Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
ExtensionSpoofer preview

ExtensionSpoofer

GitHubhenriksb/extensionspoofer

Spoof file icons and extensions in Windows

ids-ips-evasionimpersonation-toolsmalware-analysis+3
187
1 month ago
CVE-2026-21016-Malicious-PyPI-Package-Install-Hook-setup.py-Execution- preview

CVE-2026-21016-Malicious-PyPI-Package-Install-Hook-setup.py-Execution-

GitHubgeorge0papasotiriou/cve-2026-21016-malicious-pypi-package-install-hook-setup.py-execution-

Demonstrates how a malicious Python package executes arbitrary commands during pip install via setup.py, highlighting PyPI supply chain and…

adversarial-attackeducationexploitation+2
1 month ago
CVE-2026-25243 preview

CVE-2026-25243

GitHubdinosn/cve-2026-25243

CVE-2026-25243 — Redis RESTORE zipmap double-free → remote code execution (ASLR on).

binary-exploitationexploitationmemory-forensics+5
133 months ago
c-copy-fail preview

c-copy-fail

GitHubopenpixelsystems/c-copy-fail

C-based exploit for CVE-2026-31431 in the Linux Kernel Crypto API, targeting aarch64 and amd64 architectures with shellcode generation and ancillary…

binary-exploitationexploitationexploit-frameworks+3
14 months ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubahmadf77/cve-2026-23744

Python exploit script for CVE-2026-23744 that delivers a reverse shell to a specified target URL, requiring a netcat listener for command-and-control.

command-and-controlexploitationpayload-development+3
5 months ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubthemalwareguardian/cve-2025-5548

Buffer overflow in FreeFloat FTP Server 1.0 illustrating how a single unsafe handler can generate multiple CVE entries across different commands.

binary-exploitationdebuggerseducation+7
15 months ago
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
15 months ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubthemalwareguardian/cve-2017-14980

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can…

binary-exploitationdebuggerseducation+7
15 months ago
CVE-2003-0264 preview

CVE-2003-0264

GitHubthemalwareguardian/cve-2003-0264

Classic stack-based buffer overflow in SLMail 5.1 showing how early mail servers could be compromised through oversized SMTP and POP3 commands.

binary-exploitationdebuggerseducation+7
15 months ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubdairrow/cve-2025-31161

PoC Authentication Bypass to RCE to Exploit CVE-2025-31161

authenticationexploitationpayload-development+5
18 months ago
React2ShellPoC preview

React2ShellPoC

GitHubgit0xlai/react2shellpoc

This repository provides a proof-of-concept for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server Components. It…

educationexploitationpapers-research+3
8 months ago
CVE-2025-33053-POC preview

CVE-2025-33053-POC

GitHubcyberw1ng/cve-2025-33053-poc

POC for CVE-2025-33053 WebDav Exploit, demonstrating how the vulnerability can be triggered in a real environment. This repository focuses on…

command-and-controleducationexploitation+7
8 months ago
PHP-CGI-INTERNAL-RCE preview

PHP-CGI-INTERNAL-RCE

GitHubmananjain61/php-cgi-internal-rce

Delivering PHP RCE (CVE-2024-4577) to the Local Network Servers

dns-analysisexploitationpayload-development+3
1 year ago
CVE-2017-1000353 preview

CVE-2017-1000353

GitHubvulhub/cve-2017-1000353

jenkins CVE-2017-1000353 POC

exploitationpayload-developmentpenetration-testing+2
571 year ago
parquet-rce-poc-CVE-2025-30065 preview

parquet-rce-poc-CVE-2025-30065

GitHubmouadk/parquet-rce-poc-cve-2025-30065

Proof-of-concept exploit for CVE-2025-30065 demonstrating remote class instantiation and SSRF via malicious Parquet files in Java applications.

educationexploitationpayload-development+3
31 year ago
CVE-2024-35106-POC preview

CVE-2024-35106-POC

GitHublaskdjlaskdj12/cve-2024-35106-poc

Proof-of-concept exploit for CVE-2024-35106, a stack buffer overflow in NEXTU FLETA AX1500 Wi-Fi 6 router. Demonstrates denial-of-service and…

binary-exploitationembedded-systems-securityexploitation+5
1 year ago
CVE-2019-18634 preview

CVE-2019-18634

GitHubl0w3/cve-2019-18634

This repo contains both the exploit and the explaination of how this vulnerability is exploited

binary-exploitationeducationexploitation+3
1 year ago
CVE-2024-48990-Exploit preview

CVE-2024-48990-Exploit

GitHubally-petitt/cve-2024-48990-exploit

My exploit for CVE-2024-48990. Full details of how I made this are on my blog.

exploitationpayload-developmentpenetration-testing+3
51 year ago
Previous123Next