Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
23 results
flash-xdomain-xploit preview

flash-xdomain-xploit

GitHubgursev/flash-xdomain-xploit

ActionScript Proof of Concept to perform cross-domain reads

data-exfiltrationexploitationinformation-gathering+3
44
13 years ago
flash-xdomain-xploit preview

flash-xdomain-xploit

GitHubopensecurityresearch/flash-xdomain-xploit

ActionScript Proof of Concept to perform cross-domain reads

exploitationinformation-gatheringweb-application-exploitation+1
1613 years ago
CVE-2018-4407 preview

CVE-2018-4407

GitHublucagiovagnoli/cve-2018-4407

A buffer overflow vulnerability in the XNU kernel's ICMP error code causes IOS devices to crash (laptops and mobiles).

binary-exploitationexploitationinformation-gathering+3
17 years ago
smbghost preview

smbghost

GitHubsujitawake/smbghost

CVE-2020-0796_CoronaBlue_SMBGhost

exploitationinformation-gatheringnetwork-security+3
36 years ago
rdg_scanner_cve-2020-0609 preview

rdg_scanner_cve-2020-0609

GitHubruppde/rdg_scanner_cve-2020-0609

Scanning for Remote Desktop Gateways (Potentially unpatched CVE-2020-0609 and CVE-2020-0610)

exploitationinformation-gatheringnetwork-security+3
396 years ago
CVE-2026-31024 preview

CVE-2026-31024

GitHuberikdervishi03/cve-2026-31024

Proof of Concept (PoC) for a stack-based buffer overflow in Steghide 0.5.1. Demonstrates how long file paths trigger a crash (DoS) and leak sensitive…

binary-exploitationeducationexploitation+5
23 months ago
cve-2025-58360 preview

cve-2025-58360

GitHubthomas-osgood/cve-2025-58360

Python exploit class for CVE-2025-58360, an XXE vulnerability in GeoServer's GetMap function enabling arbitrary file read. Includes automated…

educationexploitationinformation-gathering+3
17 months ago
CVE-2022-27255-checker preview

CVE-2022-27255-checker

GitHubstryker-project/cve-2022-27255-checker

Simple checker for CVE-2022-27255 using poc_crash and telnet availability

exploitationinformation-gatheringnetwork-security+2
104 years ago
CVE-2022-0482_exploit preview

CVE-2022-0482_exploit

GitHubmija-pilkaite/cve-2022-0482_exploit

A final project for "Network Security" class at NYCU (National Yang Ming Chiao Tung University, Taiwan). Exploiting a CVE in "EasyAppointments"…

educationexploitationinformation-gathering+3
12 years ago
CVE-2020-11019 preview

CVE-2020-11019

GitHublixterclarixe/cve-2020-11019

In FreeRDP less than or equal to 2.0.0, when running with logger set to "WLOG_TRACE", a possible crash of application could occur due to a read of an…

curated-resourceseducationinformation-gathering+2
3 years ago
CVE-2019-8540 preview

CVE-2019-8540

GitHubmaldiohead/cve-2019-8540

Kernel Stack info leak at exportObjectToClient function

binary-analysisexploitationinformation-gathering+2
407 years ago
jadx-magic-strings preview

jadx-magic-strings

GitHub0rshemesh/jadx-magic-strings

JADX plugin that extracts method names, class references, and source file paths from string constants found in DEX files and decompiled Android code.

android-securitybinary-analysiscode-analysis+5
409 months ago
CVE-2017-3078 preview

CVE-2017-3078

GitHubhomjxi0e/cve-2017-3078

Proof-of-concept exploit for CVE-2017-3078, a memory corruption vulnerability in Adobe Flash Player ATF module enabling arbitrary code execution on…

binary-exploitationexploitationinformation-gathering+2
9 years ago
Blackash-CVE-2025-20343 preview

Blackash-CVE-2025-20343

GitHubfevar54/blackash-cve-2025-20343

Technical documentation and proof-of-concept for CVE-2025-20343, a high-severity denial-of-service vulnerability in Cisco ISE allowing…

authentication-authorizationexploitationinformation-gathering+2
10 months ago
hermes-osint preview

hermes-osint

GitHubexpert21/hermes-osint

Hermes — an ephemeral, Docker-powered OSINT framework for testing, tinkering, and secure investigative automation.

dns-subdomain-enumerationeducationemail-harvesting+6
437 months ago
CVE-2009-3036 preview

CVE-2009-3036

GitHubbrinhosa/cve-2009-3036

Repository documenting CVE-2009-3036, an HTML injection vulnerability in Symantec IM Manager, including details and exploit references.

exploitationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2018-4901 preview

CVE-2018-4901

GitHubbigric3/cve-2018-4901

crash poc & Leak info PoC

binary-exploitationexploitationinformation-gathering+2
168 years ago
CVE-2002-0201 preview

CVE-2002-0201

GitHubalt3kx/cve-2002-0201

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP…

exploitationinformation-gatheringpenetration-testing+2
8 years ago
Previous12Next