Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
793 results
CVE-2025-55182-NextJS-RCE-PoC preview

CVE-2025-55182-NextJS-RCE-PoC

GitHubpkrasulia/cve-2025-55182-nextjs-rce-poc

Working Proof of Concept (PoC) for CVE-2025-55182 (React2Shell) - Unauthenticated Remote Code Execution in Next.js 15.0.0 via React Server Components

educationexploitationlabs-practice+3
4
9 months ago
CVE-2025-32463_chwoot preview

CVE-2025-32463_chwoot

GitHubashardev002/cve-2025-32463_chwoot

🔍 Demonstrate the CVE-2025-32463 privilege-escalation flaw in sudo's chroot feature with this minimal, reproducible proof of concept environment.

container-securityeducationexploitation+3
11 day ago
From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps preview

From-Foothold-to-Domain-Admin-Weaponizing-CVE-2025-54918-in-Real-World-DevOps

GitHubmrk336/from-foothold-to-domain-admin-weaponizing-cve-2025-54918-in-real-world-devops

Simulated exploitation and mitigation of CVE-2025-54918 (Windows NTLM flaw). Includes detection scripts, Ansible patching, and CI/CD hardening.…

cloud-securityconfiguration-auditingdevsecops+7
411 months ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubgodoy-sec/cve-2017-14980

Study of a classic stack-based buffer overflow vulnerability in a controlled lab environment for educational purposes.

binary-exploitationdebuggerseducation+5
129 days ago
CVE-2026-9086-poc preview

CVE-2026-9086-poc

GitHubsaku0512/cve-2026-9086-poc

CVE-2026-9086 proof-of-concept for Keycloak client URI validation bypass using mixed-case javascript: and data: XSS payloads, with Docker-based…

educationexploitationlabs-practice+3
129 days ago
CVE-2022-22965 preview

CVE-2022-22965

GitHubkhidottrivi/cve-2022-22965

In-depth technical analysis of CVE-2022-22965 (Spring4Shell) with environment setup, debug walkthrough, and exploit chain breakdown for educational…

code-analysiseducationexploitation+3
44 years ago
ZygoteExploitDemo preview

ZygoteExploitDemo

GitHubgitamans/zygoteexploitdemo

Educational demonstration of CVE-2024-31317 Zygote Injection Vulnerability on Android

android-securitybinary-exploitationeducation+7
26 months ago
100DaysofYARA preview

100DaysofYARA

GitHubsquiblydoo/100daysofyara

Rules shared by the community from 100 Days of YARA 2026

curated-resourceseducationlabs-practice+3
56 months ago
CVE-2025-32463-PoC preview

CVE-2025-32463-PoC

GitHubfreedurok/cve-2025-32463-poc

Proof of Concept for CVE-2025-32463 Local privilege escalation exploit targeting sudo -R on vulnerable Linux systems. For educational and authorized…

educationexploitationlabs-practice+3
51 year ago
cve-2023-4863-analysis preview

cve-2023-4863-analysis

GitHubshcesama/cve-2023-4863-analysis

Educational analysis of CVE-2023-4863 (libwebp heap buffer overflow) with Blue Team detection tools, static WebP scanner, defensive Java validator,…

binary-analysisdefensive-toolsdynamic-analysis-sandboxing+5
23 months ago
lehack-2026-challenge preview

lehack-2026-challenge

GitHubsynacktiv/lehack-2026-challenge

Sources of Synacktiv's challenge for leHack 2026

ctfdigital-forensicseducation+3
22 months ago
CVE-2026-34040-PoC preview

CVE-2026-34040-PoC

GitHubm0nk3ygod/cve-2026-34040-poc

Lab reproduction of CVE-2026-34040: bypasses Docker/Moby AuthZ plugins using oversized (>1MB) request bodies to create privileged containers with…

cloud-infrastructure-securitycontainer-securityeducation+3
3 months ago
CVE-2023-23397 preview

CVE-2023-23397

GitHubpushkarup/cve-2023-23397

This script exploits CVE-2023-23397, a Zero-Day vulnerability in Microsoft Outlook, allowing the generation of malicious emails for testing and…

educationexploitationlabs-practice+3
42 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubtr3m0x/cve-2021-41773

PoC and analysis of CVE-2021-41773

educationlabs-practicepenetration-testing+3
1 month ago
CVE-2026-65761 preview

CVE-2026-65761

GitHubywh-jfellus/cve-2026-65761

Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`

database-securityeducationlabs-practice+2
1 month ago
Spring4Shell-POC preview

Spring4Shell-POC

GitHubprinceh4k/spring4shell-poc

Proof of Concept for exploiting the CVE-2022-22965 (Spring4Shell) vulnerability in an isolated environment, with Remote Code Execution (RCE)…

educationexploitationlabs-practice+4
1 month ago
CVE-2021-3156-Baron-Samedit preview

CVE-2021-3156-Baron-Samedit

GitHubkranti08/cve-2021-3156-baron-samedit

Exploitation and mitigation analysis of CVE-2021-3156 heap-based buffer overflow in sudo

binary-exploitationeducationexploitation+4
2 months ago
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
Previous1…141516…45Next