Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
87 results
CVE-2026-59827 preview

CVE-2026-59827

GitHubc0gnit00/cve-2026-59827

Blog on CVE-2026-59827, Unsafe H2 query ouput deserialization

binary-exploitationeducationexploitation+3
2 months ago
marshalsec preview

marshalsec

GitHubmbechler/marshalsec

Java deserialization vulnerability exploitation tool with payload generators for multiple marshallers (Jackson, XStream, SnakeYAML) and JNDI…

educationexploitationpapers-research+5
3.7k1 year ago
CVE-2023-21716 preview

CVE-2023-21716

GitHubgyaansastra/cve-2023-21716

A vulnerability within Microsoft Office's wwlib allows attackers to achieve remote code execution with the privileges of the victim that opens a…

binary-exploitationeducationexploitation+3
596 days ago
kartlanpwn preview

kartlanpwn

GitHubchadhyatt/kartlanpwn

Technical analysis and proof-of-concept for CVE-2024-45200, a stack-based buffer overflow in Mario Kart 8 Deluxe's Pia P2P networking library,…

binary-exploitationeducationexploitation+2
641 year ago
CVE-2026-42779 preview

CVE-2026-42779

GitHubdinosn/cve-2026-42779

Proof-of-concept demonstrating a deserialization filter bypass in Apache MINA leading to remote code execution, with detailed root cause analysis,…

educationexploitationpapers-research+2
114 months ago
CVE-2025-69219 preview

CVE-2025-69219

GitHubsak110/cve-2025-69219

Proof-of-concept exploit for CVE-2025-69219, demonstrating remote code execution in Apache Airflow Providers HTTP via unsafe pickle deserialization.…

binary-exploitationeducationexploitation+3
76 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHubk3ystr0k3r/cve-2026-48907

CVE-2026-48907 – Joomla JCE Unauthenticated Remote Code Execution (RCE)

educationexploitationincident-response+8
42 months ago
CVE-2026-38526-KrayinCRM preview

CVE-2026-38526-KrayinCRM

GitHubish3ng0m4/cve-2026-38526-krayincrm

Authenticated Arbitrary File Upload leading to Remote Code Execution Technical analysis and controlled reproduction of CVE-2026-38526 in Webkul…

educationexploitationpapers-research+5
10 days ago
DNS-Mayhem-CVE-2026-41096-Deep-Dive preview

DNS-Mayhem-CVE-2026-41096-Deep-Dive

GitHubmrk336/dns-mayhem-cve-2026-41096-deep-dive

In‑depth technical analysis of CVE‑2026‑41096, a critical heap overflow in Windows DNSAPI.dll enabling remote code execution via crafted DNS…

dns-analysiseducationexploitation+4
44 months ago
React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web preview

React2Shell-CVE-2025-55182-The-Deserialization-Bug-That-Broke-the-Web

GitHubadityabhatt3010/react2shell-cve-2025-55182-the-deserialization-bug-that-broke-the-web

React2Shell, CVE-2025-55182, RCE Vulnerability: A critical breakdown of the unsafe deserialization flaw in React Server Components that enables…

ctfeducationexploitation+8
89 months ago
my-CVE-2021-1675 preview

my-CVE-2021-1675

GitHubhahaleyile/my-cve-2021-1675

Detailed analysis and exploit implementation for Windows PrintNightmare (CVE-2021-1675/34527) with RPC-based privilege escalation and remote code…

binary-exploitationeducationexploitation+4
35 years ago
PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability preview

PoC-and-yara-rules-of-CVE-2025-59528-Flowise-has-Remote-Code-Execution-vulnerability

GitHubhackpatato/poc-and-yara-rules-of-cve-2025-59528-flowise-has-remote-code-execution-vulnerability

Proof-of-concept exploit and YARA detection rules for CVE-2025-59528, a remote code execution vulnerability in Flowise, intended for authorized…

educationexploitationmalware-analysis+2
129 days ago
CVE-2021-26411 preview

CVE-2021-26411

GitHubcrackercat/cve-2021-26411

Proof-of-concept exploit for CVE-2021-26411, an Internet Explorer memory corruption vulnerability enabling remote code execution.

educationexploitationpapers-research+2
24 years ago
CVE-2024-32002-PoC preview

CVE-2024-32002-PoC

GitHubnishanthanand21/cve-2024-32002-poc

PoC of CVE-2024-32002 - Remote Code Execution while cloning special-crafted local repositories

educationexploitationpapers-research+2
32 years ago
CVE-2025-43300 preview

CVE-2025-43300

GitHubticofookfook/cve-2025-43300

Detailed technical analysis of CVE-2025-43300, a buffer overflow vulnerability in DNG file processing enabling remote code execution. Explains the…

binary-exploitationeducationexploitation+2
40 years ago
llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection preview

llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

GitHubhunt-benito/llama-factory-webui-rce-cve-2026-58116-trust-remote-code-model-path-injection

Proof-of-concept exploit for CVE-2026-58116 demonstrating remote code execution in LLaMA-Factory WebUI via trust_remote_code model path injection.…

code-analysisctfeducation+5
2 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubphucc29/cve-2025-55182

Proof-of-concept exploit demonstrating remote code execution via insecure deserialization in React Flight protocol (CVE-2025-55182). Includes Snort…

educationexploitationpapers-research+2
2 months ago
CVE-2026-33937 preview

CVE-2026-33937

GitHubeqstlab/cve-2026-33937

Handlebars.js AST Injection Remote Code Execution Vulnerability

educationexploitationlabs-practice+5
25 months ago
Previous12345Next