Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

data-exfiltrationemail-securityexploitation+6
16 days ago
CVE-2026-64640 preview

CVE-2026-64640

GitHuboscerd/cve-2026-64640

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

api-securitycloud-securitydata-exfiltration+5
23 days ago
impacket preview

impacket

GitHubfortra/impacket

Python library for low-level network protocol manipulation, featuring SMB, MSRPC, Kerberos, and WMI implementations with tools for authentication…

authenticationcommand-and-controldatabase-security+17
16.1k1 day ago
informer preview

informer

GitHubpaulpierre/informer

A Telegram Mass Surveillance Bot in Python

crawlerdata-exfiltrationimpersonation-tools+3
1.7k10 months ago
Solitude preview

Solitude

GitHubnccgroup/solitude

Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more advanced…

data-exfiltrationinformation-gatheringmobile-security+4
3765 years ago
Log4jCenter preview

Log4jCenter

GitHubpuzzlepeaches/log4jcenter

Exploiting CVE-2021-44228 in vCenter for remote code execution and more.

command-and-controldata-exfiltrationexploitation+3
1034 years ago
CVE-2025-24104 preview

CVE-2025-24104

GitHubifpdz/cve-2025-24104

Technical writeup of CVE-2025-24104: an iOS sandbox escape via symlink validation bypass in backup restoration, enabling arbitrary file reads outside…

binary-exploitationdata-exfiltrationexploitation+4
521 year ago
web-inf-path-trav preview

web-inf-path-trav

GitHubinvicti-security/web-inf-path-trav

Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications

data-exfiltrationexploitationpenetration-testing+3
333 years ago
flowise-arbitrary-file-read-getFileFromStorage preview

flowise-arbitrary-file-read-getFileFromStorage

GitHubmajpuv/flowise-arbitrary-file-read-getfilefromstorage

Unauthenticated arbitrary file read in Flowise (< 2.2.4) via path traversal in getFileFromStorage (storageUtils.ts). Caused by un-sanitized file path…

data-exfiltrationexploitationinformation-gathering+4
27 days ago
React2Shell preview

React2Shell

GitHub4nuxd/react2shell

R2S is a comprehensive exploitation and post-exploitation framework targeting the Next.js React Server Components vulnerability (CVE-2025-55182). It…

command-and-controlcontainer-escapedata-exfiltration+7
8 months ago
twitter-intelligence preview

twitter-intelligence

GitHubbatuhaniskr/twitter-intelligence

Twitter Intelligence OSINT project performs tracking and analysis of the Twitter

crawlerdata-exfiltrationinformation-gathering+2
2405 years ago
FARO preview

FARO

GitHubgradiant/faro

FARO - Document Sensitivity Detector

configuration-auditingdata-exfiltrationeducation+5
103 years ago
android-workprofile-exploit preview

android-workprofile-exploit

GitHubhasan-al-hussein/android-workprofile-exploit

Controlled defensive analysis of CVE-2025-22442 work-profile provisioning, policy timing, and enterprise isolation.

android-securitydata-exfiltrationeducation+5
11 month ago
CVE-2026-36851 preview

CVE-2026-36851

GitHubsyntaxsaiyan/cve-2026-36851

Walkthrough and PoC of File path traversal vulnerability(CVE-2026-36851) for UnPoller 2.33.0

data-exfiltrationeducationexploitation+3
1 month ago
C2-and-Post-Exploitation-Framework preview

C2-and-Post-Exploitation-Framework

GitHubjacobtaylor3/c2-and-post-exploitation-framework

CVE-2021-21220 Exploitation infrastructure

command-and-controldata-exfiltrationeducation+8
3 months ago
CVE-2023-7231 preview

CVE-2023-7231

GitHubbbo513/cve-2023-7231

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

cloud-securitycontainer-securitydata-exfiltration+6
11 year ago
CVE-2025-55130 preview

CVE-2025-55130

GitHubscumfrog/cve-2025-55130

POC for CVE-2025-55130

container-escapedata-exfiltrationexploitation+3
16 months ago
CVE-2026-21002-Serverless-Cold-Start-Credential-Leakage-via-Reused-tmp preview

CVE-2026-21002-Serverless-Cold-Start-Credential-Leakage-via-Reused-tmp

GitHubgeorge0papasotiriou/cve-2026-21002-serverless-cold-start-credential-leakage-via-reused-tmp

PoC exploit for CVE-2026-21002 serverless cold-start credential leakage, demonstrating how reused Lambda /tmp directories expose AWS secrets to other…

cloud-infrastructure-securitycloud-securitydata-exfiltration+4
26 days ago
Previous123Next