Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
354 results
CVE-2025-47256 preview

CVE-2025-47256

GitHubsexyshoelessgodofwar/cve-2025-47256

Stack overflow in LibXMP

binary-exploitationexploitationfuzzing+3
11 year ago
PoC-CVE-2025-25200 preview

PoC-CVE-2025-25200

GitHubdwictor0/poc-cve-2025-25200

ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js.

exploitationstatic-analysisvulnerability-analysis+1
5 months ago
CVE-2019-10172 preview

CVE-2019-10172

GitHubrusakovichma/cve-2019-10172

CVE-2019-10172 PoC and Possible mitigations

code-analysisexploitationstatic-analysis+2
15 years ago
Detection-script-for-cve-2021-23358 preview

Detection-script-for-cve-2021-23358

GitHubekamsinghwalia/detection-script-for-cve-2021-23358

Detection script for cve-2021-23358

code-analysisstatic-analysissupply-chain-security+2
13 years ago
CVE-2024-12877-Exploit preview

CVE-2024-12877-Exploit

GitHubsoltanali0/cve-2024-12877-exploit

Educational CVE-2024-12877 exploit demo for PHP Object Injection in GiveWP WordPress plugin. Includes root cause analysis, regex bypass techniques,…

code-analysisctfeducation+6
11 year ago
ply_exploit_rejection preview

ply_exploit_rejection

GitHubtom025/ply_exploit_rejection

Arguments to reject CVE-2025-56005

code-analysiseducationpapers-research+2
7 months ago
SealSecurityAssignment preview

SealSecurityAssignment

GitHubcucumberanorsncompany/sealsecurityassignment

Researching on the vulnrability CVE-2023-26136

code-analysiseducationexploitation+3
12 years ago
CVE-2021-44228---Log4Shell-Analysis preview

CVE-2021-44228---Log4Shell-Analysis

GitHubpcmkuit/cve-2021-44228---log4shell-analysis

Technical deep dive into Apache Log4j2 JNDI injection vulnerability. Features static code analysis, patch comparison, attack vectors (LDAP/RMI/DNS),…

code-analysiseducationexploitation+3
9 months ago
joniles__mpxj_CVE-2020-35460_8-3-4 preview

joniles__mpxj_CVE-2020-35460_8-3-4

GitHubshoucheng3/joniles__mpxj_cve-2020-35460_8-3-4

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

code-analysisexploitationstatic-analysis+2
1 year ago
nahsra__antisamy_CVE-2017-14735_1-5-6 preview

nahsra__antisamy_CVE-2017-14735_1-5-6

GitHubshoucheng3/nahsra__antisamy_cve-2017-14735_1-5-6

Java library for fast, configurable HTML sanitization from untrusted sources. Uses policy-driven scanning to remove malicious JavaScript and CSS,…

api-securitycode-analysismisconfiguration+3
9 months ago
jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1 preview

jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1

GitHubshoucheng3/jenkinsci__workflow-cps-plugin_cve-2022-25173_2646-v6ed3b5b01ff1

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

code-analysisdevsecopsdynamic-analysis-sandboxing+3
10 months ago
SkypeACLKeyGen.exe-analysis-for-hacking-team preview

SkypeACLKeyGen.exe-analysis-for-hacking-team

GitHubspiralbl0ck/skypeaclkeygen.exe-analysis-for-hacking-team

SkypeACLKeyGen.exe analysis for hacking team

binary-analysisbinary-exploitationdigital-forensics+5
2 years ago
apache__myfaces_CVE-2011-4367_2-0-11 preview

apache__myfaces_CVE-2011-4367_2-0-11

GitHubshoucheng3/apache__myfaces_cve-2011-4367_2-0-11

Exploit for CVE-2011-4367 targeting Apache MyFaces JSF implementation, demonstrating a remote code execution vulnerability in the Jakarta Faces…

code-analysisstatic-analysisvulnerability-analysis+2
8 months ago
CVE-2023-26136 preview

CVE-2023-26136

GitHubmorrisel/cve-2023-26136

This repository contains a solution for the CVE-2023-26136 vulnerability.

code-analysiseducationpapers-research+3
1 year ago
duo-agentflow-auditor preview

duo-agentflow-auditor

GitLabcentisgood/duo-agentflow-auditor

AI Code Security — four agents that catch what SAST misses in AI-generated code. Built on GitLab Duo Agent Platform.

ai-securitycode-analysisdevsecops+8
6 months ago
CVE-2022-0219 preview

CVE-2022-0219

GitHubhaxatron/cve-2022-0219

Proof-of-concept exploit for CVE-2022-0219, an XXE vulnerability in Jadx that allows local file disclosure when exporting malicious APK files via the…

android-securitycode-analysismobile-security+3
4 years ago
CVE-2024-22640 preview

CVE-2024-22640

GitHubzunak/cve-2024-22640

Proof-of-concept exploit for CVE-2024-22640, a ReDoS vulnerability in TCPDF <=6.7.4 triggered by crafted HTML color input, with demonstration code.

code-analysisexploitationfuzzing+3
2 years ago
Tough-Cookie-v2.5.0-Patched preview

Tough-Cookie-v2.5.0-Patched

GitHubdani33339/tough-cookie-v2.5.0-patched

Patched tough-cookie v2.5.0 fixing CVE-2023-26136 prototype pollution vulnerability with Object.create(null) in MemoryCookieStore, including exploit…

code-analysiseducationexploitation+3
1 year ago
Previous1…17181920Next