Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
25 results
CVE-2026-39987 preview

CVE-2026-39987

GitHubalreadyclosed/cve-2026-39987

CVE-2026-39987 for marimo 0.20.4 PoC

ctfeducationexploitation+2
1 month ago
NGINX_2026_CVE_Bundle_CTI_Report preview

NGINX_2026_CVE_Bundle_CTI_Report

GitHubchpratik/nginx_2026_cve_bundle_cti_report

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

cloud-securitycurated-resourceseducation+6
1 month ago
camel-pqc-tls preview

camel-pqc-tls

GitHuboscerd/camel-pqc-tls

Post-Quantum Cryptography (PQC) TLS 1.3 examples with Apache Camel using X25519MLKEM768 hybrid key exchange on JDK 21 (BouncyCastle) and JDK 27…

cryptographycurated-resourceseducation+1
24 months ago
Loki preview

Loki

GitHubbitwise-01/loki

Remote Access Tool

command-and-controlcryptographyeducation+4
6274 years ago
poodle-PoC preview

poodle-PoC

GitHubmpgn/poodle-poc

:poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle:

cryptographyeducationencryption-decryption-tools+4
2673 years ago
CVE-2020-28502 preview

CVE-2020-28502

GitHubs-index/cve-2020-28502

CVE-2020-28502 node-XMLHttpRequest RCE

educationexploitationpayload-development+3
35 years ago
Testability-CVE-2014-1266 preview

Testability-CVE-2014-1266

GitHublandonf/testability-cve-2014-1266

Demonstrating that SSLVerifySignedServerKeyExchange() is trivially testable.

code-analysiscryptographyeducation+1
2612 years ago
List-CVE-2025-2026 preview

List-CVE-2025-2026

GitHubmagercode/list-cve-2025-2026

Daftar CVE 2025-2026 terupdate

curated-resourceseducationinformation-gathering+3
18 months ago
CVE-2024-24919-POC preview

CVE-2024-24919-POC

GitHubseed1337/cve-2024-24919-poc

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated arbitrary file read vulnerability in Check Point SSL VPN appliances. Includes Nuclei…

educationexploitationpenetration-testing+2
472 years ago
CVE-2024-10924-Bypass-MFA-Wordpress-LAB preview

CVE-2024-10924-Bypass-MFA-Wordpress-LAB

GitHubd1se0/cve-2024-10924-bypass-mfa-wordpress-lab

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

authenticationctfeducation+5
41 year ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubsariamubeen/cve-2024-10924

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

authentication-authorizationeducationexploitation+3
1 year ago
CVE-2023-27997-POC preview

CVE-2023-27997-POC

GitHubnode011/cve-2023-27997-poc

Fortigate SSL VPN buffer overflow exploit

educationexploitationpenetration-testing+2
1 year ago
CVE-2014-3566-poodle-cookbook preview

CVE-2014-3566-poodle-cookbook

GitHubmikesplain/cve-2014-3566-poodle-cookbook

Chef cookbook that detects and fails runs on servers vulnerable to CVE-2014-3566 (POODLE) by scanning specified SSL ports, serving as both a security…

configuration-auditingdevsecopseducation+2
311 years ago
renef-skills preview

renef-skills

GitHubvichhka-git/renef-skills

Agent Skill for operating renef.io — Android ARM64 dynamic instrumentation: hook native/Java, patch memory, trace syscalls, bypass SSL pinning/root…

android-securitybinary-analysisctf+9
153 months ago
wordpress-cve-2024-10924-exploit preview

wordpress-cve-2024-10924-exploit

GitHubh8su/wordpress-cve-2024-10924-exploit

A Proof-of-Concept (PoC) exploit for CVE-2024-10924, a vulnerability in the Really Simple SSL WordPress plugin that allows bypassing two-factor…

authentication-authorizationeducationexploitation+4
21 year ago
cve-2020-0601_poc preview

cve-2020-0601_poc

GitHubgremwell/cve-2020-0601_poc

Proof-of-concept exploit for CVE-2020-0601 (Windows CryptoAPI spoofing) that generates rogue CA certificates to intercept HTTPS traffic, with…

cryptographyeducationexploitation+2
26 years ago
CVE-2024-40898 preview

CVE-2024-40898

GitHubanilpatel199n/cve-2024-40898

This Python script checks for the presence of CVE-2024-40898, a critical vulnerability in Apache HTTP Server that may allow SSL/TLS certificate…

educationexploitationpenetration-testing+2
11 year ago
wordpress-cve-2024-10924-pentest preview

wordpress-cve-2024-10924-pentest

GitHubademto/wordpress-cve-2024-10924-pentest

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

authenticationeducationexploitation+5
31 year ago
Previous12Next