Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
595 results
cve-images preview

cve-images

GitHubedgecases-purplehax/cve-images

Intentionally-vulnerable nginx 1.30.0 CVE lab images (CVE-2026-40701/42934/42945/42946) for isolated security research. Lab use only.

container-securityctfcurated-resources+5
1
2 months ago
rust-cve-2025-55182-scanner preview

rust-cve-2025-55182-scanner

GitHubkaxm23/rust-cve-2025-55182-scanner

powerfull rust cve-2025-55182-scanner used for ctf & ethical purpose only

ctfexploitationpenetration-testing+3
4 months ago
CVE-2025-66034 preview

CVE-2025-66034

GitHub4nuxd/cve-2025-66034

CVE-2025-66034 - fontTools varLib Arbitrary File Write → RCE PoC exploit for an Arbitrary File Write + XML Injection vulnerability in…

ctfexploitationpayload-development+3
4 months ago
jwt-key-confusion-poc preview

jwt-key-confusion-poc

GitHubaalex954/jwt-key-confusion-poc

JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction

ctfexploitationpayload-generation+3
24 years ago
iCSeeU preview

iCSeeU

GitHublr-m/icseeu

This is a suite of tools/PoCs/exploits for cameras using the iCSee application. And yes - it can run NES games!

binary-exploitationctfdebuggers+9
21 year ago
php_filter_chain_oracle_poc preview

php_filter_chain_oracle_poc

GitHub4xura/php_filter_chain_oracle_poc

PoC scripts to exploit LFR (Local File Read) via PHP filters chain oracle (php://filter), especially for CTF purposes or the exploit of…

ctfexploitationinformation-gathering+3
21 year ago
CVE-2024-51482-ZoneMinder-CCTV-HTB-Reliable-EXP preview

CVE-2024-51482-ZoneMinder-CCTV-HTB-Reliable-EXP

GitHuberhui-li/cve-2024-51482-zoneminder-cctv-htb-reliable-exp

Performing multiple time-based blind injections for the same character and selecting the most frequent result significantly reduces errors and…

ctfexploitationpenetration-testing+2
5 months ago
ivre-wizard preview

ivre-wizard

GitHubbitburner/ivre-wizard

An interactive wizard front end for IVRE to make creating scans to the database easier.

ctfinformation-gatheringlabs-practice+3
22 years ago
cve-2026-54316-lab preview

cve-2026-54316-lab

GitHubinertfluid/cve-2026-54316-lab

Reproduction lab for CVE-2026-54316 (Claude Code WebFetch huggingface.co bare-hostname permission bypass / exfiltration)

ctfdata-exfiltrationeducation+5
2 months ago
CVE-2012-6422 preview

CVE-2012-6422

GitHubwired0ut/cve-2012-6422

An exploitation for the /dev/exynos-mem vulnerability introduced in earlier samsung phones.

binary-exploitationctfexploitation+2
111 months ago
CVE-2023-46818 preview

CVE-2023-46818

GitHubvulnerk0/cve-2023-46818

Python PoC for CVE-2023-46818

ctfexploitationpenetration-testing+2
1 year ago
RootQuest-CTF-Box-Multi-Stage-Exploitation-VM preview

RootQuest-CTF-Box-Multi-Stage-Exploitation-VM

GitHubthieveshkar/rootquest-ctf-box-multi-stage-exploitation-vm

Custom vulnerable VM (Ubuntu 14.04) designed for teaching multi-stage penetration testing. Features 10 interconnected challenges across Forensics,…

binary-exploitationcryptographyctf+7
10 months ago
php-8.1.0-dev-exploit preview

php-8.1.0-dev-exploit

GitHubuseru1k/php-8.1.0-dev-exploit

Exploit for the PHP 8.1.0-dev backdoor vulnerability (CVE-2021-21707)

ctfexploitationpayload-generation+3
10 months ago
cmsms-sqli preview

cmsms-sqli

GitHubtim-karov/cmsms-sqli

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

ctfexploitationpassword-cracking+3
7 months ago
React2Shell-CVE-Lab preview

React2Shell-CVE-Lab

GitHubxxxtectationxxx/react2shell-cve-lab

A self-hosted vulnerable Next.js environment running on Docker for simulating CVE-2025-55182. Built for educational security research and CTF…

container-securityctfeducation+6
18 months ago
pwnkit-helper preview

pwnkit-helper

GitHubdr4xp/pwnkit-helper

For CTF's and Safe Environments.... CVE-2021-4034 Local PrivEsc.

ctfexploitationpenetration-testing+2
111 months ago
dual-ec-drbg preview

dual-ec-drbg

GitHubeddieoz/dual-ec-drbg

Educational Proof-of-Concept for the Dual_EC_DRBG backdoor (CVE-2014-8610) - NIST P-256 state recovery attack demonstration

cryptographyctfeducation+3
6 months ago
webvm preview

webvm

GitHubaxlan/webvm

Virtual Machine for the Web

cloud-securityctfeducation+3
7 months ago
Previous1…567…34Next