Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
CVE-2018-12533 preview

CVE-2018-12533

GitHubllamaonsecurity/cve-2018-12533

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

exploitationlabs-practicepapers-research+3
9
5 years ago
Awesome-Fuzzing preview

Awesome-Fuzzing

GitHubsecfigo/awesome-fuzzing

A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for…

binary-analysiscurated-resourceseducation+6
5.9k3 years ago
chronomaly preview

chronomaly

GitHubfarazsth98/chronomaly

Android kernel exploit for CVE-2025-38352, previously exploited in-the-wild. Targets vulnerable x86_64 Linux kernels v5.10.x.

android-securitybinary-exploitationeducation+3
3117 months ago
react2shell preview

react2shell

GitHubfreeqaz/react2shell

RCE exploit toolkit for CVE-2025-55182 and CVE-2025-66478 in React Server Components. Includes multiple exploit variants, detection scripts, a…

code-analysisdynamic-analysis-sandboxingeducation+6
688 months ago
power_analysis preview

power_analysis

GitHublord-feistel/power_analysis

Proof-of-concept demonstrating a power analysis side-channel attack against a vulnerable RSA implementation on Arduino (Atmega328P), with detailed…

cryptographyeducationembedded-systems-security+2
322 years ago
0xKern3lCrush preview

0xKern3lCrush

GitHubdeathshotxd/0xkern3lcrush

Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for…

educationexploitationmalware-analysis+4
516 months ago
internet-of-vulnerable-things preview

internet-of-vulnerable-things

GitHubotsmr/internet-of-vulnerable-things

The results of my small term paper on the topic of the Internet of Vulnerable Things and the exploit for CVE-2022-48194.

educationembedded-systems-securityexploitation+6
193 years ago
vuke preview

vuke

GitHuboritwoen/vuke

Research tool for studying vulnerable cryptographic key generation (brainwallet, PRNG, milksad, LCG, xorshift)

cryptographyeducationexploitation+4
195 months ago
BYOVD-Research preview

BYOVD-Research

GitHubkosec-llc/byovd-research

BYOVD research performed by KOSEC. Includes vulnerable drivers and writeups (CVE-2026-0828).

binary-analysiseducationexploitation+2
93 months ago
debianopenssl preview

debianopenssl

GitHubbadkeys/debianopenssl

Private keys vulnerable to Debian OpenSSL bug (CVE-2008-0166)

cryptographycurated-resourceseducation+3
71 year ago
CVE-2022-44789 preview

CVE-2022-44789

GitHubalalng/cve-2022-44789

Proof-of-concept exploit and writeup for CVE-2022-44789, a heap buffer overflow in MuJS JavaScript interpreter, including vulnerable version and…

binary-exploitationeducationexploitation+2
123 years ago
grandstream-cve-2026-2329-analysis preview

grandstream-cve-2026-2329-analysis

GitHubvivianuba/grandstream-cve-2026-2329-analysis

Defensive vulnerability-research project comparing vulnerable and patched Grandstream GXP1600 firmware for CVE-2026-2329, using SquashFS extraction,…

binary-analysiseducationfirmware-analysis+4
10 days ago
CVE-2021-22204 preview

CVE-2021-22204

GitHubtrganda/cve-2021-22204

In-depth technical analysis of CVE-2021-22204 (ExifTool RCE) with PoC reproduction, payload construction, and Perl code review of the vulnerable DjVu…

binary-exploitationcode-analysiseducation+3
34 years ago
CVE-2025-47423 preview

CVE-2025-47423

GitHubhaluka92/cve-2025-47423

Detailed disclosure of CVE-2025-47423: Local File Inclusion in Personal Weather Station Dashboard 12_lts. Includes PoC, vulnerable code analysis, and…

curated-resourceseducationexploitation+3
15 days ago
CVE-2026-48030 preview

CVE-2026-48030

GitHubmuslimbek-0x/cve-2026-48030

Proof-of-concept exploit for CVE-2026-48030, a critical OS command injection in Pheditor 2.0.1-2.0.3. Includes vulnerable code analysis, PoC script,…

code-analysiseducationexploitation+3
3 months ago
CVE-2025-63419 preview

CVE-2025-63419

GitHubmmakingdom/cve-2025-63419

CrushFTP before 11.3.7_60 is vulnerable to HTML Injection. The Web-Based Server has a feature where users can share files, the feature reflects the…

educationpapers-researchvulnerability-analysis+2
29 months ago
CVE-2021-23383 preview

CVE-2021-23383

GitHubfazilbaig1/cve-2021-23383

The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from…

code-analysiseducationpapers-research+2
21 year ago
CVE-2026-23499 preview

CVE-2026-23499

GitHublukasz-rybak/cve-2026-23499

CVE-2026-23499 - Saleor vulnerable to stored XSS via Unrestricted File Upload

educationpapers-researchvulnerability-analysis+2
4 months ago
Previous123Next