Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
CVE-2026-50787 preview

CVE-2026-50787

GitHubbrynax/cve-2026-50787

Security advisory detailing CVE-2026-50787, an uncontrolled resource consumption vulnerability in e-SIC Livre CAPTCHA generation, enabling remote…

curated-resourceseducationvulnerability-analysis+1
3 days ago
gosentry preview

gosentry

GitHubtrailofbits/gosentry

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

binary-analysiscode-analysisdevsecops+5
1183 days ago
EasySpider preview

EasySpider

GitHubnaibowang/easyspider

A visual no-code/code-free web crawler/spider易采集:一个可视化浏览器自动化测试/数据采集/网页爬虫软件,可以无代码图形化的设计和执行爬虫任务。别名:ServiceWrapper面向Web应用的智能化服务封装系统。

crawlereducationscripting-automation+1
44.5k11 days ago
CVE-2026-63766_exploit preview

CVE-2026-63766_exploit

GitHub0xdak/cve-2026-63766_exploit

Unauthenticated OS command injection exploit for GPT-SoVITS Gradio web UI. Delivers RCE via unsanitized path parameters in audio-processing helpers,…

command-and-controleducationexploitation+3
1 month ago
CVE-2026-50229 preview

CVE-2026-50229

GitHubzero-trace7/cve-2026-50229

Automated XSS scanner and proof-of-concept exploit for CVE-2026-50229 in Apache Tomcat examples. Detects and exploits reflected cross-site scripting…

educationexploitationpenetration-testing+3
1 month ago
p3-loader preview

p3-loader

GitHuborange-cyberdefense/p3-loader

P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure as an execution and…

binary-exploitationdefensive-toolseducation+8
2121 month ago
polytracker preview

polytracker

GitHubtrailofbits/polytracker

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

binary-analysisdynamic-code-analysiseducation+4
5982 months ago
cerebro-red-v2 preview

cerebro-red-v2

GitHubleviticus-triage/cerebro-red-v2

CEREBRO-RED v2: Advanced LLM Red Team Research Platform with PAIR Algorithm and LLM-as-a-Judge Evaluation

adversarial-attackai-securitydynamic-analysis-sandboxing+8
165 months ago
CVE-2023-34836 preview

CVE-2023-34836

GitHubsahiloj/cve-2023-34836

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Microworld Technologies eScan Management Console v14.0.1400.2281. The vulnerable…

educationpapers-researchpenetration-testing+2
16 months ago
CVE-2024-55187 preview

CVE-2024-55187

GitHubmallo-m/cve-2024-55187

Detailed CVE-2024-55187 advisory with proof-of-concept for a remote code execution vulnerability in phpIpam, exploiting path poisoning and PHAR file…

code-analysiseducationexploitation+3
8 months ago
CVE-2025-20384 preview

CVE-2025-20384

GitHubaxselll/cve-2025-20384

Proof-of-concept demonstrating log injection and poisoning in Splunk via crafted URL parameters, highlighting OWASP log injection risks.

educationexploitationlog-analysis+3
8 months ago
CVE-2023-50164-Apache-Struts-RCE preview

CVE-2023-50164-Apache-Struts-RCE

GitHubjakabakos/cve-2023-50164-apache-struts-rce

A critical security vulnerability, identified as CVE-2023-50164 (CVE: 9.8) was found in Apache Struts, allowing attackers to manipulate file upload…

educationexploitationpayload-development+3
8610 months ago
CVE-2025-56381 preview

CVE-2025-56381

GitHubmoalali/cve-2025-56381

ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the…

educationexploitationpenetration-testing+2
111 months ago
CVE-2023-50164-HTB-strutted preview

CVE-2023-50164-HTB-strutted

GitHubmkirahmet/cve-2023-50164-htb-strutted

Proof-of-concept for CVE-2023-50164 (Apache Struts 2), originally by jakabakos and adapted for the HTB Strutted lab environment. For educational use…

ctfeducationexploitation+3
11 months ago
CVE-2016-10033 preview

CVE-2016-10033

GitHubalexander47777/cve-2016-10033

Proof-of-concept exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer, demonstrating injection of additional sendmail…

educationexploitationpayload-generation+3
1 year ago
CVE-2025-53652-Jenkins-Git-Parameter-Analysis preview

CVE-2025-53652-Jenkins-Git-Parameter-Analysis

GitHubpl4tyz/cve-2025-53652-jenkins-git-parameter-analysis

CVE-2025-53652: Jenkins Git Parameter Analysis

code-analysiscommand-and-controldevsecops+3
21 year ago
cve-2025-4664 preview

cve-2025-4664

GitHubamalmurali47/cve-2025-4664

PoC and Setup for CVE-2025-4664

educationexploitationinformation-gathering+3
41 year ago
CVE-2025-25615 preview

CVE-2025-25615

GitHubarmaansidana2003/cve-2025-25615

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing teachers to view attendance for any class section via…

educationexploitationpenetration-testing+2
1 year ago
Previous123Next