Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
109 results
CVE-2026-87796 preview

CVE-2026-87796

GitHubabraxas/cve-2026-87796

Reproduction pack and PoC script for CVE-2026-87796, an unauthenticated arbitrary file upload RCE in Multi Uploader for Gravity Forms <= 1.1.9, with…

educationexploitationlabs-practice+6
1
10 days ago
CVE-2026-59346-POC preview

CVE-2026-59346-POC

GitHub0xcyberstan/cve-2026-59346-poc

PoC for CVE-2026-59346 - 32-bit integer overflow in VMware's VMXNET3 TSO segmentation path, guest-to-host crash.

binary-exploitationexploitationhardware-iot-security+3
113 days ago
ai-kubernetes-helm-chart-security preview

ai-kubernetes-helm-chart-security

GitHubsorami-consulting-au/ai-kubernetes-helm-chart-security

Evidence and data for the Sorami technical report on security defaults of 15 AI serving, vector database and MCP Helm charts on Kubernetes.

ai-securitycloud-securityconfiguration-auditing+5
12 days ago
CVE-2026-39107 preview

CVE-2026-39107

GitHubmgtx2/cve-2026-39107

Detailed disclosure of a stored XSS vulnerability in Kimi AI v1.0's Preview tab, including attack scenario, PoC, and remediation guidance for…

educationpapers-researchvulnerability-analysis+2
3 months ago
CVE-2026-75898 preview

CVE-2026-75898

GitHubt3bik/cve-2026-75898

Proof-of-concept for CVE-2026-75898, an SSRF in RAGFlow's Invoke component. Demonstrates the vulnerability with unmodified source, includes E2E…

educationexploitationpapers-research+2
1 month ago
heartbleed-proof-of-concept preview

heartbleed-proof-of-concept

GitHubundacmic/heartbleed-proof-of-concept

Proof of concept for exploiting the Heartbeat Extension bug detailed in the CVE-2014-0160. :old_key: :unlock:

educationexploitationpapers-research+2
53 years ago
OWASP-Subtractive-Hardening-Top-10 preview

OWASP-Subtractive-Hardening-Top-10

GitHubowasp/owasp-subtractive-hardening-top-10

The OWASP Subtractive Security Top 10 Project is an initiative to identify, document, and promote the highest-impact opportunities for reducing cyber…

ai-securitycloud-securitycontainer-security+6
293 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubhassham1/cve-2026-87902

WordPress Core <= 7.1.1 unauthenticated LFI to RCE - validation lab, PoC, nuclei template (GHSA-7hp8-65ch-5whp)

educationexploitationlabs-practice+7
15 days ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
1227 days ago
CVE-2026-59550 preview

CVE-2026-59550

GitHubflx-0x00/cve-2026-59550

Unauthenticated time-based blind SQL injection PoC for AWP Classifieds <= 4.4.7, with a Docker lab, full writeup, and patch diff.

educationexploitationlabs-practice+5
13 days ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
awesome-linux-attack-forensics-purplelabs preview

awesome-linux-attack-forensics-purplelabs

GitHubcr0nx/awesome-linux-attack-forensics-purplelabs

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

container-securitycurated-resourcesdigital-forensics+8
3413 years ago
IAGA-Sentinel preview

IAGA-Sentinel

GitHubiaga-team/iaga-sentinel

Cryptographically signed, replay-verifiable evidence layer for AI agents. Governs actions in the loop, produces Ed25519-signed receipts linked into a…

ai-securitycontainer-securitycryptography+4
18317 days ago
Kestra-cve-2026-53576 preview

Kestra-cve-2026-53576

GitHubatlasvector/kestra-cve-2026-53576

End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common…

container-securityexploitationincident-response+8
3 days ago
Johnny-You-Are-Fired preview

Johnny-You-Are-Fired

GitHubrub-nds/johnny-you-are-fired

Artifacts for the USENIX publication.

cryptographyemail-securitypapers-research+3
566 years ago
quantum-zk-proof-poc preview

quantum-zk-proof-poc

GitHubtrailofbits/quantum-zk-proof-poc

Proof-of-concept code for beating Google's ZK proof of quantum cryptanalysis

cryptographyeducationexploitation+3
165 months ago
red-teaming-auto-mode preview

red-teaming-auto-mode

GitHubsafety-research/red-teaming-auto-mode

Research code for red-teaming AI auto-mode monitors, including simulation evals, fuzzing, and monitor implementations for Claude Code and Codex…

ai-securityeducationfuzzing+3
13 days ago
CVE-2026-66906 preview

CVE-2026-66906

GitHuboscerd/cve-2026-66906

Proof-of-concept reproducers for Apache Camel path traversal vulnerability (CVE-2026-66906) in camel-azure-storage-blob, demonstrating arbitrary file…

educationexploitationpapers-research+2
1 month ago
Previous1234567Next