Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
CVE-2026-63292 preview

CVE-2026-63292

GitHub0xblackash/cve-2026-63292

Documents CVE-2026-63292, a stack-based buffer overflow in Apache mod_vhost_alias, with affected versions, safe version and configuration checks, and…

configuration-auditingdefensive-toolseducation+4
3 days ago
CVE-2026-103648 preview

CVE-2026-103648

GitHubeternullsec/cve-2026-103648

Advisory and PoC for CVE-2026-103648, a path traversal (CWE-22) in image-downloader 4.3.0 enabling arbitrary file write, with root-cause analysis,…

educationexploitationlabs-practice+6
2 days ago
CVE-2026-100380 preview

CVE-2026-100380

GitHubbombobombone/cve-2026-100380

PoC and patch verification notes for CVE-2026-100380, a reflected XSS in Wikibase language-validation error pages, with a script that detects…

exploitationpapers-researchvulnerability-analysis+2
6 days ago
CVE-2026-86950 preview

CVE-2026-86950

GitHub0xblackash/cve-2026-86950

Defensive research documentation for CVE-2026-86950, an Apple CoreGraphics out-of-bounds write, covering vulnerability triage, affected versions,…

defensive-toolseducationincident-response+4
15h 25m ago
onelogon preview

onelogon

GitHubrub-softsec/onelogon

Code and data for our paper "Onelogon: Taking over Active Directory Accounts via Netlogon" (WOOT’26).

authenticationexploitationnetwork-security+4
1261 month ago
ResourcePoison preview

ResourcePoison

GitHubmichalbednarski/resourcepoison

Writeup and exploit for CVE-2025-22441: Privilege escalation from installed app to SystemUI process on Android due to pass of untrusted…

android-securityexploitationmobile-security+3
1080 years ago
CVE-2026-28576-poc preview

CVE-2026-28576-poc

GitHubmobilehackinglab/cve-2026-28576-poc

Educational proof-of-concept demonstrating a SQL injection vulnerability in Android 17's Contacts Provider, allowing a zero-permission app to…

android-securityeducationexploitation+4
4228 days ago
TheLastBundleMismatch preview

TheLastBundleMismatch

GitHubmichalbednarski/thelastbundlemismatch

Writeup and exploit for CVE-2023-45777, bypass for Intent validation inside AccountManagerService on Android 13 despite "Lazy Bundle" mitigation

android-securitybinary-analysisexploitation+2
1012 years ago
CVE-2023-36884-MS-Office-HTML-RCE preview

CVE-2023-36884-MS-Office-HTML-RCE

GitHubjakabakos/cve-2023-36884-ms-office-html-rce

MS Office and Windows HTML RCE (CVE-2023-36884) - PoC and exploit

educationexploitationpapers-research+3
412 years ago
FLAWED preview

FLAWED

GitHuboff-by-1-labs/flawed

Fix-Like Artifacts With Embedded Defects

ai-securitycode-analysisdefensive-tools+8
242 months ago
apache-activemq-rce-research preview

apache-activemq-rce-research

GitHubdinosn/apache-activemq-rce-research

Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings + Crowdfense comparison

educationexploitationpapers-research+4
93 months ago
CVE-2025-24054_CVE-2025-24071-PoC preview

CVE-2025-24054_CVE-2025-24071-PoC

GitHubhelidem/cve-2025-24054_cve-2025-24071-poc

Proof of Concept for the NTLM Hash Leak via .library-ms CVE-2025-24054 / CVE-2025-24071

educationexploitationlabs-practice+5
2211 months ago
CVE-2024-21338-Exploit preview

CVE-2024-21338-Exploit

GitHubmistyfir/cve-2024-21338-exploit

Proof-of-concept exploit for CVE-2024-21338, a Windows AppLocker driver (appid.sys) privilege escalation vulnerability used by Lazarus group as a…

binary-exploitationeducationexploitation+3
76 months ago
CVE-2025-10585-The-Chrome-V8-Zero-Day preview

CVE-2025-10585-The-Chrome-V8-Zero-Day

GitHubadityabhatt3010/cve-2025-10585-the-chrome-v8-zero-day

Google patched CVE-2025-10585, a Chrome V8 zero-day under active exploitation — here’s what it is, why it matters, and how to stay safe.

educationexploitationpapers-research+3
131 year ago
CVE-2026-28956-jxl-messages-surface preview

CVE-2026-28956-jxl-messages-surface

GitHubeddinos2/cve-2026-28956-jxl-messages-surface

iOS Messages JPEG XL delivery-surface probe and patch-diff notes for CVE-2026-28956.

exploitationios-securitymalware-analysis+3
1 month ago
autofs-cve-2026-84568 preview

autofs-cve-2026-84568

GitHubjvidhan/autofs-cve-2026-84568

Reverse engineering notes and working PoC for CVE-2026-84568, a macOS automountd trust-boundary violation allowing mounts from localhost or the…

binary-analysiseducationexploitation+4
114 days ago
cve-2026-25541-fuel-analysis preview

cve-2026-25541-fuel-analysis

GitHubtrajanox/cve-2026-25541-fuel-analysis

CVE-2026-25541 impact analysis for Fuel infrastructure (bytes crate integer overflow)

code-analysiscurated-resourceseducation+3
13 months ago
CVE-2024-38063 preview

CVE-2024-38063

GitHubfaizan-khanx/cve-2024-38063

CVE-2024-38063 - Remotely Exploiting The Kernel Via IPv6

binary-exploitationeducationexploitation+5
12 years ago
Previous123Next