Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
TheLastBundleMismatch preview

TheLastBundleMismatch

GitHubmichalbednarski/thelastbundlemismatch

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

android-securitybinary-analysisexploitation+2
101
2 years ago
ResourcePoison preview

ResourcePoison

GitHubmichalbednarski/resourcepoison

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

android-securityexploitationmobile-security+3
1080 years ago
FLAWED preview

FLAWED

GitHuboff-by-1-labs/flawed

Fix-Like Artifacts With Embedded Defects

ai-securitycode-analysisdefensive-tools+8
242 months ago
CVE-2026-74469 preview

CVE-2026-74469

GitHub0xblackash/cve-2026-74469

Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC,…

binary-exploitationeducationexploitation+5
7 days ago
ghost-hoock preview

ghost-hoock

GitHubgenksome/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
421 days ago
CVE-2019-1068 preview

CVE-2019-1068

GitHubvulnerability-playground/cve-2019-1068

Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.

binary-exploitationeducationexploitation+3
14 years ago
CVE-2025-10585-The-Chrome-V8-Zero-Day preview

CVE-2025-10585-The-Chrome-V8-Zero-Day

GitHubadityabhatt3010/cve-2025-10585-the-chrome-v8-zero-day

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

educationexploitationpapers-research+3
131 year ago
CVE-2026-85046 preview

CVE-2026-85046

GitHubatiilla/cve-2026-85046

Proof-of-concept and technical analysis for CVE-2026-85046, a V8 type confusion in inline Array.prototype.sort, including root cause, patch diff, and…

binary-analysiseducationexploitation+3
827 days ago
ghost-hoock preview

ghost-hoock

GitHubdeaurity/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
120 days ago
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day preview

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

android-securityeducationexploitation+7
318 days ago
CVE-2026-28956-jxl-messages-surface preview

CVE-2026-28956-jxl-messages-surface

GitHubeddinos2/cve-2026-28956-jxl-messages-surface

iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.

exploitationios-securitymalware-analysis+3
1 month ago
CVE-2026-80844 preview

CVE-2026-80844

GitHub0xblackash/cve-2026-80844

Research repository for CVE-2026-80844 (DirtyAH6), a Linux kernel IPv6 AH6/XFRM local privilege escalation, with PoC, root-cause and patch analysis.

binary-exploitationeducationexploitation+3
7 days ago
ai-vuln-rediscovery-nginx-cve-2026-42945 preview

ai-vuln-rediscovery-nginx-cve-2026-42945

GitHubchamsbouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

Reproducible AI-assisted vulnerability rediscovery of CVE-2026-42945 in nginx, including technical analysis, PoC trigger, and patch validation for…

ai-securitybinary-exploitationeducation+3
4 months ago
CVE-2023-52356-libtiff-analysis preview

CVE-2023-52356-libtiff-analysis

GitHubyardenbenita/cve-2023-52356-libtiff-analysis

Root-cause analysis and patch validation of CVE-2023-52356 in libtiff using AddressSanitizer and GDB.

binary-analysisdebuggerseducation+2
28 days ago
CVE-2023-36884-MS-Office-HTML-RCE preview

CVE-2023-36884-MS-Office-HTML-RCE

GitHubjakabakos/cve-2023-36884-ms-office-html-rce

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

educationexploitationpapers-research+3
412 years ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubgrayxploit/cve-2026-48907

Proof-of-concept exploit and technical analysis for CVE-2026-48907, a CVSS 10.0 pre-authentication remote code execution vulnerability in the Joomla…

educationexploitationpapers-research+4
3 months ago
VLC_CVE-2021-25804_Analysis preview

VLC_CVE-2021-25804_Analysis

GitHubdshankle/vlc_cve-2021-25804_analysis

In-depth technical analysis of CVE-2021-25804, a VLC AVI parser vulnerability. Includes root cause, patch diff, and exploitation primitives for…

binary-analysiscode-analysiseducation+3
4 years ago
CVE-2025-60719-AFD.SYS preview

CVE-2025-60719-AFD.SYS

GitHubakamai/cve-2025-60719-afd.sys

Proof-of-concept and root-cause analysis of CVE-2025-60719, a use-after-free vulnerability in Windows afd.sys leading to local privilege escalation,…

ai-assisted-reversingbinary-exploitationeducation+3
49 months ago
Previous123Next