Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
732 results
Log4j-JNDIServer preview

Log4j-JNDIServer

GitHubimmunityinc/log4j-jndiserver

This project will help to test the Log4j CVE-2021-44228 vulnerability.

command-and-controlexploitationpayload-generation+3
9
4 years ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubeqstlab/cve-2026-19478

Proof-of-concept exploit for CVE-2026-19478, an unauthenticated GraphQL injection in GitLab CE/EE allowing arbitrary method invocation and project…

exploitationpenetration-testingred-teaming+3
41 month ago
fastjson-cve preview

fastjson-cve

GitHubipisav/fastjson-cve

Reproduction project for CVE-2026-16723, a critical RCE in fastjson 1.2.68-1.2.83. Demonstrates AutoType bypass, JNDI injection, and TemplatesImpl…

educationexploitationpapers-research+2
1 month ago
log4shell-exploitation-detection preview

log4shell-exploitation-detection

GitHubkalidoulabghaly/log4shell-exploitation-detection

Hands-on project demonstrating Log4Shell exploitation, detection engineering with Splunk and auditd, and validated remediation in a containerized…

container-securityeducationexploitation+5
20 days ago
code-graph-rag-PoC preview

code-graph-rag-PoC

GitHubsqueeze440/code-graph-rag-poc

PoC — symlink following to arbitrary file read/write outside project root in code-graph-rag (GHSA-85gg-2gfq-q95m, CVE-2026-87008, CVSS 7.1).

educationexploitationpapers-research+3
16 days ago
cve-2023-23397-purple-team preview

cve-2023-23397-purple-team

GitHubpraneethnaidu1910-cmd/cve-2023-23397-purple-team

Purple team project exploiting CVE-2023-23397 Outlook NTLM leak with phishing delivery, plus Sigma/Wazuh detections mapped to MITRE ATT&CK for the…

educationemail-securityexploitation+3
1 month ago
pdfjs-vuln-demo preview

pdfjs-vuln-demo

GitHubclarkio/pdfjs-vuln-demo

This project is intended to serve as a proof of concept to demonstrate exploiting the vulnerability in the PDF.js (pdfjs-dist) library reported in…

educationexploitationlabs-practice+3
41 year ago
CVE-2025-2783 preview

CVE-2025-2783

GitHubbytereaper77/cve-2025-2783

This project is a research-oriented and educational simulation designed to demonstrate the concept of a sandbox escape vulnerability within Google…

binary-exploitationeducationexploitation+1
81 year ago
CVE-2022-30190 preview

CVE-2022-30190

GitHubderziad/cve-2022-30190

This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability…

educationexploitationpayload-generation+2
61 year ago
CVE-2019-12180 preview

CVE-2019-12180

GitHub0x-nope/cve-2019-12180

Advisory and proof of concept for CVE-2019-12180, demonstrating arbitrary Groovy code execution in SoapUI and ReadyAPI via malicious project files.

code-analysisexploitationpayload-development+3
46 years ago
CVE-2026-37065 preview

CVE-2026-37065

GitHubjfs-jfs/cve-2026-37065

Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion

exploitationpenetration-testingred-teaming+2
3 months ago
CVE-2026-18718 preview

CVE-2026-18718

GitHubsn0x-sharma/cve-2026-18718

Found a 0-Day in Ghidra: Shared Project File Became a Code Execution Vector

code-analysisexploitationpayload-generation+2
11 month ago
CVE-2023-2825-PoC preview

CVE-2023-2825-PoC

GitHubgroppoxx/cve-2023-2825-poc

PoC for CVE-2023-2825: automated GitLab 16.0.0 arbitrary file read via nested public groups, project upload traversal, reusable upload paths, and…

exploitationinformation-gatheringpenetration-testing+2
44 months ago
CVE-2026-26211 preview

CVE-2026-26211

GitHublindhunt/cve-2026-26211

Public disclosure and proof-of-concept for CVE-2026-26211, a stored XSS vulnerability in Ekushey Project Manager CRM v5.0, including technical…

educationexploitationpapers-research+2
116 days ago
NSEC3-Encloser-Attack preview

NSEC3-Encloser-Attack

GitHubgoethe-universitat-cybersecurity/nsec3-encloser-attack

This project generates DNS zonefiles with custom NSEC3 parameters to reproduce and evaluate the attacks in CVE-2023-50868.

dns-analysisdns-fuzzingeducation+3
62 years ago
POC-CVE-2026-58048 preview

POC-CVE-2026-58048

GitHubimbas007/poc-cve-2026-58048

Security research project

database-securityexploitationlabs-practice+4
21 month ago
CVE-2022-40363 preview

CVE-2022-40363

GitHubolafdaf/cve-2022-40363

A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a…

binary-analysisembedded-systems-securityexploitation+3
53 years ago
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

api-security-testingeducationexploitation+4
1 month ago
Previous1…789…41Next