Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
549 results
CVE-2020-36184 preview

CVE-2020-36184

GitHubal1ex/cve-2020-36184

CVE-2020-36184 && Jackson-databind RCE

code-analysiseducationexploitation+3
155 years ago
CVE-2024-22243 preview

CVE-2024-22243

GitHubseanpesce/cve-2024-22243

Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).

code-analysisctfeducation+4
131 year ago
CVE-2026-0776 preview

CVE-2026-0776

GitHubwhenx/cve-2026-0776

Security research and proof-of-concept for CVE-2026-0776 affecting Discord Desktop Client.

code-analysiseducationexploitation+2
92 months ago
ore-mal-pkg-inspector preview

ore-mal-pkg-inspector

GitHubrapticore/ore-mal-pkg-inspector

Multi-Ecosystem Malicious Package Detection and Supply Chain Security Scanner

code-analysisdevsecopseducation+6
84 months ago
lightweight_static_analysis preview

lightweight_static_analysis

GitHubnccgroup/lightweight_static_analysis

Create useful, lightweight static analyses using open source tools + a tiny bit of your code

code-analysiseducationpenetration-testing+4
136 years ago
vulnrepro-benchmark preview

vulnrepro-benchmark

GitHubfarhadalimohammadi-dir/vulnrepro-benchmark

Benchmark measuring AI models' ability to detect vulnerabilities in source code via real bug bounty cases with balanced recall and false-positive…

ai-securitycode-analysisctf+7
93 months ago
react2shell preview

react2shell

GitHubzr0n/react2shell

A complete framework for exploiting the vulnerability CVE-2025-55182

code-analysiseducationexploitation+5
129 months ago
cve-2022-22947-spring-cloud-gateway preview

cve-2022-22947-spring-cloud-gateway

GitHubenokiy/cve-2022-22947-spring-cloud-gateway

Detailed analysis and exploit for CVE-2022-22947, a remote code execution vulnerability in Spring Cloud Gateway via SpEL injection in the Actuator…

code-analysiseducationexploitation+4
184 years ago
React2Shell-CVE-2025-55182 preview

React2Shell-CVE-2025-55182

GitHubadityabhatt3010/react2shell-cve-2025-55182

React2Shell CVE-2025-55182: unauthenticated unsafe deserialization in React Server Components leading to reliable remote code execution via the…

code-analysisctfeducation+6
82 months ago
CVE-2018-11235-DEMO preview

CVE-2018-11235-DEMO

GitHubchybeta/cve-2018-11235-demo

Demonstrates exploitation of CVE-2018-11235, a Git submodule RCE vulnerability, with build script and analysis for educational purposes.

code-analysiseducationexploitation+2
148 years ago
Gitlab-RCE preview

Gitlab-RCE

GitHubpetrusviet/gitlab-rce

CVE-2021-22192

code-analysiseducationexploitation+3
125 years ago
VulTriage preview

VulTriage

GitHubvinsontang1/vultriage

The code of VulTriage: Triple-Path Context Augmentation for LLM-Based Vulnerability Detection

ai-securitycode-analysiseducation+4
104 months ago
codeql-workshop-cve-2021-21380 preview

codeql-workshop-cve-2021-21380

GitHubrvermeulen/codeql-workshop-cve-2021-21380

A CodeQL workshop covering CVE-2021-21380

code-analysiseducationlabs-practice+3
121 year ago
CVE-2022-22947 preview

CVE-2022-22947

GitHub4nnns/cve-2022-22947

Spring-Cloud-Spel-RCE

code-analysiseducationexploitation+3
124 years ago
CVE-2026-12191 preview

CVE-2026-12191

GitHubhakaioffsec/cve-2026-12191

PoC for CVE-2026-12191

binary-exploitationcode-analysiseducation+3
52 months ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubverylazytech/cve-2025-3248

Proof-of-concept exploit for CVE-2025-3248, a remote code injection vulnerability in Langflow prior to 1.3.0. Sends crafted HTTP requests to execute…

code-analysiseducationexploitation+3
101 year ago
CVE-2026-33439 preview

CVE-2026-33439

GitHubthemalwareguardian/cve-2026-33439

First publicly shared exploit implementation for CVE-2026-33439 (OpenAM pre-auth RCE via jato.clientSession deserialization).

binary-exploitationcode-analysiseducation+8
105 months ago
CVE-2020-36188 preview

CVE-2020-36188

GitHubal1ex/cve-2020-36188

CVE-2020-36188 &&Jackson-databind RCE

code-analysiseducationexploitation+3
115 years ago
Previous1…678…31Next