Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
843 results
CVE-2026-20700 preview

CVE-2026-20700

GitHubr3n3r0/cve-2026-20700

PoC demonstrating dyld as a PAC signing oracle via hand-crafted Mach-O chained fixups on arm64e, achieving controlled PAC-valid pointer writes and…

binary-exploitationctfeducation+8
13
3 months ago
CVE-2019-18935-memShell preview

CVE-2019-18935-memShell

GitHubdust-life/cve-2019-18935-memshell

C++ memshell DLL generator for CVE-2019-18935, enabling in-memory web shell deployment via Telerik UI deserialization with Assembly.Load and IJW…

exploitationpayload-developmentpenetration-testing+2
131 year ago
PhantomEvasion preview

PhantomEvasion

GitHubesskumar/phantomevasion

Python-based antivirus evasion tool generating undetectable executables from msfvenom payloads with advanced techniques like junkcode injection,…

exploit-frameworkspayload-generationpenetration-testing+5
176 years ago
CVE-2017-9101 preview

CVE-2017-9101

GitHubjasperla/cve-2017-9101

Authenticated remote code execution exploit for PlaySMS 1.4 via CSV phonebook upload. Provides single-command and interactive shell modes for…

exploitationpayload-generationpenetration-testing+3
147 years ago
Lastenzug preview

Lastenzug

GitHubps1337/lastenzug

Socks4a proxy leveraging PIC, Websockets and static obfuscation on assembly level

ids-ips-evasionpayload-developmentpost-exploitation+3
264 years ago
flopz preview

flopz

GitHubflopz-project/flopz

Pure Python assembler toolkit for creating shellcode, dynamically patching binaries, and instrumenting firmware images for debugging and fuzzing on…

binary-analysisembedded-systems-securityfirmware-analysis+3
142 years ago
CVE-2020-1349 preview

CVE-2020-1349

GitHub0neb1n/cve-2020-1349

Exploit for Outlook 2019 zero-click vulnerability CVE-2020-1349, using MIME header parsing bugs to achieve heap overflow and EIP control via vftable…

binary-exploitationemail-securityexploitation+2
116 years ago
CVE-2025-2620-poc preview

CVE-2025-2620-poc

GitHubotsmane-ahmed/cve-2025-2620-poc

Proof-of-concept exploit for CVE-2025-2620, a critical stack-based buffer overflow in D-Link DAP-1620 routers enabling unauthenticated remote code…

binary-exploitationembedded-systems-securityexploitation+8
161 year ago
cve-2023-42115 preview

cve-2023-42115

GitHubkirinse/cve-2023-42115

Python-based exploit and reverse shell payload generator for CVE-2023-42115, featuring scan and exploit modes with cross-platform payload creation.

exploitationpayload-developmentpayload-generation+3
92 years ago
CVE-2024-0311 preview

CVE-2024-0311

GitHubcalligraf0/cve-2024-0311

Proof-of-concept exploit for CVE-2024-0311 bypassing Skyhigh Client Proxy policy via process injection and named pipe manipulation, with custom…

binary-exploitationexploitationids-ips-evasion+4
91 year ago
CVE-2022-24500 preview

CVE-2022-24500

GitHub0x7n6/cve-2022-24500

Standalone exploit for CVE-2022-24500 targeting Windows SMB, generating and executing shellcode to deliver a reverse Meterpreter payload.

exploitationpayload-generationpenetration-testing+3
103 years ago
CVE-2022-0847_dirty-pipe preview

CVE-2022-0847_dirty-pipe

GitHubludovicpatho/cve-2022-0847_dirty-pipe

Hacked up Dirty Pipe (CVE-2022-0847) PoC that hijacks a SUID binary to spawn a root shell. (and attempts to restore the damaged binary as well)

binary-exploitationexploitationpayload-development+3
104 years ago
CVE-2022-40471 preview

CVE-2022-40471

GitHubrashidkhanpathan/cve-2022-40471

RCE Exploit and Research

exploitationpayload-generationpenetration-testing+3
103 years ago
CVE-2016-2067 preview

CVE-2016-2067

GitHubhhj4ck/cve-2016-2067

GPU IOMMU DMA exploit for Android devices that overwrites vdso.so with shellcode to escalate privileges and spawn a reverse root shell on Nexus 6p.

android-securitybinary-exploitationexploitation+5
75 years ago
CVE-2023-27997 preview

CVE-2023-27997

GitHubdelsploit/cve-2023-27997

Python exploit for CVE-2023-27997 targeting FortiGate VM64 7.2.0 with heap spray and shellcode injection to achieve remote code execution.

binary-exploitationexploitationpayload-generation+3
92 years ago
JBWPer preview

JBWPer

GitHubim-hanzou/jbwper

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4061 - JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationshellcode+2
53 years ago
CVE-2026-43499-aristotle-apk preview

CVE-2026-43499-aristotle-apk

GitHubsoralis0912/cve-2026-43499-aristotle-apk

Android kernel exploit for CVE-2026-43499 (Futex-PI use-after-free) that gains temporary root on Xiaomi XIG04 to enable ADB. Includes automated…

android-securitybinary-exploitationexploitation+5
41 month ago
CVE-2025-34085 preview

CVE-2025-34085

GitHubyukinime/cve-2025-34085

Automated scanner and exploit for CVE-2025-34085, an unauthenticated RCE in the WordPress Simple File List plugin. Supports multi-target scanning,…

exploitationpayload-generationpenetration-testing+3
71 year ago
Previous1…8910…47Next