Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
cve-lite-cli preview

cve-lite-cli

GitHubowasp/cve-lite-cli

Fast, developer-friendly JS/TS dependency vulnerability scanner with local lockfile scanning, OSV matching, direct vs transitive visibility, --fix,…

code-analysiscurated-resourcesdevsecops+5
756
3h 57m ago
CVE-2026-65320-fastcore preview

CVE-2026-65320-fastcore

GitHubrahulreddykarne/cve-2026-65320-fastcore

Documents CVE-2026-65320, a tar-slip path traversal in fastcore's untar_dir(), with a harmless proof-of-concept demonstrating arbitrary file write…

code-analysiseducationexploitation+3
8 days ago
EXPLOIT-CVE-2026-33634 preview

EXPLOIT-CVE-2026-33634

GitHubjoaovicdev/exploit-cve-2026-33634

Deliberately vulnerable Docker lab reproducing CVE-2026-33634: LiteLLM gateway SSRF via api_base plus a trojanized dependency, with a multi-phase…

cloud-securitycontainer-securitydata-exfiltration+7
12 days ago
xz-utils-backdoor-case-study preview

xz-utils-backdoor-case-study

GitHubmichel-dv/xz-utils-backdoor-case-study

Technical case study of the XZ Utils backdoor (CVE-2024-3094), covering supply-chain trust abuse, malicious release artifacts, build-stage injection,…

educationincident-responsemalware-analysis+6
19 days ago
airecon preview

airecon

GitHubpikpikcu/airecon

AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual…

ai-securityeducationexploitation+6
1.1k23 days ago
reproducer-okio-cve-2023-3635 preview

reproducer-okio-cve-2023-3635

GitHubjoshuaasmith/reproducer-okio-cve-2023-3635

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

android-securityeducationmobile-security+2
24 days ago
chrome-vuln-scanner preview

chrome-vuln-scanner

GitHubvirologi-info/chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

defensive-toolseducationstatic-analysis+2
1 month ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubd4ytox/cve-2021-22204

ExifTool RCE exploit (CVE-2021-22204) - improved version, no exiftool dependency

educationexploitationpayload-generation+3
1 month ago
violent-python3 preview

violent-python3

GitHubeonraider/violent-python3

Source code for the book "Violent Python" by TJ O'Connor. The code has been fully converted to Python 3, reformatted to comply with PEP8 standards…

bluetooth-securityeducationexploitation+8
1.1k1 month ago
CVE-2026-5061 preview

CVE-2026-5061

GitHub0xmrma/cve-2026-5061

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

code-analysisdata-exfiltrationeducation+2
12 months ago
wp2shell-lab preview

wp2shell-lab

GitHubananay/wp2shell-lab

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

api-security-testingcode-analysiseducation+3
2 months ago
log4shell-scanner preview

log4shell-scanner

GitHubarpitgupta369/log4shell-scanner

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.

defensive-toolseducationlog-analysis+3
2 months ago
sdk preview

sdk

GitLabcosignet/sdk

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

api-securityauthenticationauthentication-authorization+3
2 months ago
vsftpd-234-backdoor preview

vsftpd-234-backdoor

GitHubh4r335hr/vsftpd-234-backdoor

Dependency-free interactive Python exploit for the vsftpd 2.3.4 backdoor (CVE-2011-2523).

educationexploitationlabs-practice+3
4 months ago
CVE-2026-45321-Tanstack preview

CVE-2026-45321-Tanstack

GitHubrenewablehacking/cve-2026-45321-tanstack

Educational lab simulating npm supply chain attacks, CI/CD abuse, and install-time code execution via CVE-2026-45321. Hands-on defensive security…

educationlabs-practicemalware-analysis+2
4 months ago
copy-fail-checker preview

copy-fail-checker

GitHubsamanzamani/copy-fail-checker

Read-only Bash checker for the Copy Fail Linux kernel vulnerability (CVE-2026-31431)

cryptographyeducationexploitation+4
54 months ago
ollama preview

ollama

GitHubdannyendortest/ollama

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…

devsecopseducationexploitation+3
4 months ago
node-prompt-here preview

node-prompt-here

GitHubdannyendortest/node-prompt-here

Deliberately vulnerable Node.js demo target for CVE-2020-7602, used to showcase automated dependency vulnerability detection and one-click PR-based…

educationlabs-practicesupply-chain-security+2
4 months ago
Previous123Next