Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
ai-kubernetes-helm-chart-security preview

ai-kubernetes-helm-chart-security

GitHubsorami-consulting-au/ai-kubernetes-helm-chart-security

Evidence and data for the Sorami technical report on security defaults of 15 AI serving, vector database and MCP Helm charts on Kubernetes.

ai-securitycloud-securityconfiguration-auditing+5
1
2 days ago
Kestra-cve-2026-53576 preview

Kestra-cve-2026-53576

GitHubatlasvector/kestra-cve-2026-53576

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

container-securityexploitationincident-response+8
3 days ago
ShadowMem preview

ShadowMem

GitHubzjuwyh/shadowmem

Defensive framework that maintains a safety-focused shadow memory to detect and block prompt-injection and long-horizon threats against LLM agents…

ai-securitydefensive-toolseducation+4
18 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubhassham1/cve-2026-87902

WordPress Core <= 7.1.1 unauthenticated LFI to RCE - validation lab, PoC, nuclei template (GHSA-7hp8-65ch-5whp)

educationexploitationlabs-practice+7
15 days ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
CVE-2026-29057-POC preview

CVE-2026-29057-POC

GitHublearnerxuan/cve-2026-29057-poc

Docker-based lab reproducing CVE-2026-29057 Next.js request smuggling, comparing vulnerable 15.5.12 against patched 15.5.13 with a raw chunked HTTP…

educationexploitationlabs-practice+5
4 days ago
CVE-2026-68121 preview

CVE-2026-68121

GitHubhorkimhab/cve-2026-68121

Proof-of-concept for CVE-2026-68121 (PPPoEject), providing a Python exploit implementation for authorized security research and lab testing.

educationexploitationlabs-practice+4
8 days ago
CVE-2026-74469 preview

CVE-2026-74469

GitHubhorkimhab/cve-2026-74469

Proof-of-concept and educational research repository for CVE-2026-74469 (DiagSpill), providing vulnerability analysis material for authorized lab…

ctfeducationexploitation+4
8 days ago
CVE-2026-81000 preview

CVE-2026-81000

GitHubhorkimhab/cve-2026-81000

Educational CVE-2026-81000 proof-of-concept repository for authorized security research, vulnerability awareness, and controlled lab testing.

educationexploitationlabs-practice+4
8 days ago
red-teaming-auto-mode preview

red-teaming-auto-mode

GitHubsafety-research/red-teaming-auto-mode

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

ai-securityeducationfuzzing+3
14 days ago
CVE-2026-77991 preview

CVE-2026-77991

GitHubabraxas/cve-2026-77991

Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

educationexploitationlabs-practice+6
110 days ago
CVE-2026-87796 preview

CVE-2026-87796

GitHubabraxas/cve-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

educationexploitationlabs-practice+6
110 days ago
rep-openai-artifactory preview

rep-openai-artifactory

GitHubalixiacf/rep-openai-artifactory

Forensic Analysis and Local Replication of the OpenAI-Artifactory Privilege Escalation Incident (CVE-2026-65616)

ai-securitycloud-securitycontainer-security+7
111 days ago
CVE-2026-19975 preview

CVE-2026-19975

GitHubhorkimhab/cve-2026-19975

Proof-of-concept and research repository for CVE-2026-19975 in Azuriom, with setup instructions and a linked technical writeup for authorized…

educationexploitationlabs-practice+3
12 days ago
CVE-2026-5430 preview

CVE-2026-5430

GitHubhorkimhab/cve-2026-5430

Educational CVE-2026-5430 research repository with proof-of-concept material for authorized security testing in isolated lab environments.

educationexploitationlabs-practice+2
13 days ago
CVE-2026-59346-POC preview

CVE-2026-59346-POC

GitHub0xcyberstan/cve-2026-59346-poc

PoC for CVE-2026-59346 - 32-bit integer overflow in VMware's VMXNET3 TSO segmentation path, guest-to-host crash.

binary-exploitationexploitationhardware-iot-security+3
113 days ago
CVE-2026-76461 preview

CVE-2026-76461

GitHubhorkimhab/cve-2026-76461

Educational security research repository for learning, testing, and researching CVE vulnerabilities and defensive practices in isolated lab…

ctfeducationexploitation+3
14 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
13 days ago
Previous1234567Next