Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1201 results
CVE-2026-Wordpress preview

CVE-2026-Wordpress

GitHubhorkimhab/cve-2026-wordpress

Educational CVE proof-of-concept collection targeting WordPress vulnerabilities, with setup scripts and lab guidance for authorized security research…

curated-resourceseducationexploitation+5
1
2 days ago
blackbox-pentesting-infsecos preview

blackbox-pentesting-infsecos

GitHubsaqibnet/blackbox-pentesting-infsecos

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

ctfeducationexploitation+9
5 months ago
CVE-2026-59358 preview

CVE-2026-59358

GitHubabraxas/cve-2026-59358

Proof-of-concept lab and exploit client for CVE-2026-59358, demonstrating Cloud Foundry UAA reuse of a user PKCE token as client_credentials Bearer…

authenticationexploitationidentity-access-management+4
3 days ago
struts2-CVE-2013-2251 preview

struts2-CVE-2013-2251

GitHubnth347/struts2-cve-2013-2251

Vulnerable environment of CVE-2013-2251 (S2-016) for testing

educationexploitationlabs-practice+4
3 years ago
struts2-CVE-2020-17530 preview

struts2-CVE-2020-17530

GitHubnth347/struts2-cve-2020-17530

Vulnerable environment of CVE-2020-17530 (S2-061) for testing

educationexploitationlabs-practice+4
3 years ago
CVE-2026-59265 preview

CVE-2026-59265

GitHubhorkimhab/cve-2026-59265

Proof-of-concept and research material for CVE-2026-59265, a LibreOffice and OpenOffice vulnerability, intended for authorized lab testing and…

educationexploitationlabs-practice+4
3 days ago
cve-2026-105221-gist-tls preview

cve-2026-105221-gist-tls

GitHubabraxas/cve-2026-105221-gist-tls

CVE-2026-105221 - gist RubyGem - High - MITM - GitHub OAuth token theft

cryptographyexploitationlabs-practice+4
4 days ago
Nginx-chain-Rift-Poolslip preview

Nginx-chain-Rift-Poolslip

GitHuby198nt/nginx-chain-rift-poolslip

ASLR-independent nginx RCE chain PoC combining the PoolSlip heap over-read leak (CVE-2026-9256) with the rift overflow (CVE-2026-42945) to reach…

binary-exploitationeducationexploitation+7
144 months ago
Gu3ssWeak preview

Gu3ssWeak

GitHubb4sith-sec/gu3ssweak

Deliberately vulnerable Android app for mobile security research and bug bounty practice - OWASP Mobile Top 10

android-securityctfeducation+7
814 days ago
opencart-reward-free-checkout preview

opencart-reward-free-checkout

GitHubabraxas/opencart-reward-free-checkout

Proof-of-concept exploit and lab for an OpenCart 4.1.0.4 reward points plus Free Checkout payment bypass, letting an authenticated customer keep…

exploitationlabs-practicepenetration-testing+3
9 days ago
cve-2026-103956-loom-unauth preview

cve-2026-103956-loom-unauth

GitHubabraxas/cve-2026-103956-loom-unauth

CVE-2026-103956 - Loom for AWS - Critical - Auth bypass - unauthenticated super-admin when no IdP is configured

authenticationcloud-securityexploitation+5
36 days ago
CVE-2026-103648 preview

CVE-2026-103648

GitHubeternullsec/cve-2026-103648

Advisory and PoC for CVE-2026-103648, a path traversal (CWE-22) in image-downloader 4.3.0 enabling arbitrary file write, with root-cause analysis,…

educationexploitationlabs-practice+6
6 days ago
struts2-CVE-2021-31805 preview

struts2-CVE-2021-31805

GitHubnth347/struts2-cve-2021-31805

Vulnerable environment of CVE-2021-31805 (S2-062) for testing

educationexploitationlabs-practice+4
3 years ago
mediawiki-CVE-2026-100382 preview

mediawiki-CVE-2026-100382

GitHubnth347/mediawiki-cve-2026-100382

Docker lab reproducing CVE-2026-100382: unauthenticated argument-injection RCE in MediaWiki ExternalData's #get_program_data, with PoC payloads and…

command-and-controleducationexploitation+4
312 days ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
13 days ago
cve-2026-19553-wrap-bio preview

cve-2026-19553-wrap-bio

GitHubabraxas/cve-2026-19553-wrap-bio

Proof-of-concept lab reproducing CVE-2026-19553, where CPython ssl.SSLContext.wrap_bio() silently skips TLS hostname verification when…

cryptographyeducationexploitation+4
3 days ago
CVE-2026-20896 preview

CVE-2026-20896

GitHubyym8538/cve-2026-20896

Proof-of-concept lab and Python/cURL scripts demonstrating CVE-2026-20896, an authentication bypass in official Gitea Docker images via the…

authenticationcontainer-securityexploitation+5
11 month ago
CVE-2026-22599 preview

CVE-2026-22599

GitHubabraxas/cve-2026-22599

Python PoC and Docker lab for CVE-2026-22599, an authenticated SQL injection in Strapi's Content-Type Builder write API via Knex raw defaultTo.

database-securityexploitationlabs-practice+5
13 days ago
Previous12…67Next