Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
15 results
CVE-2023-42222 preview

CVE-2023-42222

GitHubitssixtyn3in/cve-2023-42222

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

educationexploitationpapers-research+2
3
3 years ago
CVE-2026-103584 preview

CVE-2026-103584

GitHubbombobombone/cve-2026-103584

Sanitized report and loopback-only PoC script for CVE-2026-103584, a javascript: URL scheme XSS in MediaWiki CommonsMetadata LicenseUrl rendering.

exploitationpapers-researchvulnerability-analysis+2
10 days ago
CVE-2023-24329-PoC preview

CVE-2023-24329-PoC

GitHubh4r335hr/cve-2023-24329-poc

Proof-of-concept exploit for CVE-2023-24329, a Python urllib parsing flaw enabling URL confusion attacks. Includes a runnable script and references…

educationexploitationpapers-research+2
3 years ago
phishcollector preview

phishcollector

GitHubolizimmermann/phishcollector

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

crawlereducationinformation-gathering+8
237 months ago
CVE-2024-27564 preview

CVE-2024-27564

GitHubbabydessy/cve-2024-27564

Proof-of-concept for CVE-2024-27564, an unauthenticated SSRF in pictureproxy.php via the url parameter, with vulnerable code, curl PoC, and…

exploitationpapers-researchvulnerability-analysis+2
2 years ago
CVE-2025-60656 preview

CVE-2025-60656

GitHubdotadrien/cve-2025-60656

Stored XSS vulnerability proof-of-concept for Script Pag's 'Recent Ads' module, exploiting unsanitized double quotes in image URL fields to execute…

educationpapers-researchvulnerability-analysis+2
8 months ago
CVE-2021-26832 preview

CVE-2021-26832

GitHubgal-nagli/cve-2021-26832

Cross Site Scripting (XSS) at the "Reset Password" page form of Priority Enterprise Management System v8.00 allows attackers to execute javascript on…

educationpapers-researchvulnerability-analysis+2
55 years ago
CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille- preview

CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-

GitHubtheopaid/cve-2026-66754-remote-denial-of-service-via-reachable-assertion-in-url-prefix-handling-rouille-

Security Advisory: Remote Denial of Service via Reachable Assertion in URL Prefix Handling (rouille)

educationpapers-researchvulnerability-analysis+1
2 months ago
CVE-2026-34212 preview

CVE-2026-34212

GitHub0xmrma/cve-2026-34212

Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor…

educationexploitationpapers-research+3
3 months ago
CVE-2024-28515 preview

CVE-2024-28515

GitHubheshi906/cve-2024-28515

Documentation of CVE-2024-28515, a buffer overflow vulnerability in CSAPP Lab3 (buflab-update.pl), enabling remote code execution via crafted URL…

binary-exploitationeducationexploitation+2
12 years ago
CVE-2026-33017 preview

CVE-2026-33017

GitHubeqstlab/cve-2026-33017

Langflow RCE

code-analysiseducationexploitation+3
111 month ago
CVE-2023-49438 preview

CVE-2023-49438

GitHubbrandon-t-elliott/cve-2023-49438

CVE-2023-49438 - Open Redirect Vulnerability in Flask-Security-Too

educationpapers-researchvulnerability-analysis+2
52 years ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
12 months ago
CVE-2021-43129 preview

CVE-2021-43129

GitHubskotizo/cve-2021-43129

Vulnerability in D2L Brightspace's Learning Management System(LMS)

educationexploitationpapers-research+2
24 years ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
1 year ago