Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
104 results
Reversecore_MCP preview

Reversecore_MCP

GitHubsjkim1127/reversecore_mcp

A security-first MCP server that empowers AI agents to perform automated reverse engineering, malware analysis, forensics, vulnerability research,…

binary-analysisdigital-forensicsdynamic-analysis-sandboxing+7
199
11h 44m ago
CVE-2020-16947 preview

CVE-2020-16947

GitHub0neb1n/cve-2020-16947

Proof-of-concept exploit for CVE-2020-16947, a Microsoft Outlook RCE triggered by malformed HTML content leading to a heap buffer overflow and remote…

binary-exploitationemail-securityexploitation+3
1225 years ago
clif preview

clif

GitHub0x4ndy/clif

clif is a command-line interface (CLI) application fuzzer, pretty much what wfuzz or ffuf are for web. It was inspired by sudo vulnerability…

binary-exploitationdynamic-analysis-sandboxingexploitation+3
1003 years ago
CVE-2020-1493 preview

CVE-2020-1493

GitHub0neb1n/cve-2020-1493

Technical analysis and PoC details for CVE-2020-1493, a zero-click Outlook RCE triggered by malformed MS-TNEF attachments leading to remote code…

binary-exploitationemail-securityexploitation+3
256 years ago
killasa preview

killasa

GitHubjgajek/killasa

Exploit tool for CVE-2016-1287 that tests Cisco ASA devices by sending crafted IKEv2 fragments with invalid lengths to trigger denial of service.

exploitationfuzzingnetwork-security+2
1610 years ago
Hipcam-RTSP-Format-Validation-Vulnerability preview

Hipcam-RTSP-Format-Validation-Vulnerability

GitHubmaximilianljungblut/hipcam-rtsp-format-validation-vulnerability

This POC exploits a format validation vulnerability in the RTSP service of the Hipcam RealServer/V1.0, inducing a crash for approximately 45 seconds…

exploitationfuzzingiot-security+2
192 years ago
danish_phone_wordlist_generator preview

danish_phone_wordlist_generator

GitHubn0kovo/danish_phone_wordlist_generator

Generate wordlists of Danish phone numbers by area and/or usage (Mobile, landline etc.) Useful for password cracking or fuzzing Danish targets.

fuzzingosintpassword-cracking
84 years ago
netgear_r6700v3_circled preview

netgear_r6700v3_circled

GitHubcyber-defence-campus/netgear_r6700v3_circled

Demonstrate some functionalities of Morion by generating an exploit for CVE-2022-27646 (stack buffer overflow on Netgear R6700v3 routers).

binary-exploitationeducationembedded-systems-security+4
81 year ago
CVE-2022-40363 preview

CVE-2022-40363

GitHubolafdaf/cve-2022-40363

A buffer overflow in the component nfc_device_load_mifare_ul_data of Flipper Devices Inc., Flipper Zero before v0.65.2 allows attackers to cause a…

binary-analysisembedded-systems-securityexploitation+3
53 years ago
PoC-CVE-2025-69419 preview

PoC-CVE-2025-69419

GitHubkha-beleh/poc-cve-2025-69419

Minimal proof-of-concept reproducer for CVE-2025-69419, a heap buffer overflow in OpenSSL's PKCS12_get_friendlyname() triggered by a crafted…

binary-analysiscryptographyeducation+3
1 month ago
dns_client_fuzzing preview

dns_client_fuzzing

GitHubpersonnumber3377/dns_client_fuzzing

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

binary-analysisdns-analysisexploitation+2
2 months ago
buds-audit preview

buds-audit

GitHubspiritualmachines/buds-audit

No-dongle, no-root Bluetooth security assessment tool for wireless earbuds affected by the Airoha SDK vulnerability chain (CVE-2025-20700/20701/20702)

bluetooth-securityembedded-systems-securityexploitation+8
11 month ago
cve-2026-23398-poc preview

cve-2026-23398-poc

GitHubzpol/cve-2026-23398-poc

Reproducible lab for CVE-2026-23398, a Linux kernel NULL dereference in icmp_tag_validation() triggered by ICMP Fragmentation Needed packets, causing…

educationexploitationfuzzing+3
15 months ago
CVE-2026-42945-nginx-rift-poc preview

CVE-2026-42945-nginx-rift-poc

GitHubf2u0a0d3/cve-2026-42945-nginx-rift-poc

PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab,…

binary-exploitationdynamic-analysis-sandboxingeducation+6
13 months ago
CVE-2024-22641 preview

CVE-2024-22641

GitHubzunak/cve-2024-22641

Proof-of-concept for CVE-2024-22641: ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted SVG files, demonstrating regex backtrack limit…

educationexploitationfuzzing+3
12 years ago
CVE-2026-20404-MediaTek-modem-remote-DoS-rogue-base-station-scenario- preview

CVE-2026-20404-MediaTek-modem-remote-DoS-rogue-base-station-scenario-

GitHubgeorge0papasotiriou/cve-2026-20404-mediatek-modem-remote-dos-rogue-base-station-scenario-

A MediaTek modem input validation issue can cause a system crash (remote DoS) when a UE connects to a rogue base station controlled by an attacker…

binary-analysisexploitationfuzzing+2
16 months ago
CVE-2025-55780 preview

CVE-2025-55780

GitHubish2yu/cve-2025-55780

Null Pointer Dereference in MuPDF , First CVE discovered by me

binary-analysiseducationexploitation+3
11 months ago
windows_tcpip_fuzz preview

windows_tcpip_fuzz

GitHubpersonnumber3377/windows_tcpip_fuzz

This is my attempt at fuzzing the tcpip.sys driver in windows via using scapy. This is inspired by this vulnerability here:…

binary-analysisexploitationfuzzing+2
1 year ago
Previous123456Next