Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
67 results
CVE-2025-66204 preview

CVE-2025-66204

GitHublukasz-rybak/cve-2025-66204

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

authenticationeducationpapers-research+3
5 months ago
CVE-2022-24992 preview

CVE-2022-24992

GitHubesistferry/cve-2022-24992

Proof-of-concept for CVE-2022-24992, a path traversal vulnerability in QRCDR's QR-Code generator script, with technical write-up and exploitation…

educationexploitationpapers-research+2
10 months ago
CVE-2026-0897 preview

CVE-2026-0897

GitHubhyperps/cve-2026-0897

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms…

educationexploitationmalware-analysis+2
5 months ago
CVE-2026-666 preview

CVE-2026-666

GitHubadriangigliotti/cve-2026-666

Educational proof-of-concept for CVE-2026-666, a remote code execution vulnerability in ShadowWeb Framework's deserialization, with technical details…

educationexploitationpapers-research+2
18 months ago
CVE-2025-25618 preview

CVE-2025-25618

GitHubarmaansidana2003/cve-2025-25618

Proof-of-concept demonstrating incorrect access control in Unifiedtransform v2.0, allowing teachers to modify section details. Includes step-by-step…

educationpapers-researchpenetration-testing+2
1 year ago
MOVEit-CVE-2023-34362 preview

MOVEit-CVE-2023-34362

GitHubchinyemba-ck/moveit-cve-2023-34362

A video presentation analysing the technical details, scale and lessons to be learned from the MOVEit CVE-2023=3462(CS50 Introduction to Cyber…

curated-resourceseducationpapers-research+2
2 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xb1lal/cve-2025-29927

Advisory and information hub for the Next.js middleware authorization bypass CVE-2025-29927, including a link to technical analysis and details.

educationexploitationpapers-research+2
1 year ago
CVE-2026-48030 preview

CVE-2026-48030

GitHubmuslimbek-0x/cve-2026-48030

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

code-analysiseducationexploitation+3
3 months ago
CVE-2026-23499 preview

CVE-2026-23499

GitHublukasz-rybak/cve-2026-23499

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

educationpapers-researchvulnerability-analysis+2
5 months ago
CVE-2025-26206 preview

CVE-2025-26206

GitHubxibhi/cve-2025-26206

A critical Cross-Site Request Forgery (CSRF) vulnerability in Sell Done Storefront v.1.0. Discovered by B. Sibhi

educationpapers-researchvulnerability-analysis+2
1 year ago
CVE-2021-41081 preview

CVE-2021-41081

GitHubsudaiv/cve-2021-41081

N-DAY VULNERABILITY RESEARCH (FROM PATCH TO EXPLOIT ANALYSIS OF CVE-2021-41081)

binary-analysiseducationexploitation+2
4 years ago
ZombieVPN preview

ZombieVPN

GitHub0xsha/zombievpn

PoC and technical analysis for CVE-2020-12828, including reproduction steps and vulnerability details for security researchers.

educationexploitationpapers-research+2
286 years ago
CVE-2025-65094 preview

CVE-2025-65094

GitHublukasz-rybak/cve-2025-65094

Proof-of-concept for CVE-2025-65094: privilege escalation via IDOR in WBCE CMS. Demonstrates group ID manipulation to gain admin access, with…

educationpapers-researchpenetration-testing+3
5 months ago
CVE-2023-37190 preview

CVE-2023-37190

GitHubsahiloj/cve-2023-37190

A Stored Cross-Site Scripting (XSS) vulnerability exists in Issabel-PBX version 4.0.0-6. The application fails to properly sanitize and encode…

educationexploitationpapers-research+3
17 months ago
CVE-2025-67876 preview

CVE-2025-67876

GitHublukasz-rybak/cve-2025-67876

Detailed CVE-2025-67876 proof-of-concept demonstrating stored XSS in ChurchCRM group role names leading to admin session hijacking, with full…

educationexploitationpapers-research+3
5 months ago
CVE-2025-66628 preview

CVE-2025-66628

GitHubsumitshah00/cve-2025-66628

Technical analysis of CVE-2025-66628, an integer overflow in ImageMagick's TIM parser leading to out-of-bounds reads, with root cause, exploitation…

binary-analysiscode-analysiseducation+4
19 months ago
CVE-2026-0847 preview

CVE-2026-0847

GitHubhyperps/cve-2026-0847

A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including…

educationexploitationpapers-research+3
5 months ago
CVE-2026-74469 preview

CVE-2026-74469

GitHub0xblackash/cve-2026-74469

Research repository for CVE-2026-74469 (DiagSpill), a Linux kernel SCTP peer transport counter overflow causing an out-of-bounds write, with PoC,…

binary-exploitationeducationexploitation+5
2 days ago
Previous1234Next