Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
54 results
CVE-2019-1068 preview

CVE-2019-1068

GitHubvulnerability-playground/cve-2019-1068

Root cause analysis and PoC for a Microsoft SQL Server Stack Overflow Vulnerability by reversing svl.dll.

binary-exploitationeducationexploitation+3
1
4 years ago
CVE-2024-0044 preview

CVE-2024-0044

GitHubcanyie/cve-2024-0044

Proof-of-concept and writeup for bypassing the initial patch of CVE-2024-0044, an Android framework vulnerability enabling privilege escalation from…

android-securitybinary-exploitationeducation+5
1802 years ago
patch-diffing-in-the-dark preview

patch-diffing-in-the-dark

GitHubvulnerabilityresearchcentre/patch-diffing-in-the-dark

Leveraging patch diffing to discover new vulnerabilities

binary-analysisbinary-exploitationeducation+3
1441 year ago
CVE-2026-85046 preview

CVE-2026-85046

GitHubatiilla/cve-2026-85046

Proof-of-concept and technical analysis for CVE-2026-85046, a V8 type confusion in inline Array.prototype.sort, including root cause, patch diff, and…

binary-analysiseducationexploitation+3
827 days ago
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day preview

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

android-securityeducationexploitation+7
318 days ago
ghost-hoock preview

ghost-hoock

GitHubgenksome/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
421 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
20 days ago
CVE-2023-52356-libtiff-analysis preview

CVE-2023-52356-libtiff-analysis

GitHubyardenbenita/cve-2023-52356-libtiff-analysis

Root-cause analysis and patch validation of CVE-2023-52356 in libtiff using AddressSanitizer and GDB.

binary-analysisdebuggerseducation+2
28 days ago
CVE-2026-93485 preview

CVE-2026-93485

GitHub0xblackash/cve-2026-93485

Defensive research repository for CVE-2026-93485, a WordPress core stored XSS flaw, with version-check scanner, technical analysis, and patch…

defensive-toolseducationpapers-research+3
13 days ago
DNS-Mayhem-CVE-2026-41096-Deep-Dive preview

DNS-Mayhem-CVE-2026-41096-Deep-Dive

GitHubmrk336/dns-mayhem-cve-2026-41096-deep-dive

In‑depth technical analysis of CVE‑2026‑41096, a critical heap overflow in Windows DNSAPI.dll enabling remote code execution via crafted DNS…

dns-analysiseducationexploitation+4
44 months ago
CVE-2025-39682 preview

CVE-2025-39682

GitHubsuominen/cve-2025-39682

Single-page tracker recording per-distribution patch status for CVE-2025-39682, a use-after-free in the Linux kernel kTLS receive path.

ioc-managementpapers-researchthreat-intelligence+1
8 days ago
CVE-2021-3156 preview

CVE-2021-3156

GitHubmhackiori/cve-2021-3156

Visualization, Fuzzing, Exploit and Patch of Baron Samedit Vulnerability

binary-exploitationeducationexploitation+4
54 years ago
CVE-2025-60719-AFD.SYS preview

CVE-2025-60719-AFD.SYS

GitHubakamai/cve-2025-60719-afd.sys

Proof-of-concept and root-cause analysis of CVE-2025-60719, a use-after-free vulnerability in Windows afd.sys leading to local privilege escalation,…

ai-assisted-reversingbinary-exploitationeducation+3
49 months ago
ghost-hoock preview

ghost-hoock

GitHubdeaurity/ghost-hoock

GhostLock stripped to one primitive: SELinux off on Galaxy A17 (BZA5) via futex PI UAF (CVE-2026-43499). No root, no cred patch, no rwforge.

android-securitybinary-exploitationexploitation+6
120 days ago
CVE-2026-9830 preview

CVE-2026-9830

GitHubchpratik/cve-2026-9830

Threat intelligence report repository for CVE-2026-9830, an authentication bypass vulnerability in BookingPress Pro WordPress plugin, with detailed…

authenticationincident-responsepapers-research+5
2 months ago
CVE-2026-52885 preview

CVE-2026-52885

GitHubv3s9er/cve-2026-52885

Technical analysis of CVE-2026-52885: a TOCTOU race condition in Notepad++ v8.9.6.2 allowing arbitrary command execution via HMAC integrity bypass.…

binary-analysiscode-analysiseducation+3
1 month ago
Dirty-Frag-Research-CVE-2026-43284- preview

Dirty-Frag-Research-CVE-2026-43284-

GitHubnabhan-mohy/dirty-frag-research-cve-2026-43284-

Comprehensive technical research on CVE-2026-43284 (Dirty Frag), including Linux kernel internals, root cause analysis, patch analysis, detection…

container-securityincident-responseintrusion-detection+2
2 months ago
cve-2026-13934 preview

cve-2026-13934

GitHubartwiderobo/cve-2026-13934

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and…

code-analysiseducationexploitation+3
2 months ago
Previous123Next