Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
JYso preview

JYso

GitHubqi4l/jyso

Dual-purpose JNDI injection and Java deserialization exploitation framework with advanced bypass capabilities for WAF, RASP, and high JDK versions.…

command-and-controlctfexploit-frameworks+5
1.8k
2 months ago
CVE-2025-27363 preview

CVE-2025-27363

GitHubtin-z/cve-2025-27363

Integer overflow in FreeType software, which also affects Chrome

binary-exploitationeducationexploitation+3
311 month ago
XBadManners preview

XBadManners

GitHubttffdd/xbadmanners

PoC generator and memory extraction tool for CVE-2018-16323 ImageMagick memory leak. Generates malicious XBM images to leak server memory, with…

data-exfiltrationexploitationmemory-forensics+2
837 years ago
CVE-2022-26717-Safari-WebGL-Exploit preview

CVE-2022-26717-Safari-WebGL-Exploit

GitHubtheori-io/cve-2022-26717-safari-webgl-exploit

Proof-of-concept exploit for CVE-2022-26717, a use-after-free vulnerability in Safari's WebGL implementation, enabling remote code execution via…

binary-exploitationexploitationmemory-forensics+2
614 years ago
CVE-2022-22947- preview

CVE-2022-22947-

GitHub0730nophone/cve-2022-22947-

Proof-of-concept exploit for Spring Cloud Gateway CVE-2022-22947 that leverages Actuator SpEL injection to run arbitrary commands and deploy a…

command-and-controlexploitationmemory-forensics+3
604 years ago
CVE-2021-21017 preview

CVE-2021-21017

GitHubzeusbox/cve-2021-21017

Proof-of-concept exploit for Adobe Reader type confusion leading to heap overflow, with detailed root-cause analysis and detection guidance.

binary-exploitationexploitationfuzzing+3
445 years ago
CVE-2025-2783 preview

CVE-2025-2783

GitHubalchemist3dot14/cve-2025-2783

Simulated proof-of-concept for CVE-2025-2783, a Chrome Mojo IPC sandbox escape. Includes phishing delivery, memory fuzzing, IPC simulation, and…

binary-exploitationeducationexploitation+8
331 year ago
CVE-2025-5777 preview

CVE-2025-5777

GitHubbughuntar/cve-2025-5777

Exploit tool for CVE-2025-5777, a Citrix NetScaler memory leak, featuring malformed request triggering, hex dump output, and async scanning for…

exploitationinformation-gatheringmemory-forensics+3
301 year ago
WebKit-CVE-2016-4622 preview

WebKit-CVE-2016-4622

GitHubhdbreaker/webkit-cve-2016-4622

Deep-dive analysis and exploitation walkthrough of CVE-2016-4622, a WebKit JavaScriptCore memory disclosure vulnerability via Array.slice TOCTOU race…

binary-exploitationeducationexploitation+4
231 year ago
CVE-2026-14382 preview

CVE-2026-14382

GitHubjaf0rk/cve-2026-14382

Proof-of-concept exploit for CVE-2026-14382, a high-severity ANGLE vulnerability in Chromium, with 32-bit and AArch64 PoCs achieving program counter…

android-securitybinary-exploitationexploitation+4
71 month ago
CVE-2013-2730 preview

CVE-2013-2730

GitHubfeliam/cve-2013-2730

Proof-of-concept exploit for CVE-2013-2730, demonstrating a memory corruption vulnerability with a C-based implementation for security research and…

binary-exploitationexploitationmemory-forensics+2
1013 years ago
Cassowary-CVE-2024-23222-x86_64 preview

Cassowary-CVE-2024-23222-x86_64

GitHubfuzzysecurity/cassowary-cve-2024-23222-x86_64

Proof-of-concept adaptation of CVE-2024-23222 (WebKit JSC TOCTOU) for Linux x86_64, demonstrating stale-cell UAF via DFG compiler race window with…

binary-exploitationexploitationmemory-forensics+4
105 months ago
CVE-2022-22947 preview

CVE-2022-22947

GitHubsijido/cve-2022-22947

Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

exploitationmemory-forensicsvulnerability-analysis+1
94 years ago
CVE-2020-15999 preview

CVE-2020-15999

GitHuboxfemale/cve-2020-15999

Proof-of-concept exploit for CVE-2020-15999, a heap-buffer-overflow in Chrome's FreeType font rendering via crafted SBIX table, with ASAN crash…

binary-analysisexploitationfuzzing+3
35 years ago
CVE-2022-22620 preview

CVE-2022-22620

GitHubspringsec/cve-2022-22620

Exploit for CVE-2022-22620 (Zombie): use-after-free in WebKit/Safari with infoleak of JSObject address, tested on webkitgtk-2.34.3.

binary-exploitationexploitationmemory-forensics+2
64 years ago
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

Exploits pre-auth XSS in WordPress (CVE-2026-64638) to achieve RCE; includes safe-check mode, reverse shell, C2 beaconing, persistence, privilege…

command-and-controlexploitationmemory-forensics+6
117 days ago
CVE-2021-30573 preview

CVE-2021-30573

GitHubkh4sh3i/cve-2021-30573

Proof-of-concept exploit for CVE-2021-30573, a use-after-free vulnerability in Google Chrome's GPU component allowing remote heap corruption via…

exploitationmemory-forensicsvulnerability-analysis+1
24 years ago
CVE-2017-8641_chakra_Js_GlobalObject preview

CVE-2017-8641_chakra_Js_GlobalObject

GitHubhomjxi0e/cve-2017-8641_chakra_js_globalobject

There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP.…

binary-exploitationexploitationmemory-forensics+3
19 years ago
Previous12Next