Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
457 results
CVE-2026-35031 preview

CVE-2026-35031

GitHubkeraattin/cve-2026-35031

Critical path traversal to RCE vulnerability in Jellyfin Media Server (CVSS 9.9). Includes proof-of-concept exploit, technical analysis, and…

educationexploitationpapers-research+5
2
4 months ago
PGP-client-checker-CVE-2021-33560 preview

PGP-client-checker-CVE-2021-33560

GitHubibm/pgp-client-checker-cve-2021-33560

Tool to check whether a PGP client is affected by CVE-2021-33560

cryptographyeducationencryption-decryption-tools+2
111 months ago
Supply-Chain preview

Supply-Chain

GitLabtoxicbishop/supply-chain

A comprehensive guide to software supply chain security. This open-source manuscript provides security professionals and developers with practical…

curated-resourceseducationlearning-paths-courses+2
12 months ago
CVE-2022-44268-MagiLeak preview

CVE-2022-44268-MagiLeak

GitHubadhikara13/cve-2022-44268-magileak

Tools for working with ImageMagick to handle arbitrary file read vulnerabilities. Generate, read, and apply profile information to PNG files using a…

educationexploitationpapers-research+2
23 years ago
CVE-2024-38063 preview

CVE-2024-38063

GitHubth3tr1ckst3r/cve-2024-38063

CVE-2024-38063 research so you don't have to.

curated-resourceseducationexploitation+3
21 year ago
CVE-2025-67876 preview

CVE-2025-67876

GitHublukasz-rybak/cve-2025-67876

CVE-2025-67876 - ChurchCRM has Stored XSS in Group Role Name Leading to Admin Session Hijacking

educationexploitationpapers-research+3
4 months ago
CVE-2025-4138 preview

CVE-2025-4138

GitHublocalh0ste/cve-2025-4138

Tarfile module directory traversal vulnerability ( with overflow crossed Directory ) --> Lead to Privilege escalation

binary-exploitationeducationexploitation+3
6 months ago
CVE-2025-63419 preview

CVE-2025-63419

GitHubmmakingdom/cve-2025-63419

CrushFTP before 11.3.7_60 is vulnerable to HTML Injection. The Web-Based Server has a feature where users can share files, the feature reflects the…

educationpapers-researchvulnerability-analysis+2
28 months ago
CVE-2025-60791 preview

CVE-2025-60791

GitHubsmarttfoxx/cve-2025-60791

Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application leaves valid device-bound…

debuggerseducationexploitation+3
210 months ago
CVE-2026-23499 preview

CVE-2026-23499

GitHublukasz-rybak/cve-2026-23499

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

educationpapers-researchvulnerability-analysis+2
4 months ago
conti-ransomware-writeup preview

conti-ransomware-writeup

GitHubjustjeff211/conti-ransomware-writeup

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…

digital-forensicseducationforensics+6
4 months ago
CVE-2025-65094 preview

CVE-2025-65094

GitHublukasz-rybak/cve-2025-65094

CVE-2025-65094 - WBCE CMS is Vulnerable to Privilege Escalation via Group ID Manipulation (IDOR)

educationpapers-researchpenetration-testing+3
4 months ago
CVE-2025-66024 preview

CVE-2025-66024

GitHublukasz-rybak/cve-2025-66024

CVE-2025-66024 - XWiki Blog Application home page vulnerable to Stored XSS via Post Title

educationpapers-researchvulnerability-analysis+2
4 months ago
CVE-2021-23383 preview

CVE-2021-23383

GitHubfazilbaig1/cve-2021-23383

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from…

code-analysiseducationpapers-research+2
21 year ago
CVE-2023-37190 preview

CVE-2023-37190

GitHubsahiloj/cve-2023-37190

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

educationexploitationpapers-research+3
16 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubdevianntsec/cve-2025-55182

Advanced security research on CVE-2025-55182 (React2Shell). Features an exploitation framework with 6 functional impact scenarios (RCE to Secret…

educationexploitationexploit-frameworks+8
14 months ago
MOVEit-Transfer-Data-Breach-Analysis. preview

MOVEit-Transfer-Data-Breach-Analysis.

GitHubtubaaiftikhar-ui/moveit-transfer-data-breach-analysis.

​Detailed analysis of the 2023 MOVEit Transfer data breach (CVE-2023-34362) for CS50 Cybersecurity. This project explores the technical impact of…

database-securityeducationincident-response+3
5 months ago
CVE-2023-38831-WinRAR-Vulnerability-Analysis preview

CVE-2023-38831-WinRAR-Vulnerability-Analysis

GitHubolowostandard1/cve-2023-38831-winrar-vulnerability-analysis

This project is a cybersecurity research and analysis project focused on CVE-2023-38831, a critical WinRAR vulnerability that allows attackers to…

educationexploitationlabs-practice+3
13 months ago
Previous1…789…26Next