Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
honor-6.12.38-43499-research preview

honor-6.12.38-43499-research

GitHubpyyyc/honor-6.12.38-43499-research

Research repository documenting exploitation attempts of CVE-2026-43499 futex UAF on Honor YLP-W00 kernel 6.12.38, including PoC sources, kernel…

android-securitybinary-exploitationexploitation+5
10 days ago
CVE-2026-43805-PoC preview

CVE-2026-43805-PoC

GitHubtls456/cve-2026-43805-poc

CVE-2026-43805 IOKit IODMACommand race analysis and proof of concept

binary-analysisexploitationios-security+5
7 days ago
cve-2023-6931-pipa preview

cve-2023-6931-pipa

GitHubyutori-natsu/cve-2023-6931-pipa

Kernel LPE exploit for CVE-2023-6931 on Xiaomi Pad 6 (pipa), chaining a perf read_size overflow to root and disabling SELinux via data-only…

android-securitybinary-exploitationexploitation+6
12 days ago
streambox-cve-2026-28618 preview

streambox-cve-2026-28618

GitHubraafatabualazm/streambox-cve-2026-28618

Redacted notes on CVE-2026-28618 / StreamBox APV lab — heap write into a session object via FRAME height mismatch

android-securitybinary-exploitationeducation+6
13 days ago
frida-il2cpp-datacollector preview

frida-il2cpp-datacollector

GitHubgmh5225/frida-il2cpp-datacollector

Frida-based tool that ports Cheat Engine's MonoDataCollector to Android and iOS, enabling runtime Mono/IL2CPP data collection and memory inspection…

android-securitybinary-analysisdebuggers+5
133 years ago
ghostlock-pfem10 preview

ghostlock-pfem10

GitHubimeiplus/ghostlock-pfem10

GhostLock (CVE-2026-43499) for OPPO Find X5 Pro (PFEM10) — OPlus watchdog & heap-spray detector reverse engineering

android-securitybinary-exploitationexploitation+6
16 days ago
CVE-2026-28609-matroska-pcm-oob preview

CVE-2026-28609-matroska-pcm-oob

GitHubdevrodt2/cve-2026-28609-matroska-pcm-oob

Proof-of-concept and instrumented reproduction harness for CVE-2026-28609, an out-of-bounds write in Android's MatroskaExtractor reachable via a…

android-securitybinary-exploitationexploitation+5
613 days ago
zenfone9-root preview

zenfone9-root

GitHubramenfast/zenfone9-root

Temporary root (uid 0) on a bootloader-locked ASUS Zenfone 9 via CVE-2025-21479 + a perf-based physical-address leak. GPLv3.

android-securitybinary-exploitationexploitation+7
316 days ago
asus-i005-cve-2026-43499 preview

asus-i005-cve-2026-43499

GitHubhuaguiqi/asus-i005-cve-2026-43499

CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked

android-securitybinary-exploitationexploitation+7
17 days ago
CVE-2026-65343-e7eb2ed preview

CVE-2026-65343-e7eb2ed

GitHubhidayat-tanjung/cve-2026-65343-e7eb2ed

PoC for CVE-2026-65343, an AppleKeyStore kernel OOB read on iOS 26.6 that leaks kernel pointers to defeat KASLR from a sandboxed app via…

binary-exploitationexploitationios-security+6
219 days ago
ghost-hoock preview

ghost-hoock

GitHubdeaurity/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
118 days ago
CVE-2026-43499-T807D preview

CVE-2026-43499-T807D

GitHubbobikl/cve-2026-43499-t807d

Android kernel exploit research package for CVE-2026-43499, containing popsicle exploit source, embedded su payload, root bridge helper, and…

android-securitybinary-exploitationexploitation+7
1 month ago
ghost-hoock preview

ghost-hoock

GitHubgenksome/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
419 days ago
ghostlock-cve-2026-43499-4.19-k40 preview

ghostlock-cve-2026-43499-4.19-k40

GitHubccp-p/ghostlock-cve-2026-43499-4.19-k40

Android kernel LPE PoC for CVE-2026-43499, an rtmutex use-after-free in 4.19 Qualcomm kernels, adapted for Redmi K40 with LD_PRELOAD root payload.

android-securitybinary-exploitationexploitation+6
417 days ago
CVE-2021-28664-PoC preview

CVE-2021-28664-PoC

GitHubwoaphone/cve-2021-28664-poc

PoC skeleton for CVE-2021-28664, a Mali kbase GPU driver use-after-free, demonstrating a kernel arbitrary physical memory read/write primitive on…

android-securitybinary-exploitationeducation+6
222 days ago
CVE-2026-43499-S26 preview

CVE-2026-43499-S26

GitHubsammyenigma/cve-2026-43499-s26

Android GKI 6.12 kernel exploit for CVE-2026-43499, chaining an rt_mutex rollback bug with pselect stack overwrite to gain root on Samsung and Pixel…

android-securitybinary-exploitationexploitation+8
1 month ago
RootMyVivo-Exploit preview

RootMyVivo-Exploit

GitHubzenyxx-xd/rootmyvivo-exploit

GhostLock (CVE-2026-43499) exploit fork for RootMyVivo Neo — iQOO Neo 11 (PD2520, SM8750, 6.6.89). For authorized research on own devices only.

android-securitybinary-exploitationexploitation+5
13 days ago
CVE-2026-20687-AppleJPEGDriver-UAF preview

CVE-2026-20687-AppleJPEGDriver-UAF

GitHubenfilade-labs/cve-2026-20687-applejpegdriver-uaf

CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

binary-exploitationexploitationios-security+4
25 months ago
Previous123Next