-2024-22243 preview

CVE-2024-22243

GitHubseanpesce/cve-2024-22243

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

code-analysisctfeducation+4
131 year ago
CVE-2019-17564 preview

CVE-2019-17564

GitHubfairyming/cve-2019-17564

CVE-2019-17564:Apache Dubbo反序列化漏洞

code-analysisexploitationpayload-development+3
86 years ago
bigdecimal-segfault-fix preview

bigdecimal-segfault-fix

GitHubnzkoz/bigdecimal-segfault-fix

Provides a quick workaround for the segfault bug in Ruby (CVE-2009-1904)

code-analysisgeneral-purpose-utilitiesmisconfiguration+1
1417 years ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubadityabhatt3010/react2shell-cve-2025-55182

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

code-analysisctfeducation+6
72 months ago
SGLang-0.5.9-RCE preview

SGLang-0.5.9-RCE

GitHubstuub/sglang-0.5.9-rce

Proof of Concept exploitation of CVE-2026-5760 - RCE in SGLang 0.5.9 via malicious GGUF

code-analysisctfeducation+5
54 months ago
Linux-Kernel-Dirty-Pipe-Exploitation-Logic-Bug- preview

Linux-Kernel-Dirty-Pipe-Exploitation-Logic-Bug-

GitHubbluedragonsecurity/linux-kernel-dirty-pipe-exploitation-logic-bug-

Exploiting CVE-2022-0847 - written by : Antonius (w1sdom)

binary-exploitationcode-analysisctf+5
37 months ago
CorruptQueryAccessWorkaround preview

CorruptQueryAccessWorkaround

GitHublauxjpn/corruptqueryaccessworkaround

The latest workaround for the "Query is corrupt" error introduced with CVE-2019-1402

code-analysisdatabase-securitygeneral-purpose-utilities+2
36 years ago
CVE-2018-20718 preview

CVE-2018-20718

GitHubus3r777/cve-2018-20718

Proof-of-concept exploit for CVE-2018-20718, a PHP object injection vulnerability in Pydio before 8.2.1 enabling unauthenticated remote code…

code-analysisexploitationpenetration-testing+3
37 years ago
CVE-2025-49113-Roundcube-RCE preview

CVE-2025-49113-Roundcube-RCE

GitHubrippsec/cve-2025-49113-roundcube-rce

CVE-2025-49113 – Roundcube ≤1.6.10 post-auth RCE via PHP object deserialization (HackTheBox CTF)

code-analysisctfexploitation+4
4 months ago
mcp-stdio-shellguard preview

mcp-stdio-shellguard

GitHubstudiomeyer-io/mcp-stdio-shellguard

Defense-in-depth bundle for MCP stdio servers: drop-in guardExec/guardSpawn wrappers, AST audit CLI, reference MCP server. Closes the Ox-Security…

api-securitycode-analysisdevsecops+5
2 days ago
CVE-2022-40635 preview

CVE-2022-40635

GitHubmbadanoiu/cve-2022-40635

CVE-2022-40635: Groovy Sandbox Bypass in CrafterCMS

code-analysisexploitationremote-access-tool+2
22 years ago
CVE-2026-34156 preview

CVE-2026-34156

GitHub0xblackash/cve-2026-34156

CVE-2026-34156

code-analysisctfeducation+4
5 months ago
react-rsc-cve-2025-55182-lab preview

react-rsc-cve-2025-55182-lab

GitHubjeanback1/react-rsc-cve-2025-55182-lab

Educational lab demonstrating CVE-2025-55182: Critical RCE in React Server Components via prototype pollution in the Flight protocol

code-analysisctfeducation+4
3 months ago
react-vuln-scanner preview

react-vuln-scanner

GitHubumairahmadh/react-vuln-scanner

A bash script to scan your server for React applications vulnerable to **CVE-2025-55182** — a critical remote code execution vulnerability (CVSS…

code-analysisdevsecopsexploitation+3
19 months ago
roundcube-cve-2025-49113-lab preview

roundcube-cve-2025-49113-lab

GitHubankitpandey383/roundcube-cve-2025-49113-lab

Hands-on exploitation lab for Roundcube Webmail CVE-2025-49113 (authenticated PHP object deserialization → RCE) to read /secret.txt.

code-analysisctfeducation+7
9 months ago
Previous1…567…100Next