Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
457 results
CVE-2015-2291 preview

CVE-2015-2291

GitHubgmh5225/cve-2015-2291

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a…

binary-exploitationeducationexploitation+3
5
4 years ago
CVE-2025-6018-6019 preview

CVE-2025-6018-6019

GitHubdesertdemons/cve-2025-6018-6019

CVE-2025-6018 CVE-2025-6019 PoC Exploit - Local Privilege Escalation in openSUSE/SUSE Linux Enterprise 15 - PAM bypass + udisks2 XFS race condition…

binary-exploitationeducationexploitation+4
55 months ago
CVE-2021-26832 preview

CVE-2021-26832

GitHubgal-nagli/cve-2021-26832

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…

educationpapers-researchvulnerability-analysis+2
55 years ago
CVE-2025-68434-OSPOS-CSRF preview

CVE-2025-68434-OSPOS-CSRF

GitHubnixon-h/cve-2025-68434-ospos-csrf

PoC & Write-up for CVE-2025-68434: Critical CSRF in OpenSourcePOS. Exploits a disabled filter configuration to allow unauthenticated attackers to…

educationexploitationpapers-research+3
32 months ago
CVE-2026-48908-Joomla-SP-Page-Builder-RCE preview

CVE-2026-48908-Joomla-SP-Page-Builder-RCE

GitHubimxur/cve-2026-48908-joomla-sp-page-builder-rce

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

educationpapers-researchvulnerability-analysis+1
227 days ago
nagios-xi-5.7.5-bugs preview

nagios-xi-5.7.5-bugs

GitHubfs0c-sh/nagios-xi-5.7.5-bugs

Bugs reported to Nagios XI

curated-resourceseducationpapers-research+2
55 years ago
CLFS preview

CLFS

GitHubbyt3n33dl3/clfs

it's a CVE-2023-28252 (Patched), but feel free to use it for check any outdated software or reseach

binary-exploitationeducationexploitation+2
62 years ago
CVE-2022-2590-analysis preview

CVE-2022-2590-analysis

GitHubhyeonjun17/cve-2022-2590-analysis

Dirty COW restricted to shmem in linux kernel

binary-exploitationeducationexploitation+2
62 years ago
CVE-2026-54121 preview

CVE-2026-54121

GitHubchpratik/cve-2026-54121

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

educationincident-responselog-analysis+4
124 days ago
CVE-2025-41088 preview

CVE-2025-41088

GitHubmarinafabregat/cve-2025-41088

Stored Cross-Site Scripting (XSS) in Xibo Signage's Xibo CMS v4.1.2, due to a lack of proper validation of user input.

educationexploitationpapers-research+3
59 months ago
NSEC3-Encloser-Attack preview

NSEC3-Encloser-Attack

GitHubgoethe-universitat-cybersecurity/nsec3-encloser-attack

This project generates DNS zonefiles with custom NSEC3 parameters to reproduce and evaluate the attacks in CVE-2023-50868.

dns-analysisdns-fuzzingeducation+3
62 years ago
CVE-2026-1208 preview

CVE-2026-1208

GitHubsnailsploit/cve-2026-1208

Friendly Functions for Welcart <= 1.2.5 - Cross-Site Request Forgery to Settings Update

educationexploitationpapers-research+3
3 months ago
CVE-2026-34213 preview

CVE-2026-34213

GitHub0xmrma/cve-2026-34213

A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside…

educationpapers-researchpenetration-testing+2
1 month ago
Transformers-Forged-To-Fight-Offline-Version preview

Transformers-Forged-To-Fight-Offline-Version

GitHubgeamztheangrybirds727/transformers-forged-to-fight-offline-version

TRANSFORMERS: Forged to Fight is a 3D combat game where you take over some of the most charismatic troopers straight out of the Transformers…

binary-analysisbinary-exploitationcurated-resources+5
21 month ago
CVE-2025-55182-React2Shell-RCE-POC preview

CVE-2025-55182-React2Shell-RCE-POC

GitHubrat5ak/cve-2025-55182-react2shell-rce-poc

This repository documents research into deserialization behavior within Next.js React Server Components (RSC) using the Flight protocol. It focuses…

code-analysiseducationexploitation+3
38 months ago
Jump-over-ASLR-BTB preview

Jump-over-ASLR-BTB

GitHubbytereaper77/jump-over-aslr-btb

jump over aslr attacking branch predictors to bypass aslr Technique

binary-exploitationeducationexploitation+2
411 months ago
libsafe-CVE-2005-1125 preview

libsafe-CVE-2005-1125

GitHubtagatac/libsafe-cve-2005-1125

Libsafe - Safety Check Bypass Vulnerability (Proof of Concept Exploit & Time Randomization to Thwart It)

binary-exploitationeducationexploitation+2
34 years ago
DirtyPipe-CVE-2022-0847 preview

DirtyPipe-CVE-2022-0847

GitHubvinukalana/dirtypipe-cve-2022-0847

This repository is developed to analysis and understand DirtyPipe exploit CVE-2022-0847

binary-exploitationeducationexploitation+3
24 years ago
Previous1…678…26Next