Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
58 results
DirtyPipe-Exploit preview

DirtyPipe-Exploit

GitHubkaranlvm/dirtypipe-exploit

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe) enabling local privilege escalation on Linux kernels 5.8 through 5.16.10 by overwriting…

binary-exploitationeducationexploitation+3
2
10 months ago
distributed-system-testing preview

distributed-system-testing

GitHubshenli/distributed-system-testing

AI-agent skills for distributed-systems testing

ai-securitychaos-engineeringcurated-resources+4
2301 month ago
CVE-2026-51788 preview

CVE-2026-51788

GitHubaykhan32/cve-2026-51788

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

authenticationeducationemail-security+3
2 months ago
CVE-2025-70600---Urve-Smart-Office---Stored-XSS-in-iOS-App preview

CVE-2025-70600---Urve-Smart-Office---Stored-XSS-in-iOS-App

GitHubgpheheise/cve-2025-70600---urve-smart-office---stored-xss-in-ios-app

Proof-of-concept for a stored cross-site scripting (XSS) vulnerability in the URVE Smart Office iOS app, with CVE details, impact analysis, and…

educationios-securitymobile-security+3
7 months ago
CVE-2026-48030 preview

CVE-2026-48030

GitHubmuslimbek-0x/cve-2026-48030

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

code-analysiseducationexploitation+3
3 months ago
CVE-2025-50461 preview

CVE-2025-50461

GitHubanchor0221/cve-2025-50461

Technical Details and Exploit for CVE-2025-50461

binary-exploitationeducationexploitation+3
1 year ago
Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit preview

Hoverfly-1.11.3-RCE-CVE-2025-54123-Exploit

GitHub0x00phantom-hat/hoverfly-1.11.3-rce-cve-2025-54123-exploit

Exploit for CVE-2025-54123, an authenticated OS command injection in Hoverfly's middleware API, providing check-only, single-command, interactive…

command-and-controleducationexploitation+6
13 months ago
CVE-2025-65640 preview

CVE-2025-65640

GitHubvincenzo-emanuele/cve-2025-65640

Public advisory for CVE-2025-65640: Stored XSS vulnerability in Globe Document Intelligence.

educationpapers-researchpenetration-testing+3
103 months ago
CVE-2025-65094 preview

CVE-2025-65094

GitHublukasz-rybak/cve-2025-65094

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

educationpapers-researchpenetration-testing+3
4 months ago
CVE-2026-31278 preview

CVE-2026-31278

GitHubmda1r/cve-2026-31278

CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2

exploitationnetwork-securitypapers-research+3
2 months ago
Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis preview

Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis

GitHubkaandemir993/salat-stealer-telegram-proxy-decoy-c2-analysis

"Reverse engineering analysis of Salat Stealer, a Go-based info-stealer that uses a Telegram proxy decoy, C2 communication, and encrypted memory…

binary-analysiscommand-and-controleducation+6
51 month ago
CVE-2025-47423 preview

CVE-2025-47423

GitHubhaluka92/cve-2025-47423

Detailed disclosure of CVE-2025-47423: Local File Inclusion in Personal Weather Station Dashboard 12_lts. Includes PoC, vulnerable code analysis, and…

curated-resourceseducationexploitation+3
23 days ago
CVE-2025-66204 preview

CVE-2025-66204

GitHublukasz-rybak/cve-2025-66204

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

authenticationeducationpapers-research+3
4 months ago
CVE-2025-66024 preview

CVE-2025-66024

GitHublukasz-rybak/cve-2025-66024

Proof-of-concept for CVE-2025-66024: Stored XSS in XWiki Blog Application via unescaped post title in HTML title tag. Includes reproduction steps,…

educationpapers-researchvulnerability-analysis+2
4 months ago
CVE-2025-67221 preview

CVE-2025-67221

GitHubkpatsakis/cve-2025-67221

Documentation and reproduction code for CVE-2025-67221, a denial-of-service vulnerability in orjson's dumps() function caused by uncontrolled…

code-analysiseducationpapers-research+1
17 months ago
Flowise-RCE-CVE-2025-59528 preview

Flowise-RCE-CVE-2025-59528

GitHubr3nsi15/flowise-rce-cve-2025-59528

Authenticated Remote Code Execution (RCE) exploit for Flowise AI versions ≤ 3.0.4. Leverages a vulnerability in the…

educationexploitationpapers-research+4
14 months ago
CVE-2025-64720-PoC preview

CVE-2025-64720-PoC

GitHubdantsco/cve-2025-64720-poc

Proof-of-concept exploit for CVE-2025-64720, a libpng buffer overflow in palette premultiplication. Includes exploit generator, test harness with…

binary-analysiseducationexploitation+4
8 months ago
CVE-2024-34328 preview

CVE-2024-34328

GitHub0xsu3ks/cve-2024-34328

Proof-of-concept for open redirection via Host header manipulation in Sielox AnyWare 2.1.2 (CVE-2024-34328), with exploit steps, impact, and…

educationpapers-researchphishing+2
1 year ago
Previous1234Next