Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
cve-2025-39682 preview

cve-2025-39682

GitHubkhoatran107/cve-2025-39682

Linux kernel TLS zero-length record handling exploit for CVE-2025-39682, targeting kernelCTF mitigation instances with a 79% success rate.

binary-exploitationctfeducation+2
6
11 months ago
CVE-2026-63030-wp2r00t preview

CVE-2026-63030-wp2r00t

GitHubj4ck3lsyn-gen2/cve-2026-63030-wp2r00t

A fully red-team(offensive security) weaponized variant of wp2shell, built for authorized penetration testing & educational purposes.

ctfeducationexploitation+5
62 months ago
wordpress-batch-rce-lab preview

wordpress-batch-rce-lab

GitHubzenithgenius/wordpress-batch-rce-lab

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.

code-analysisctfeducation+6
12 months ago
TryHackMe-Blue-MS17-010 preview

TryHackMe-Blue-MS17-010

GitHubporcumarcooo/tryhackme-blue-ms17-010

Walkthrough, threat analysis, and remediation guide for CVE-2017-0144 (EternalBlue).

ctfdefensive-toolseducation+4
25 days ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubtoddkk02/cve-2025-29927

Proof-of-concept exploit for CVE-2025-29927, demonstrating authentication bypass in Next.js middleware via the x-middleware-subrequest header, with…

authentication-authorizationctfids-ips-evasion+3
6 months ago
EternalBlue-Exploit-Demonstration preview

EternalBlue-Exploit-Demonstration

GitHubdannic145/eternalblue-exploit-demonstration

Educational lab demonstrating EternalBlue (MS17-010) exploitation against Windows 7 using Metasploit, including post-exploitation, WannaCry…

ctfeducationexploitation+8
5 months ago
CVE-2026-4480-PoC preview

CVE-2026-4480-PoC

GitHubthecybergeek/cve-2026-4480-poc

Proof-of-concept exploit for CVE-2026-4480, an unauthenticated remote command execution in Samba's print subsystem via %J injection. Includes reverse…

ctfeducationexploitation+3
234 months ago
CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read preview

CVE-2025-2539---File-Away-WordPress-Plugin-Arbitrary-File-Read

GitHubfazaroot/cve-2025-2539---file-away-wordpress-plugin-arbitrary-file-read

Authenticated arbitrary file read exploit for the File Away WordPress plugin (CVE-2025-2539). Includes PoC, attack flow, detection signatures, and…

ctfeducationexploitation+6
9 months ago
CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough preview

CVE-2024-24945-NGINX-RIFT---TryHackMe-Lab-Walkthrough

GitHubbenedictejepu/cve-2024-24945-nginx-rift---tryhackme-lab-walkthrough

This lab demonstrates the exploitation of CVE-2024-24945, a heap corruption vulnerability affecting NGINX. The objective was to understand how memory…

binary-exploitationctfeducation+5
3 months ago
CVE-2026-8838-RCE preview

CVE-2026-8838-RCE

GitHubmaxime288/cve-2026-8838-rce

Educational PoC for CVE-2026-8838, a critical RCE vulnerability in Amazon Redshift Python Driver via unsafe eval() in vector_in(). Includes technical…

binary-exploitationctfeducation+3
4 months ago
CVE-2024-21520-Demo preview

CVE-2024-21520-Demo

GitHubch4n3-yoon/cve-2024-21520-demo

Educational repository demonstrating XSS vulnerabilities in Django Rest Framework applications. Contains intentionally vulnerable code to teach…

code-analysisctfeducation+3
2 years ago
mitigation-cve-2019-9787 preview

mitigation-cve-2019-9787

GitHubkuangting4231/mitigation-cve-2019-9787

PoC and mitigation for CVE-2019-9787 (WordPress XSS/CSRF/RCE). Demonstrates sanitization fixes, HttpOnly cookies, and hash-based CSRF defense with…

ctfeducationexploitation+3
4 years ago