Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
476 results
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.6k
27 days ago
http-terminator preview

http-terminator

GitHubportswigger/http-terminator

AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms…

ai-securityexploitationfuzzing+8
1242 months ago
CVE-2025-7461 preview

CVE-2025-7461

GitHubbx33661/cve-2025-7461

Detailed analysis of CVE-2025-7461, a SQL injection vulnerability in Modern Bag E-commerce System, including root cause, affected code, and…

educationpapers-researchvulnerability-analysis+1
41 year ago
CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal preview

CVE-2026-87902-A-working-PoC-for-WordPress-s-critical-path-traversal

GitHubrabakuku/cve-2026-87902-a-working-poc-for-wordpress-s-critical-path-traversal

Reference notes and mitigation configs for CVE-2026-87902, a WordPress Core unauthenticated path traversal and LFI flaw chainable to RCE, with Nginx,…

defensive-toolseducationpapers-research+3
17 days ago
PoC-in-GitHub preview

PoC-in-GitHub

GitHubnomi-sec/poc-in-github

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

curated-resourcesexploitationinformation-gathering+7
8.1k3h 54m ago
Firefox-CVE-2024-9680 preview

Firefox-CVE-2024-9680

GitHubtdonaworth/firefox-cve-2024-9680

Educational analysis of CVE-2024-9680, a use-after-free vulnerability in Firefox's CSS Animation Timeline, with detailed exploit mechanics and…

binary-exploitationeducationexploitation+3
111 year ago
advisory preview

advisory

GitHubcarlosalbertotuma/advisory

Public security advisories and PoCs for vulnerabilities discovered in open-source web software, with root-cause analysis, CVE references,…

code-analysiscurated-resourceseducation+7
212 days ago
file-notification-attacks preview

file-notification-attacks

GitHubisec-tugraz/file-notification-attacks

Research artifacts for file-notification side-channel attacks on Linux, Windows, and macOS, demonstrating inotify/FSEvents leakage, keystroke timing,…

android-securityeducationexploitation+6
1218 days ago
polytracker preview

polytracker

GitHubtrailofbits/polytracker

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

binary-analysisdynamic-code-analysiseducation+4
5994 months ago
h2spacex preview

h2spacex

GitHubnxenon/h2spacex

HTTP/2 Last Frame Synchronization (also known as Single Packet Attack) low Level Library / Tool based on Scapy‌ + Exploit Timing Attacks

exploitationfuzzingnetwork-security+6
2293 months ago
splitting-the-email-atom preview

splitting-the-email-atom

GitHubportswigger/splitting-the-email-atom

Research materials and tooling for exploiting email address parser discrepancies to bypass access controls, including fuzzers, Hackvertor tags, CSS…

ctfeducationemail-security+7
9910 months ago
CVE-2021-38297 preview

CVE-2021-38297

GitHubgkrishnan724/cve-2021-38297

A Proof of concept scenario for exploitation of CVE2021-38297 GO WASM buffer-overflow

binary-exploitationctfeducation+5
82 years ago
CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http- preview

CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-

GitHubtheopaid/cve-2026-66752-http-request-smuggling-via-unparsed-transfer-encoding-values-tiny_http-

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

papers-researchvulnerability-analysisweb-application-exploitation+1
2 months ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubthemehackers/cve-2025-54100

CVE-2025-54100 (CVSS 7.8 High) is a command injection vulnerability in the Invoke-WebRequest cmdlet of Windows PowerShell 5.1. It arises from…

educationexploitationpapers-research+3
3110 months ago
CVE-2025-52399-SQLi-Institute-of-Current-Students preview

CVE-2025-52399-SQLi-Institute-of-Current-Students

GitHubuserr404/cve-2025-52399-sqli-institute-of-current-students

Proof-of-concept exploit for CVE-2025-52399, demonstrating SQL injection in the loginlinkfaculty endpoint of Institute-of-Current-Students, enabling…

educationexploitationpapers-research+3
11 year ago
strutt-cve-2014-0114 preview

strutt-cve-2014-0114

GitHubaenlr/strutt-cve-2014-0114

Technical analysis and proof-of-concept for Apache Struts 1 class parameter manipulation (CVE-2014-0114), demonstrating remote code execution on…

educationexploitationpapers-research+3
27 years ago
CVE-2023-38831 preview

CVE-2023-38831

GitHubmishra0230/cve-2023-38831

CVE-2023-38831 - WinRAR

binary-exploitationeducationexploitation+8
8 months ago
CVE-2026-34213 preview

CVE-2026-34213

GitHub0xmrma/cve-2026-34213

A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside…

educationpapers-researchpenetration-testing+2
3 months ago
Previous12…27Next