Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
CVE-2026-50787 preview

CVE-2026-50787

GitHubbrynax/cve-2026-50787

Security advisory detailing CVE-2026-50787, an uncontrolled resource consumption vulnerability in e-SIC Livre CAPTCHA generation, enabling remote…

curated-resourceseducationvulnerability-analysis+1
3 days ago
CVE-2025-56381 preview

CVE-2025-56381

GitHubmoalali/cve-2025-56381

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the…

educationexploitationpenetration-testing+2
111 months ago
polytracker preview

polytracker

GitHubtrailofbits/polytracker

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

binary-analysisdynamic-code-analysiseducation+4
5982 months ago
Hashcat-Cheatsheet preview

Hashcat-Cheatsheet

GitHubfrizb/hashcat-cheatsheet

Hashcat reference for OSCP/penetration testing: hash identification, cracking syntax for Linux, Windows, archives, databases, Kerberos tickets, and…

curated-resourceseducationhash-analysis+3
6316 years ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
gosentry preview

gosentry

GitHubtrailofbits/gosentry

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

binary-analysiscode-analysisdevsecops+5
1183 days ago
p3-loader preview

p3-loader

GitHuborange-cyberdefense/p3-loader

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

binary-exploitationdefensive-toolseducation+8
2121 month ago
CVE-2026-63766_exploit preview

CVE-2026-63766_exploit

GitHub0xdak/cve-2026-63766_exploit

Unauthenticated OS command injection exploit for GPT-SoVITS Gradio web UI. Delivers RCE via unsanitized path parameters in audio-processing helpers,…

command-and-controleducationexploitation+3
1 month ago
CVE-2023-34537---XSS-reflected--found-in-HotelDruid-3.0.5 preview

CVE-2023-34537---XSS-reflected--found-in-HotelDruid-3.0.5

GitHubleekenghwa/cve-2023-34537---xss-reflected--found-in-hoteldruid-3.0.5

Proof-of-concept demonstrating reflected XSS vulnerabilities in HotelDruid v3.0.5, with step-by-step exploitation guide for authenticated users…

educationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2024-55187 preview

CVE-2024-55187

GitHubmallo-m/cve-2024-55187

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

code-analysiseducationexploitation+3
8 months ago
CVE-2025-53652-Jenkins-Git-Parameter-Analysis preview

CVE-2025-53652-Jenkins-Git-Parameter-Analysis

GitHubpl4tyz/cve-2025-53652-jenkins-git-parameter-analysis

CVE-2025-53652: Jenkins Git Parameter Analysis

code-analysiscommand-and-controldevsecops+3
21 year ago
damn-vulnerable-log4j-app preview

damn-vulnerable-log4j-app

GitHubsnapattack/damn-vulnerable-log4j-app

Vulnerable web application to test CVE-2021-44228 / log4shell and forensic artifacts from an example attack

digital-forensicseducationexploitation+3
54 years ago
CVE-2021-44228-PoC preview

CVE-2021-44228-PoC

GitHubsunnyvale-it/cve-2021-44228-poc

CVE-2021-44228 (Log4Shell) Proof of Concept

educationexploitationpayload-generation+3
84 years ago
CVE-2019-0232_tomcat_cgi_exploit preview

CVE-2019-0232_tomcat_cgi_exploit

GitHubx3m1sec/cve-2019-0232_tomcat_cgi_exploit

Python exploit for CVE-2019-0232 targeting Apache Tomcat CGI vulnerabilities with automated reverse shell connection and customizable target/attacker…

educationexploitationpayload-generation+3
1 year ago
NSEC3-Encloser-Attack preview

NSEC3-Encloser-Attack

GitHubgoethe-universitat-cybersecurity/nsec3-encloser-attack

This project generates DNS zonefiles with custom NSEC3 parameters to reproduce and evaluate the attacks in CVE-2023-50868.

dns-analysisdns-fuzzingeducation+3
62 years ago
CVE-2026-50229 preview

CVE-2026-50229

GitHubzero-trace7/cve-2026-50229

Automated XSS scanner and proof-of-concept exploit for CVE-2026-50229 in Apache Tomcat examples. Detects and exploits reflected cross-site scripting…

educationexploitationpenetration-testing+3
1 month ago
CVE-2024-52301 preview

CVE-2024-52301

GitHubnyamort/cve-2024-52301

Proof-of-concept exploit for CVE-2024-52301 demonstrating environment manipulation in Laravel via injected URL parameters, with detailed code…

code-analysiseducationexploitation+3
211 year ago
CVE-2024-50340 preview

CVE-2024-50340

GitHubnyamort/cve-2024-50340

Proof-of-concept exploit for CVE-2024-50340 demonstrating Symfony ArgvInput environment variable injection via crafted URL query parameters, enabling…

code-analysiseducationexploitation+3
121 year ago
Previous123Next