Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1046 results
http-terminator preview

http-terminator

GitHubportswigger/http-terminator

AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms…

ai-securityexploitationfuzzing+8
120
1 month ago
CVE-2026-48356 preview

CVE-2026-48356

GitHubabraxas/cve-2026-48356

Proof-of-concept and lab pack for CVE-2026-48356, an unauthenticated unrestricted file upload in Magento Open Source guest-cart REST custom options.

exploitationlabs-practicepayload-generation+5
3 days ago
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
423 days ago
polychrome-rs preview

polychrome-rs

GitHubdovelus/polychrome-rs

A PoC on how to use a Compute Shader as Payload

defensive-toolsencryption-decryption-toolsexploitation+5
47 days ago
waybend preview

waybend

GitHubprinciplebreach/waybend

Self-hosted SSRF redirect, payload, callback, and DNS workbench

command-and-controldns-analysisinformation-gathering+9
516 days ago
SmuggleMyPayload preview

SmuggleMyPayload

GitHubshaheeryasirofficial/smugglemypayload

Generates HTML smuggling pages that embed and reconstruct files client-side via JavaScript, with payload encoding, chunking, obfuscation, and…

adversarial-attackdefensive-toolspayload-development+6
3914 days ago
CVE-2023-49070 preview

CVE-2023-49070

GitHubbardlaudian/cve-2023-49070

Python PoC for Apache OFBiz CVE-2023-49070: auth-bypass on /webtools/control/xmlrpc plus ysoserial gadget chain to achieve pre-auth deserialization…

command-and-controldefensive-toolsexploitation+5
5 days ago
Dji_ble_vuln preview

Dji_ble_vuln

GitHubfeedbeef/dji_ble_vuln

DJI Drone DUML Command Injection over Bluetooth — Proof of Concept for CVE-2026-78306

bluetooth-securitycommand-and-controlembedded-systems-security+6
6 days ago
CVE-2026-87902-Toolkit preview

CVE-2026-87902-Toolkit

GitHubtc4dy/cve-2026-87902-toolkit

WordPress CVE-2026-87902 LFI-to-RCE toolkit with a weaponized exploit chain (PEAR RCE, webshell, admin creation, loot) and a non-intrusive…

defensive-toolseducationexploitation+8
15 days ago
rcekit preview

rcekit

GitHubkabiri-labs/rcekit

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…

command-and-controlexploitationfuzzing+8
147 days ago
CVE-2026-78306 preview

CVE-2026-78306

GitHubwh02m1/cve-2026-78306

Proof-of-concept exploiting DJI drone Bluetooth DUML command injection, sending unauthenticated commands to read credentials, alter Wi-Fi config, and…

bluetooth-securityembedded-systems-securityexploitation+6
93 days ago
libextractor-ole2-rce preview

libextractor-ole2-rce

GitHubhaitam-lazaar/libextractor-ole2-rce

PoC for a Critical stack-based buffer overflow in GNU libextractor ≤ 1.14. A malicious .doc file triggers an unbounded VLA allocation causing…

binary-exploitationexploitationlabs-practice+4
14 days ago
GoCD_PoC_Supply_Chain_Attack preview

GoCD_PoC_Supply_Chain_Attack

GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

educationexploitationpayload-generation+7
212 days ago
CVE-2026-22686-RemoteCodeExecution-RCE-PoC preview

CVE-2026-22686-RemoteCodeExecution-RCE-PoC

GitHubmoi404/cve-2026-22686-remotecodeexecution-rce-poc

Proof-of-concept exploit and payload generator for CVE-2026-22686, a sandbox escape in enclave-vm <2.7.0 enabling arbitrary code execution and…

educationexploitationpapers-research+5
13 days ago
CVE-2026-82329-PoC-Exploit preview

CVE-2026-82329-PoC-Exploit

GitHubtc4dy/cve-2026-82329-poc-exploit

Exploit and detection toolkit for CVE-2026-82329, a JFrog Artifactory auth bypass. Forges join JWTs to mint admin tokens; includes a non-intrusive…

authenticationdefensive-toolsexploitation+7
214 days ago
CVE-2025-64512_PoC preview

CVE-2025-64512_PoC

GitHubjinook-kim/cve-2025-64512_poc

Python PoC for CVE-2025-64512, a pdfminer.six pickle deserialization RCE. Generates gzipped pickle payloads and polyglot PDFs, then delivers them to…

ctfeducationexploitation+5
14 days ago
blitzstrike preview

blitzstrike

GitHubshinthink/blitzstrike

MCP server packaging a three-tier penetration-testing methodology: attack-surface reconnaissance, source-to-sink static analysis, and live finding…

exploitationinformation-gatheringpayload-generation+8
51110 days ago
CVE-2023-45866_WIP preview

CVE-2023-45866_WIP

GitHubv3ilsm1th/cve-2023-45866_wip

Simulates a Bluetooth keyboard to exploit CVE-2023-45866, injecting keystrokes via DuckyScript on vulnerable Android, iOS, macOS, and Linux devices…

bluetooth-securityexploitationhardware-iot-security+4
1 year ago
Previous12…59Next