Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
177 results
magika preview

magika

GitHubgoogle/magika

Fast and accurate AI powered file content types detection

code-analysisforensicsgeneral-purpose-utilities+3
18.7k1 day ago
entropy preview

entropy

GitHubewenquim/entropy

CLI tool that scans codebases for high-entropy lines to detect potential secrets, with customizable file extension and top-N filtering.

code-analysissecret-detectionstatic-analysis
7354 months ago
kin preview

kin

GitHubfirelock-ai/kin

Semantic graph-based version control for AI-written code. Tracks entities and relations instead of file diffs, enabling blast radius analysis, shadow…

ai-securitycode-analysiscurated-resources+4
654 days ago
CVE-2022-25845-In-Spring preview

CVE-2022-25845-In-Spring

GitHubluelueking/cve-2022-25845-in-spring

CVE-2022-25845 (fastjson 1.2.80) exploit for Spring environments with step-by-step PoC, file read, and arbitrary file write via Jackson/commons-io…

code-analysisexploitationpayload-development+3
1091 year ago
AbxOverflow preview

AbxOverflow

GitHubmichalbednarski/abxoverflow

Writeup and exploit for CVE-2024-34740, integer overflow in Android's BinaryXmlSerializer to system_server file write and then to system_server code…

android-securitybinary-exploitationcode-analysis+5
7911 months ago
jadx-magic-strings preview

jadx-magic-strings

GitHub0rshemesh/jadx-magic-strings

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

android-securitybinary-analysiscode-analysis+5
4524 days ago
codetotal preview

codetotal

GitHuboxsecurity/codetotal

Analyze any snippet, file, or repository to detect possible security flaws such as secret in code, open source vulnerability, code security,…

code-analysissecret-detectionsupply-chain-security+1
793 years ago
CVE-2019-19634 preview

CVE-2019-19634

GitHubjra89/cve-2019-19634

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.4

code-analysisexploitationpayload-generation+3
366 years ago
CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit preview

CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit

GitHubm4sh-wacker/cve-2026-3891-pix-for-woocommerce-plugin-exploit

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

code-analysisexploitationpenetration-testing+2
212 months ago
CVE-2022-45451 preview

CVE-2022-45451

GitHubalfarom256/cve-2022-45451

PoC for Acronis Arbitrary File Read - CVE-2022-45451

binary-analysiscode-analysisexploitation+2
183 years ago
CVE-2020-26259 preview

CVE-2020-26259

GitHubjas502n/cve-2020-26259

CVE-2020-26259: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has…

code-analysisexploitationpenetration-testing+2
255 years ago
CVE-2026-48908-PoC preview

CVE-2026-48908-PoC

GitHubpapageo75/cve-2026-48908-poc

Unauthenticated RCE PoC for CVE-2026-48908 — SP Page Builder for Joomla (≤ 6.6.1): arbitrary file upload via asset.uploadCustomIcon. Self-cleaning,…

code-analysiseducationexploitation+5
183 months ago
CVE-2019-10869 preview

CVE-2019-10869

GitHubktn1990/cve-2019-10869

(Wordpress) Ninja Forms File Uploads Extension <= 3.0.22 – Unauthenticated Arbitrary File Upload

code-analysisexploitationpayload-generation+3
177 years ago
CVE-2019-19576 preview

CVE-2019-19576

GitHubjra89/cve-2019-19576

This is a filter bypass exploit that results in arbitrary file upload and remote code execution in class.upload.php <= 2.0.3

code-analysisexploitationpayload-generation+3
126 years ago
CVE-2023-46818 preview

CVE-2023-46818

GitHubhunntr/cve-2023-46818

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

code-analysisexploitationpenetration-testing+2
161 year ago
CVE-2024-37032-PoC preview

CVE-2024-37032-PoC

GitHubitzsh4dowxz/cve-2024-37032-poc

CVE-2024-37032 (Probllama) PoC for Ollama ≤0.1.33: path traversal and arbitrary file write via model digest handling, leading to automated privilege…

code-analysisexploitationpayload-development+5
83 months ago
CVE-2020-28948-and-CVE-2020-28949 preview

CVE-2020-28948-and-CVE-2020-28949

GitHub0x240x23elu/cve-2020-28948-and-cve-2020-28949

Proof-of-concept demonstration for CVE-2020-28948 and CVE-2020-28949, PHP Archive_Tar path traversal and arbitrary file write vulnerabilities.

code-analysiseducationexploitation+2
65 years ago
CVE-2026-77262 preview

CVE-2026-77262

GitHubromain-deperne/cve-2026-77262

Proof-of-concept exploit for arbitrary file read in mcp-atlassian via path traversal in confluence_upload_attachment, with analysis and reproduction…

code-analysisexploitationpenetration-testing+2
25 days ago
Previous12…10Next