Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
162 results
CVE-2026-102971 preview

CVE-2026-102971

GitHubbombobombone/cve-2026-102971

Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs.

exploitationinformation-gatheringpapers-research+3
5 days ago
AI-Infra-Guard preview

AI-Infra-Guard

GitHubtencent/ai-infra-guard

A full-stack AI Red Teaming platform securing AI ecosystems via Agent Scan, Skills Scan, MCP scan, AI Infra scan and LLM jailbreak evaluation.

ai-securitycloud-securitycontainer-security+7
6.8k2 days ago
MMSkillRisk preview

MMSkillRisk

GitHubkaill-jlq/mmskillrisk

Benchmark and evaluation harness testing whether LLM agents resist malicious instructions hidden in multimodal skill images, with 108 cases across…

adversarial-attackai-securitydata-exfiltration+7
25 days ago
cvelistV5 preview

cvelistV5

GitHubcveproject/cvelistv5

CVE cache of the official CVE List in CVE JSON 5 format

curated-resourceseducationinformation-gathering+3
3.0k6 days ago
ehids-agent preview

ehids-agent

GitHubgojue/ehids-agent

A Linux Host-based Intrusion Detection System based on eBPF.

container-escapedefensive-toolsdns-analysis+5
4582 years ago
Iran-War-Media preview

Iran-War-Media

GitHubalbintouma/iran-war-media

Iran War Media Monitor collects news articles covering the US-Israeli war on Iran and applies sentiment analysis to uncover who supports and opposes…

crawlereducationinformation-gathering+3
192 months ago
zotlit-PoC preview

zotlit-PoC

GitHubsqueeze440/zotlit-poc

PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

data-exfiltrationexploitationinformation-gathering+3
24 days ago
CVE-2026-79551-Tenda preview

CVE-2026-79551-Tenda

GitHubsnyi001/cve-2026-79551-tenda

Tenda Technology Co., Ltd NVR_4H: CH3 v2.1.V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

cryptographyembedded-systems-securityfirmware-analysis+6
20 days ago
cve-2024-23897-jenkins-poc preview

cve-2024-23897-jenkins-poc

GitHubrivaedoardo62-boop/cve-2024-23897-jenkins-poc

Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.

educationexploitationpapers-research+3
3 months ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
121 month ago
liferay-ga4-rce-research preview

liferay-ga4-rce-research

GitHubdinosn/liferay-ga4-rce-research

Security research on Liferay CE 7.0.3 GA4: pre-auth RCE as root (CVE-2020-7961 class) reproduced end-to-end, plus 16 more findings — 8+ with no known…

dynamic-analysis-sandboxingexploitationpapers-research+6
72 months ago
CVE-2026-42533 preview

CVE-2026-42533

GitHubivanesk315/cve-2026-42533

Docker lab reproducing CVE-2026-42533, a pre-auth nginx heap overflow and info leak via two-pass capture clobbering, with PoC scripts and patched…

educationexploitationfuzzing+6
25 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
20 days ago
postgresql-cve-2026-14662 preview

postgresql-cve-2026-14662

GitHubkihara-1/postgresql-cve-2026-14662

PostgreSQL の全文検索(tsvector/tsquery)に見つかった範囲外書き込み脆弱性 CVE-2026-14662 を、修正前(18.4)と修正後(18.6)を Docker で並べて動かして検証した記録と発表資料

curated-resourcesdatabase-securityeducation+3
1 month ago
chub-supply-chain-poc preview

chub-supply-chain-poc

GitHubmickmicksh/chub-supply-chain-poc

Silent dependency injection through AI documentation pipelines. 240 isolated Docker runs proving Context Hub's zero-sanitization MCP server lets…

ai-securitycode-analysiseducation+5
46 months ago
CVE-2026-87796 preview

CVE-2026-87796

GitHubabraxas/cve-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

educationexploitationlabs-practice+6
15 days ago
CVE-2026-77991 preview

CVE-2026-77991

GitHubabraxas/cve-2026-77991

Proof-of-concept and lab pack for CVE-2026-77991, a privileged PHP file-write RCE in Joomla Event Manager through 5.0.0, with Docker lab and witness…

educationexploitationlabs-practice+6
15 days ago
CVE-2022-22965-spring4shell preview

CVE-2022-22965-spring4shell

GitHubcxzero/cve-2022-22965-spring4shell

Spring4Shell (CVE-2022-22965) proof-of-concept with Docker lab, detailed vulnerability analysis, and debugging setup for educational exploitation…

educationexploitationlabs-practice+3
12 years ago
Previous12…9Next