Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
137 results
CVE_2019_2215 preview

CVE_2019_2215

GitHub0xbinder/cve_2019_2215

Proof-of-concept LPE exploit for Android Binder UAF that uses iovec spraying and addr_limit overwrite to achieve arbitrary kernel read/write.

android-securitybinary-exploitationeducation+5
1
1 day ago
hp-slate7-root-kit preview

hp-slate7-root-kit

GitHubvalentineus/hp-slate7-root-kit

HP Slate 7 2800 Android 4.1.1 rooting kit using CVE-2015-1805.

android-securitybinary-exploitationexploitation+6
12 days ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubhackerronin/cve-2024-0044

a vulnerability affecting Android version 12 & 13

android-securityexploitationmobile-app-pentesting+3
62 years ago
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal preview

two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

GitHubhunt-benito/two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

android-securityexploitationmobile-app-pentesting+4
9 days ago
Firmware-analysis preview

Firmware-analysis

GitHubgimminse/firmware-analysis

Rediscovered CVE-2020-25279, a critical vulnerability in the Shannon baseband used in Samsung Exynos chipsets

binary-analysisembedded-systems-securityexploitation+3
10 days ago
spd_flasher preview

spd_flasher

GitHubleochen-coremind/spd_flasher

CVE-2022-38694 Hardened Exploit - RP2350 USB Host Auto Flasher for Unisoc devices

educationembedded-systems-securityexploitation+3
615 days ago
CVE-2026-22012-Diameter-Protocol-Credit-Control-Bypass-in-5G preview

CVE-2026-22012-Diameter-Protocol-Credit-Control-Bypass-in-5G

GitHubgeorge0papasotiriou/cve-2026-22012-diameter-protocol-credit-control-bypass-in-5g
exploitationmobile-securitynetwork-security+1
16 days ago
exploits preview

exploits

GitHubhackerhouse-opensource/exploits

exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House

binary-exploitationcurated-resourcesembedded-systems-security+7
4705 months ago
LGPwn preview

LGPwn

GitHubcunninglogic/lgpwn

LG Root Exploit

android-securityexploitationmobile-security+2
3613 years ago
frinet preview

frinet

GitHubsynacktiv/frinet

Frida-based tracer for easier reverse-engineering on Android, iOS, Linux, Windows and most related architectures.

binary-analysisdebuggersdynamic-analysis-sandboxing+3
6242 months ago
CVE-2026-20637-AppleSEPKeyStore-UAF preview

CVE-2026-20637-AppleSEPKeyStore-UAF

GitHub0xjohnnydev/cve-2026-20637-applesepkeystore-uaf

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

binary-exploitationexploitationios-security+2
551 month ago
CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions preview

CVE-2026-28992-IOHIDFamily-FastPathUserClient-Race-Conditions

GitHub0xjohnnydev/cve-2026-28992-iohidfamily-fastpathuserclient-race-conditions

UAF and AOP coprocessor panic in IOHIDEventServiceFastPathUserClient. No entitlements, reachable from app sandbox.

binary-exploitationexploitationios-security+5
141 month ago
WebKit-NavigationAPI-SOP-Bypass preview

WebKit-NavigationAPI-SOP-Bypass

GitHub0xjohnnydev/webkit-navigationapi-sop-bypass

WebKit NavigateEvent.canIntercept SOP bypass via cross-port interception — iOS 26.3.1 BSI (CVE-2026-20643)

binary-analysismobile-securityvulnerability-analysis+2
201 month ago
iOS18.6.2-Persistent-Automation-Exploit-in-Siri-Shortcuts-and-Apple-SWC preview

iOS18.6.2-Persistent-Automation-Exploit-in-Siri-Shortcuts-and-Apple-SWC

GitHubjgoyd/ios18.6.2-persistent-automation-exploit-in-siri-shortcuts-and-apple-swc

This repo documents a vulnerability in Siri Shortcuts and Shared Web Credentials (SWC) allowing malformed payloads to persistently execute, trigger…

exploitationios-securitylateral-movement+4
185 months ago
CVE-2026-0006-openapv-poc preview

CVE-2026-0006-openapv-poc

GitHubmobilehackinglab/cve-2026-0006-openapv-poc

CVE-2026-0006: Heap buffer overflow PoC for libopenapv (Android APV codec) - CVSS 9.8

android-securitybinary-exploitationcode-analysis+6
124 months ago
IoTGoat preview

IoTGoat

GitHubowasp/iotgoat

Deliberately insecure OpenWrt-based firmware for hands-on IoT security training. Features vulnerability challenges mapped to the OWASP IoT Top 10 for…

educationembedded-systems-securityfirmware-analysis+8
91810 months ago
iOS-Bluetooth-Ethernet-Exploit preview

iOS-Bluetooth-Ethernet-Exploit

GitHubf4r3sx0/ios-bluetooth-ethernet-exploit

iOS Bluetooth PAN vulnerability that opens USB port 62078 and displays Ethernet icon without any adapter (€0). Apple sells a €89.95 adapter for the…

bluetooth-securityeducationexploitation+8
32 months ago
mavd preview

mavd

GitHubustayready/mavd

Mobile Application Vulnerability Detection

android-securityinformation-gatheringmobile-app-pentesting+4
129 years ago
Previous12…8Next