Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
901 results
CVE-2018-12533 preview

CVE-2018-12533

GitHubllamaonsecurity/cve-2018-12533

Payload generator and proof-of-concept exploit for CVE-2018-12533 (Richfaces deserialization/EL injection) with Docker-based vulnerable environment…

exploitationlabs-practicepapers-research+3
9
5 years ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
CVE-2026-19952 preview

CVE-2026-19952

GitHubabraxas/cve-2026-19952

Proof-of-concept and disclosure pack for CVE-2026-19952, an unauthenticated arbitrary file deletion in the WordPress Frontend Admin plugin, with lab…

exploitationlabs-practicepapers-research+5
3 days ago
Final-project-SQL-injection-pipeline preview

Final-project-SQL-injection-pipeline

GitHubmlily2024/final-project-sql-injection-pipeline

Hybrid machine-learning pipelines for detecting SQL injection in web traffic, combining DistilBERT and BERT-GNN models with adversarial training and…

anomaly-detectioneducationmachine-learning+3
2 months ago
VulnLLM-R preview

VulnLLM-R

GitHubucsb-mlsec/vulnllm-r

Specialized reasoning LLM for source-code vulnerability detection in C/C++ and Python, with dataset construction, SFT/DPO training, and…

code-analysismachine-learningpapers-research+2
3806 months ago
CVE-2026-0596-Reproduction preview

CVE-2026-0596-Reproduction

GitHubsparshbiswas-ai/cve-2026-0596-reproduction

Research environment and validation scripts for evaluating deserialization behaviors in MLflow and MLServer.

binary-exploitationeducationexploitation+7
4 months ago
IF-Guide preview

IF-Guide

GitHubztcoalson/if-guide

[NeurIPS '25] Code for Paper "IF-Guide: Influence Function-Guided Suppression of Harmful Training Data for Reducing LLM Toxicity"

ai-securitycode-analysisdefensive-tools+3
1311 months ago
LeakGauge preview

LeakGauge

GitHubyeasen-z/leakgauge

Detects LLM context-leakage attacks by training lightweight behavior probes on log-probabilities, with vLLM offline/server detection pipelines.

adversarial-attackai-securityanomaly-detection+2
329 days ago
IPI-exposure-signal preview

IPI-exposure-signal

GitHubjianshuod/ipi-exposure-signal

Research pipeline for detecting latent indirect prompt-injection exposure signals in agentic LLMs via hidden-state probing, including trace…

ai-securityeducationmachine-learning+1
42 months ago
CVE-2021-44228-Log4j-lookup-Rce preview

CVE-2021-44228-Log4j-lookup-Rce

GitHubm1nggod/cve-2021-44228-log4j-lookup-rce

Detailed analysis and proof-of-concept for CVE-2021-44228 (Log4j RCE), including environment setup, vulnerability analysis, JNDI injection mechanism,…

educationexploitationpapers-research+3
44 years ago
CVEREV3 preview

CVEREV3

GitHubkmeps4/cverev3

Proof-of-concept testing environment for CVE-2021-30858, based on Google Project Zero's root cause analysis of an in-the-wild iOS exploit.

binary-exploitationeducationexploitation+2
14 years ago
CVE-2023-20198 preview

CVE-2023-20198

GitHubreligan/cve-2023-20198

A cybersecurity case study analysing CVE-2023-20198 in Cisco IOS XE, covering vulnerability exploitation, mitigation strategies, secure software…

educationexploitationlabs-practice+6
9 months ago
CVE-2021-35475 preview

CVE-2021-35475

GitHubsaitamang/cve-2021-35475

Writeup for CVE-2021-35475; Stored Cross-Site Scripting(XSS) on SAS® Environment Manager 2.5

educationpapers-researchpenetration-testing+2
4 years ago
heretic preview

heretic

GitHubp-e-w/heretic

Fully automatic censorship removal for language models

adversarial-attackai-securityeducation+3
33.1k2 days ago
TEE-reversing preview

TEE-reversing

GitHubenovella/tee-reversing

A curated list of public TEE resources for learning how to reverse-engineer and achieve trusted code execution on ARM devices

android-securitybinary-analysiscurated-resources+9
1.0k8 months ago
polytracker preview

polytracker

GitHubtrailofbits/polytracker

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

binary-analysisdynamic-code-analysiseducation+4
5993 months ago
hpim-training-lab preview

hpim-training-lab

GitHubalixiacf/hpim-training-lab

Trained to Escalate: Forensic Analysis and Local Replication of RLHF-Induced Privilege Escalation in AI Agents (CVE-2026-65616)

ai-securitycontainer-securityeducation+7
113 days ago
CVE-2026-34038 preview

CVE-2026-34038

GitHubthemehackers/cve-2026-34038

CVE-2026-34038: Authenticated Remote Command Injection in Coolify

code-analysiseducationexploitation+3
13 months ago
Previous12…51Next