Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
137 results
CVE-2023-46449 preview

CVE-2023-46449

GitHubsajaljat/cve-2023-46449

Proof-of-concept exploit for CVE-2023-46449: IDOR in Sourcecodester inventory management system v1.0 password change function enabling remote account…

authenticationeducationmisconfiguration+3
2 years ago
moodle-cve preview

moodle-cve

GitHubhxuu/moodle-cve

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

ctfeducationexploitation+3
31 year ago
CVE-2026-5229 preview

CVE-2026-5229

GitHubxxconi/cve-2026-5229

CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)

authenticationeducationexploitation+3
3 months ago
CVE-2025-3605 preview

CVE-2025-3605

GitHubnxploited/cve-2025-3605

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

educationexploitationpassword-attacks+4
21 year ago
FlowiseAI-Critical-KillChain preview

FlowiseAI-Critical-KillChain

GitHubcveteam/flowiseai-critical-killchain

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

authenticationeducationexploitation+5
14 months ago
Galaxy-Bugbounty-Checklist preview

Galaxy-Bugbounty-Checklist

GitHub0xmaximus/galaxy-bugbounty-checklist

Tips and Tutorials for Bug Bounty and also Penetration Tests.

curated-resourceseducationosint+3
2.1k10 months ago
IngressNightmare-PoC preview

IngressNightmare-PoC

GitHubhakaioffsec/ingressnightmare-poc

This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).

cloud-securitycontainer-securityeducation+5
2501 year ago
ENLBufferPwn preview

ENLBufferPwn

GitHubpablomk7/enlbufferpwn

Information and PoC about the ENLBufferPwn vulnerability

binary-exploitationeducationembedded-systems-security+2
2992 years ago
relay_bible preview

relay_bible

GitHubrootsecdev/relay_bible

Technical Reference to multiple relay techniques

authenticationcurated-resourceseducation+8
1943 months ago
CVE-2026-3227-TP-Link-authenticated-RCE preview

CVE-2026-3227-TP-Link-authenticated-RCE

GitHubdo4choo/cve-2026-3227-tp-link-authenticated-rce

Proof-of-concept for authenticated OS command injection in TP-Link router firmware. Includes decryption, QEMU-based encryption hook, and 15-character…

binary-exploitationeducationexploitation+6
422 months ago
CVE-2026-41089-Netlogon-RCE preview

CVE-2026-41089-Netlogon-RCE

GitHubhydrasoft/cve-2026-41089-netlogon-rce

Technical analysis and Proof-of-Concept (PoC) for CVE-2026-41089, a critical unauthenticated Remote Code Execution (RCE) vulnerability in the Windows…

educationexploitationincident-response+4
166 days ago
vibe-coding-security preview

vibe-coding-security

GitHubboxed-dev/vibe-coding-security

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

ai-securityapi-securityauthentication+9
1420 days ago
CVE-2025-65640 preview

CVE-2025-65640

GitHubvincenzo-emanuele/cve-2025-65640

Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.

educationpapers-researchpenetration-testing+3
102 months ago
CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval- preview

CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval-

GitHubgeorge0papasotiriou/cve-2026-22005-oauth-2.0-device-code-phishing-short-interval-

Proof-of-concept for CVE-2026-22005 showing OAuth 2.0 device code phishing via too-short polling interval, with vulnerable Flask server and exploit…

authentication-authorizationeducationexploitation+4
25 days ago
CVE-2021-21972 preview

CVE-2021-21972

GitHubhurrrraaaa/cve-2021-21972

Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection,…

educationexploitationlabs-practice+4
27 days ago
supply-chain-guard preview

supply-chain-guard

GitHuberis-ths/supply-chain-guard

Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during…

devsecopseducationincident-response+6
31 month ago
CVE-2017-0144 preview

CVE-2017-0144

GitHub0xblackash/cve-2017-0144

CVE-2017-0144

educationexploitationincident-response+3
22 months ago
cve-2025-5755 preview

cve-2025-5755

GitHubcybertechajju/cve-2025-5755

Asynchronous scanner and exploit tool for CVE-2025-5777 (CitrixBleed 2). Detects memory leaks in NetScaler ADC/Gateway, parses sensitive data like…

educationexploitationinformation-gathering+3
81 year ago
Previous1…456…8Next