Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
fuzzilli preview

fuzzilli

GitHubgoogleprojectzero/fuzzilli

A JavaScript Engine Fuzzer

binary-analysiseducationfuzzing+2
2.3k5 days ago
egodeath preview

egodeath

GitHubnstarke/egodeath

A JavaScript Obfuscator based on Cryptographic Indistinguishability Obfuscation techniques

code-analysiseducationpapers-research+2
587 days ago
upb-any-recursion-audit preview

upb-any-recursion-audit

GitHubvardhan0257/upb-any-recursion-audit

Audit harness testing whether the CVE-2026-0994 Any-unwrapping recursion bug class affects upb's C core in Ruby and PHP protobuf bindings, with…

binary-analysiseducationfuzzing+4
11 days ago
obsidian-note-toolbar-PoC preview

obsidian-note-toolbar-PoC

GitHubsqueeze440/obsidian-note-toolbar-poc

PoC — frontmatter-driven arbitrary JavaScript execution in Note Toolbar for Obsidian (GHSA-q8cw-3m8c-5pf2, CVE-2026-87002, CVSS 7.0).

code-analysiseducationexploitation+5
18 days ago
CVE-2026-73319 preview

CVE-2026-73319

GitHubbombobombone/cve-2026-73319

Proof-of-concept exploit and technical write-up for CVE-2026-73319, a same-host javascript: URI XSS in XenForo before 2.3.13, including reproduction…

educationexploitationpapers-research+2
20 days ago
CVE-2026-74936-gc-potato preview

CVE-2026-74936-gc-potato

GitHubsneakynachos/cve-2026-74936-gc-potato

Reproduction of a WebAssembly use-after-free vulnerability in Mozilla's JavaScript engine, demonstrating a deterministic race condition and providing…

binary-analysisexploitationpapers-research+1
1 month ago
CVE-2026-34212 preview

CVE-2026-34212

GitHub0xmrma/cve-2026-34212

Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor…

educationexploitationpapers-research+3
3 months ago
CVE-2026-29971 preview

CVE-2026-29971

GitHubtharooon/cve-2026-29971

An attacker can execute arbitrary JavaScript in the victim's browser, potentially leading to session hijacking or privilege escalation.

educationpapers-researchpenetration-testing+3
4 months ago
CVE-2026-30691 preview

CVE-2026-30691

GitHubwalidriouah/cve-2026-30691

CVE-2026-30691: Stored Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer

educationpapers-researchvulnerability-analysis+2
4 months ago
CVE-2026-34621 preview

CVE-2026-34621

GitHubazefzafyoussef/cve-2026-34621

Research PoC demonstrating a prototype pollution and JavaScript injection chain in Adobe Acrobat Reader, enabling privileged JavaScript execution and…

binary-exploitationeducationexploitation+5
254 months ago
CVE-2021-21220 preview

CVE-2021-21220

GitHubborahll/cve-2021-21220

Educational presentation detailing the exploitation of CVE-2021-21220, a V8 JIT type confusion leading to OOB access and RCE via WebAssembly, with…

binary-exploitationeducationexploitation+3
4 months ago
CVE-2026-26903-PoC preview

CVE-2026-26903-PoC

GitHubjohn-jung/cve-2026-26903-poc

A PoC for demonstrating CVE-2026-26903

educationexploitationpapers-research+2
5 months ago
CVE-2026-34621 preview

CVE-2026-34621

GitHubercihan/cve-2026-34621

Technical analysis of Adobe Acrobat JavaScript trust boundary flaw, documenting native handler mappings and privilege-gating logic for CVE-2026-34621.

binary-analysisexploitationpapers-research+2
25 months ago
DesckVB-RAT preview

DesckVB-RAT

GitHubshadowopcode/desckvb-rat

Full analysis of a never documented before Remote Access Trojan linked to Pjoao1578 toolchain

command-and-controldigital-forensicseducation+8
97 months ago
CVE-2025-60656 preview

CVE-2025-60656

GitHubdotadrien/cve-2025-60656

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

educationpapers-researchvulnerability-analysis+2
8 months ago
CVE-2025-67730 preview

CVE-2025-67730

GitHubdharan10/cve-2025-67730

A public disclourse of CVE-2025-67730 in Frape lms By dharan ragunathan

educationpapers-researchvulnerability-analysis+2
9 months ago
CVE-2025-43541 preview

CVE-2025-43541

GitHubcrypt0bit/cve-2025-43541

PoC Exploit iOS

educationexploitationpapers-research+2
99 months ago
CVE-2025-10585-The-Chrome-V8-Zero-Day preview

CVE-2025-10585-The-Chrome-V8-Zero-Day

GitHubadityabhatt3010/cve-2025-10585-the-chrome-v8-zero-day

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

educationexploitationpapers-research+3
131 year ago
Previous12Next