Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
JAW preview

JAW

GitHubsoheilkhodayari/jaw

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

code-analysiscrawlerdatabase-security+5
1197 months ago
libinjection preview

libinjection

GitHubclient9/libinjection

SQL / SQLI tokenizer parser analyzer

code-analysisstatic-analysisvulnerability-analysis+1
1.0k8 years ago
CVE-2026-66730-Infinite-Loop-DoS-in-facil.io-MIME-Parser preview

CVE-2026-66730-Infinite-Loop-DoS-in-facil.io-MIME-Parser

GitHubtheopaid/cve-2026-66730-infinite-loop-dos-in-facil.io-mime-parser

Security Advisory: Infinite Loop DoS in facil.io MIME Parser (Partial Boundary)

code-analysiseducationpapers-research+2
2 months ago
CVE-2026-66731-Negative-Chunk-Size-Parsing-Causes-Memory-Corruption-leading-to-Server-Crash preview

CVE-2026-66731-Negative-Chunk-Size-Parsing-Causes-Memory-Corruption-leading-to-Server-Crash

GitHubtheopaid/cve-2026-66731-negative-chunk-size-parsing-causes-memory-corruption-leading-to-server-crash

Security advisory for CVE-2026-66731 with root cause analysis, PoC exploit, and fix suggestions for facil.io HTTP/1.1 chunked encoding parser bug.

code-analysisstatic-analysisvulnerability-analysis+1
2 months ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubtrganda/cve-2021-22204

In-depth technical analysis of CVE-2021-22204 (ExifTool RCE) with PoC reproduction, payload construction, and Perl code review of the vulnerable DjVu…

binary-exploitationcode-analysiseducation+3
34 years ago
CVE-2026-29628 preview

CVE-2026-29628

GitHubkiyochii/cve-2026-29628

Proof-of-concept for CVE-2026-29628, a stack-based buffer overflow in tinyobjloader's experimental parser, with ASan/UBSan reproduction and fix…

binary-analysiscode-analysisexploitation+2
5 months ago
CVE-2025-66628 preview

CVE-2025-66628

GitHubsumitshah00/cve-2025-66628

Technical analysis of CVE-2025-66628, an integer overflow in ImageMagick's TIM parser leading to out-of-bounds reads, with root cause, exploitation…

binary-analysiscode-analysiseducation+4
110 months ago
external_expat-2.1.0_CVE-2022-43680 preview

external_expat-2.1.0_CVE-2022-43680

GitHubtrinadh465/external_expat-2.1.0_cve-2022-43680

Source code repository for Expat 2.1.0, a stream-oriented XML parser library, with focus on analyzing and addressing CVE-2022-43680.

binary-analysiscode-analysisexploitation+3
3 years ago
external_expat_AOSP10_r33_CVE-2022-22822toCVE-2022-22827 preview

external_expat_AOSP10_r33_CVE-2022-22822toCVE-2022-22827

GitHubnanopathi/external_expat_aosp10_r33_cve-2022-22822tocve-2022-22827

Patched version of the Expat XML parser library addressing multiple CVEs (CVE-2022-22822 through CVE-2022-22827) for AOSP 10 r33, providing…

code-analysisgeneral-purpose-utilitiesstatic-analysis+2
3 years ago
external_expat_AOSP10_r33_CVE-2022-25236 preview

external_expat_AOSP10_r33_CVE-2022-25236

GitHubsatheesh575555/external_expat_aosp10_r33_cve-2022-25236

Patched version of Expat XML parser for AOSP10, addressing CVE-2022-25236. Provides source code for vulnerability analysis and educational review of…

code-analysisexploitationfuzzing+3
4 years ago
VLC_CVE-2021-25804_Analysis preview

VLC_CVE-2021-25804_Analysis

GitHubdshankle/vlc_cve-2021-25804_analysis

In-depth technical analysis of CVE-2021-25804, a VLC AVI parser vulnerability. Includes root cause, patch diff, and exploitation primitives for…

binary-analysiscode-analysiseducation+3
4 years ago
VUL4J-59 preview

VUL4J-59

GitHubepicosy/vul4j-59

Reproducible CVE-2015-6748 vulnerability example in jsoup HTML parser, demonstrating XSS prevention bypass and DOM-based parsing flaws for security…

code-analysiseducationstatic-analysis+2
2 years ago
external_lib_AOSP10_r33_CVE-2021-45960_CVE-2021-46143- preview

external_lib_AOSP10_r33_CVE-2021-45960_CVE-2021-46143-

GitHubtrinadh465/external_lib_aosp10_r33_cve-2021-45960_cve-2021-46143-

C library for stream-oriented XML parsing, providing a fast and configurable parser with support for custom handlers and encoding options.

code-analysisgeneral-purpose-utilitiesstatic-analysis+1
4 years ago
sanitize preview

sanitize

GitHubrgrove/sanitize

Ruby HTML and CSS sanitizer.

code-analysisdefensive-toolsweb-security
2.1k1 month ago
owasp-java-encoder preview

owasp-java-encoder

GitHubowasp/owasp-java-encoder

The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will…

code-analysisdefensive-toolsencryption-decryption-tools+3
5463 days ago
yaraast preview

yaraast

GitHubseifreed/yaraast

A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation

code-analysismalware-analysisscripting-automation+3
541 month ago
sigmalite preview

sigmalite

GitHubrunreveal/sigmalite

Go library for parsing and executing Sigma detection rules against log entries, supporting field modifiers, CIDR matching, and custom field resolvers…

code-analysisintrusion-detectionlog-analysis+2
591 year ago
ngxray preview

ngxray

GitHubcalifio/ngxray

ngxray — nginx config security scanner

code-analysisconfiguration-auditingmisconfiguration+3
254 months ago
Previous12Next