Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
141 results
neo8-ghostlock-adaptation preview

neo8-ghostlock-adaptation

GitHubmke84/neo8-ghostlock-adaptation

iQOO Neo8 (PD2301, 5.10.246 GKI) CVE-2026-43499 GhostLock 适配 · 48 宏 target.h + offsets.json + 15 轮实测 log · 只缺 write layer

android-securitybinary-exploitationexploitation+5
1
18 days ago
ghostlock-pfem10 preview

ghostlock-pfem10

GitHubcxlfhx/ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

android-securitybinary-exploitationexploitation+7
29 days ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubhainhc/cve-2026-73570

Proof-of-concept exploit for CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration Suite via zimbra-snmp log injection,…

email-securityexploitationincident-response+3
29 days ago
KasperMeow preview

KasperMeow

GitHubmein-0/kaspermeow

Proof-of-concept that exploits a Kaspersky driver vulnerability to leak kernel pointers and bypass KASLR on Windows, enabling kernel exploit chain…

binary-analysisexploitationreverse-engineering+1
141 month ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubjuanpoch/cve-2026-73570

Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)

educationexploitationpapers-research+3
26 days ago
CVE-2026-62735 preview

CVE-2026-62735

GitHubnhh9905/cve-2026-62735

Proof-of-concept for CVE-2026-62735, an integer overflow in http.sys leading to heap overflow and SYSTEM shell. Includes crash log and stack trace…

binary-exploitationexploitationexploit-frameworks+1
371 month ago
CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC preview

CVE-2026-23918-Apache-HTTP-Server-DoubleFree-PoC

GitHubcyfare/cve-2026-23918-apache-http-server-doublefree-poc

Proof-of-concept exploit for CVE-2026-23918, a double-free vulnerability in Apache HTTP Server, demonstrating remote crash via crafted requests.

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
CVE-2026-2636_PoC preview

CVE-2026-2636_PoC

GitHuboxfemale/cve-2026-2636_poc

Proof-of-concept for CVE-2026-2636, a Windows CLFS.sys vulnerability causing BSoD via ReadFile on CreateLogFile handle, enabling unprivileged denial…

exploitationexploit-frameworksvulnerability-analysis
157 months ago
Llama-Stack-0.4.0rc3-local-CVE-2026-25211 preview

Llama-Stack-0.4.0rc3-local-CVE-2026-25211

GitHubmbanyamer/llama-stack-0.4.0rc3-local-cve-2026-25211

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

database-securityexploitationinformation-gathering+3
8 months ago
CVE-2026-25548 preview

CVE-2026-25548

GitHublagathos/cve-2026-25548

Detailed technical write-up and proof-of-concept for CVE-2026-25548, a critical RCE in InvoicePlane 1.7.0 via LFI and log poisoning, including attack…

educationexploitationpenetration-testing+3
16 months ago
CVE-2026-0709 preview

CVE-2026-0709

GitHubsnipersmaster/cve-2026-0709

Python proof-of-concept for authenticated command injection in Hikvision wireless APs, enabling remote code execution testing with customizable…

command-and-controlexploitationpenetration-testing+3
7 months ago
CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit preview

CVE-2025-61882-Oracle-E-Business-Suite-Pre-Auth-RCE-Exploit

GitHubadityabhatt3010/cve-2025-61882-oracle-e-business-suite-pre-auth-rce-exploit

A critical pre-authentication Remote Code Execution (RCE) flaw in Oracle E-Business Suite (versions 12.2.3 - 12.2.14) allows attackers to gain full…

exploitationforensicsincident-response+4
1211 months ago
CVE-2025-29824-CLFS-Local-privilege-escalation preview

CVE-2025-29824-CLFS-Local-privilege-escalation

GitHubzmkeh/cve-2025-29824-clfs-local-privilege-escalation

Local privilege escalation exploit for CVE-2025-29824 targeting the Windows Common Log File System (CLFS) driver, providing proof-of-concept code for…

binary-exploitationexploitationexploit-frameworks+2
211 months ago
CVE-2026-34344 preview

CVE-2026-34344

GitHubnhh9905/cve-2026-34344

PoC for CVE-2026-34344, a Windows afd.sys type confusion causing a kernel crash via AfdQueryProviderInfo. Provides trigger code, crash log, and…

binary-exploitationeducationexploitation+1
21 month ago
rsyslog-librelp-CVE-2018-1000140-fixed preview

rsyslog-librelp-CVE-2018-1000140-fixed

GitHubs0/rsyslog-librelp-cve-2018-1000140-fixed

Patch for CVE-2018-1000140 in rsyslog's librelp library, fixing a remote code execution vulnerability in the reliable event logging protocol…

code-analysisexploitationlog-analysis+2
7 years ago
rsyslog-librelp-CVE-2018-1000140 preview

rsyslog-librelp-CVE-2018-1000140

GitHubs0/rsyslog-librelp-cve-2018-1000140

Pinned version of rsyslov vulnerable to CVE-2018-1000140

exploitationlog-analysisnetwork-security+2
7 years ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubkaleth4/cve-2026-64638

Technical analysis and defensive mitigation for a WordPress Core pre-auth XSS-to-RCE chain, including sanitizer bypass, DOM clobbering, JSONP abuse,…

exploitationincident-responselog-analysis+3
1 month ago
CVE-2026-59310 preview

CVE-2026-59310

GitHubbiutrap/cve-2026-59310

Proof-of-concept exploit for CVE-2026-59310, demonstrating remote path traversal via crafted syslog messages to write arbitrary log files on VMware…

exploitationpenetration-testingvulnerability-analysis+2
21 month ago
Previous12…8Next