Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille- preview

CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-

GitHubtheopaid/cve-2026-66754-remote-denial-of-service-via-reachable-assertion-in-url-prefix-handling-rouille-

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

educationpapers-researchvulnerability-analysis+1
2 months ago
CVE-2025-58179-Check preview

CVE-2025-58179-Check

GitHubshitodcy/cve-2025-58179-check

Python script to verify SSRF and content spoofing vulnerabilities (CVE-2025-58179) in Astro's `/_image` endpoint, with automated PoC URL generation…

educationexploitationpenetration-testing+3
211 months ago
PHP-CGI-RCE-Scanner preview

PHP-CGI-RCE-Scanner

GitHubywchen-ntust/php-cgi-rce-scanner

Scanning CVE-2024-4577 vulnerability with a url list.

educationexploitationinformation-gathering+3
11 year ago
CVE-2026-34212 preview

CVE-2026-34212

GitHub0xmrma/cve-2026-34212

Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor…

educationexploitationpapers-research+3
3 months ago
starlette-host-header-lab preview

starlette-host-header-lab

GitHubxtremebeing/starlette-host-header-lab

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

authenticationeducationlabs-practice+3
14 months ago
CVE-2024-28515 preview

CVE-2024-28515

GitHubheshi906/cve-2024-28515

Documentation of CVE-2024-28515, a buffer overflow vulnerability in CSAPP Lab3 (buflab-update.pl), enabling remote code execution via crafted URL…

binary-exploitationeducationexploitation+2
12 years ago
CVE-2025-20384 preview

CVE-2025-20384

GitHubaxselll/cve-2025-20384

Proof-of-concept demonstrating log injection and poisoning in Splunk via crafted URL parameters, highlighting OWASP log injection risks.

educationexploitationlog-analysis+3
9 months ago
CVE-2022-44877 preview

CVE-2022-44877

GitHubdkstar11q/cve-2022-44877

Bash script to detect and exploit CVE-2022-44877 command injection vulnerability in CentOS Web Panel, supporting single URL scanning, exploitation,…

command-and-controleducationexploitation+3
3 years ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubeqstlab/cve-2026-33017

Langflow RCE

code-analysiseducationexploitation+3
111 month ago
CVE-2022-22965_PoC preview

CVE-2022-22965_PoC

GitHubalt3kx/cve-2022-22965_poc

Spring Framework RCE (Quick pentest notes)

educationexploitationpayload-generation+3
174 years ago
CVE-2025-24893-PoC preview

CVE-2025-24893-PoC

GitHubisee857/cve-2025-24893-poc

XWiki SolrSearchMacros 远程代码执行漏洞PoC(CVE-2025-24893)

educationexploitationpenetration-testing+2
101 year ago
CVE-2023-49438 preview

CVE-2023-49438

GitHubbrandon-t-elliott/cve-2023-49438

CVE-2023-49438 - Open Redirect Vulnerability in Flask-Security-Too

educationpapers-researchvulnerability-analysis+2
52 years ago
Apache-CVE-2021-41773 preview

Apache-CVE-2021-41773

GitHublheeeesoo/apache-cve-2021-41773

WHS 4기 이희수. kr-vulhub 과제 제출물

educationexploitationlabs-practice+3
3 months ago
CVE-2025-30208-Series preview

CVE-2025-30208-Series

GitHubr0ngy40/cve-2025-30208-series

Analysis of the Reproduction of CVE-2025-30208 Series Vulnerabilities

code-analysiseducationexploitation+3
31 year ago
CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb- preview

CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb-

GitHubtheopaid/cve-2026-67185-unauthenticated-path-traversal-allows-arbitrary-file-read-tinyweb-

Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)

code-analysiseducationexploitation+2
12 months ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
12 months ago
CVE-2016-8863 preview

CVE-2016-8863

GitHubmephi42/cve-2016-8863

CTFs are fun, but what about exploiting a real bug?

binary-exploitationeducationexploitation+2
15 years ago
CVE-2021-43129 preview

CVE-2021-43129

GitHubskotizo/cve-2021-43129

Vulnerability in D2L Brightspace's Learning Management System(LMS)

educationexploitationpapers-research+2
24 years ago
Previous123456Next