Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
145 results
CVE-2021-3129 preview

CVE-2021-3129

GitHubhupe1980/cve-2021-3129

Laravel debug mode - Remote Code Execution (RCE)

code-analysisdynamic-code-analysisexploitation+3
3 years ago
external_expat_AOSP10_r33_CVE-2022-25236 preview

external_expat_AOSP10_r33_CVE-2022-25236

GitHubsatheesh575555/external_expat_aosp10_r33_cve-2022-25236

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

code-analysisexploitationfuzzing+3
4 years ago
CVE-2024-6387 preview

CVE-2024-6387

GitHubjack0we/cve-2024-6387

Proof-of-concept exploit for CVE-2024-6387, a remote code execution vulnerability in OpenSSH server, demonstrating exploitation techniques for…

code-analysisexploitationfuzzing+2
2 years ago
CVE-2019-19203 preview

CVE-2019-19203

GitHubtarantula-team/cve-2019-19203

An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced…

binary-analysiscode-analysisexploitation+3
6 years ago
external_expat-2.1.0_CVE-2022-25313 preview

external_expat-2.1.0_CVE-2022-25313

GitHubtrinadh465/external_expat-2.1.0_cve-2022-25313

Repository dedicated to CVE-2022-25313, a vulnerability in Expat 2.1.0, providing analysis and potential exploitation code.

binary-analysiscode-analysisexploitation+3
3 years ago
CVE-2024-22640 preview

CVE-2024-22640

GitHubzunak/cve-2024-22640

Proof-of-concept exploit for CVE-2024-22640, a ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted HTML color input, with demonstration code.

code-analysisexploitationfuzzing+3
2 years ago
CVE-2019-19204 preview

CVE-2019-19204

GitHubtarantula-team/cve-2019-19204

Heap-buffer-overflow in Oniguruma (function fetch_interval_quantifier)

binary-analysiscode-analysisexploitation+3
6 years ago
platform_external_libvpx_v1.4.0_CVE-2023-5217 preview

platform_external_libvpx_v1.4.0_CVE-2023-5217

GitHubtrinadh465/platform_external_libvpx_v1.4.0_cve-2023-5217

C library for VP8/VP9 video encoding and decoding, with a focus on security patching for CVE-2023-5217.

binary-analysiscode-analysisexploitation+3
2 years ago
external_expact_AOSP10_r33_CVE-2022-25314 preview

external_expact_AOSP10_r33_CVE-2022-25314

GitHubshaikusaf/external_expact_aosp10_r33_cve-2022-25314

C library for parsing XML, providing stream-oriented parsing with handler registration, supporting UTF-16 encoding, and including a reference manual.

binary-analysiscode-analysisexploitation+3
4 years ago
platform_external_libvpx_v1.8.0_CVE-2023-5217 preview

platform_external_libvpx_v1.8.0_CVE-2023-5217

GitHubtrinadh465/platform_external_libvpx_v1.8.0_cve-2023-5217

Patched libvpx codebase addressing CVE-2023-5217 with sanitizer support and cross-platform build configurations for secure VP8/VP9 encoding.

binary-analysiscode-analysisdynamic-analysis-sandboxing+3
2 years ago
bouncy-castle-generative-test-poc preview

bouncy-castle-generative-test-poc

GitHubmadstap/bouncy-castle-generative-test-poc

A generative test that would've caught CVE-2020-28052

code-analysiscryptographyeducation+2
5 years ago
hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final preview

hibernate__hibernate-validator_CVE-2019-10219_6-0-17-Final

GitHubshoucheng3/hibernate__hibernate-validator_cve-2019-10219_6-0-17-final

Reference implementation of Bean Validation 2.0 (JSR-380) providing annotation-driven metadata model and API for JavaBean and method validation with…

api-securitycode-analysismisconfiguration+2
1 year ago
external_expact_AOSP10_r33_CVE-2022-25315 preview

external_expact_AOSP10_r33_CVE-2022-25315

GitHubshaikusaf/external_expact_aosp10_r33_cve-2022-25315

C library for parsing XML, patched for CVE-2022-25315, providing stream-oriented XML parsing with handlers for efficient document processing.

binary-analysiscode-analysisexploitation+3
4 years ago
scan preview

scan

GitHubatomdrift-project/scan

0-day malware detection for binaries, source & scripts (that doesn't suck)

binary-analysiscode-analysisdefensive-tools+9
513 days ago
rdx preview

rdx

GitHubch0pin/rdx

A native APK and DEX decompiler written in Rust

android-securitybinary-analysiscode-analysis+6
264 days ago
seclab-taskflows-fuzzing preview

seclab-taskflows-fuzzing

GitHubgithubsecuritylab/seclab-taskflows-fuzzing

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

ai-securitycode-analysisdynamic-analysis-sandboxing+7
16 days ago
reverse-engineering-browser preview

reverse-engineering-browser

GitHubsunghoojung/reverse-engineering-browser

Local-first macOS research browser built on a custom Brave build that captures network traffic, fingerprints, scripts, and runtime evidence for…

code-analysisdebuggersdynamic-analysis-sandboxing+9
52 days ago
vmp2 preview
Archived

vmp2

GitHubaftermathlabs/vmp2

Unpack and deobfuscate VMProtect 2 protected binaries with an emulation-based VM explorer, handler profiler, and experimental LLVM recompiler for…

binary-analysiscode-analysisdynamic-code-analysis+3
13110 months ago
Previous1…789Next