Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
451 results
teamcity-cve-2026-63077-remediation preview

teamcity-cve-2026-63077-remediation

GitHubbakos-sandor-nx/teamcity-cve-2026-63077-remediation

JetBrains TeamCity On-Premises CVE-2026-63077 Emergency Hardening & Patch Runbook Package

cloud-infrastructure-securityconfiguration-auditingdevsecops+6
1 month ago
gha-lab-becf103a54 preview

gha-lab-becf103a54

GitHubpvharmo2/gha-lab-becf103a54

Authorized security-research reproduction of CVE-2025-15617 (GHSA-6xqr-4q5g-xc7x): artipacked GITHUB_TOKEN leak in wazuh FIM Windows integration…

cloud-securitycurated-resourceseducation+2
18h 48m ago
gha-lab-d9fd584b12 preview

gha-lab-d9fd584b12

GitHubpvharmo2/gha-lab-d9fd584b12

Authorized security-research lab reproducing CVE-2024-47179 (GHSL-2024-178): artifact-poisoning pwn-request chain in RSSHub docker-test workflows…

curated-resourceseducationsupply-chain-security+1
1 day ago
spring-cvss-check preview

spring-cvss-check

GitHubxiaoqimikko/spring-cvss-check

Scans Java artifacts and source for Spring/Tomcat CVEs, compares vendor vs NVD CVSS scores, verifies exploitability conditions, and checks if fix…

configuration-auditingdevsecopssupply-chain-security+2
1 day ago
CVE-2026-84361-poc preview

CVE-2026-84361-poc

GitHubsaku0512/cve-2026-84361-poc

Proof-of-concept for CVE-2026-84361, demonstrating command injection in Composer's Perforce driver via malicious P4PORT, with Docker-based…

educationexploitationsupply-chain-security+2
1 day ago
gha-lab-40e23db109 preview

gha-lab-40e23db109

GitHubpvharmo2/gha-lab-40e23db109

Security-research lab: controlled reproduction of CVE-2024-4254 (GHSA-fc78-c36r-cc59) — deploy-website.yml fork checkout/code execution in…

cloud-securitydevsecopseducation+2
1 day ago
seal-security-nuget-demo-net7 preview

seal-security-nuget-demo-net7

GitHubisecuritytw/seal-security-nuget-demo-net7

.NET 7 fork of seal-security-nuget-demo: same CVE-2024-21907 exploit story, retargeted for customers locked to .NET SDK 7.

curated-resourcesdevsecopseducation+2
3 months ago
tomcat-line-check preview

tomcat-line-check

GitHubxiaoqimikko/tomcat-line-check

CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers…

configuration-auditingsupply-chain-securityvulnerability-scanners+1
2 days ago
gha-lab-232af4821f preview

gha-lab-232af4821f

GitHubpvharmo2/gha-lab-232af4821f

Security-research lab reproducing CVE-2021-4281 (GHSA-3796-3f93-cfvx): shell command injection via PR head-branch name in…

devsecopseducationsupply-chain-security+1
3 days ago
gha-lab-83342297e0 preview

gha-lab-83342297e0

GitHubpvharmo2/gha-lab-83342297e0

Authorized security-research lab reproducing CVE-2024-41127 (GHSA-wcjf-5464-4wq9): poisoned pipeline execution via artifact-controlled code injection…

curated-resourceseducationsupply-chain-security+1
4 days ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
6 days ago
CVE-2026-7669-PoC preview

CVE-2026-7669-PoC

GitHubgouldnicholas/cve-2026-7669-poc

PoC for CVE-2026-7669: SGLang silent trust_remote_code override -> RCE

exploitationpayload-developmentremote-access-tool+3
4 months ago
reproducer-okio-cve-2023-3635 preview

reproducer-okio-cve-2023-3635

GitHubjoshuaasmith/reproducer-okio-cve-2023-3635

Reproducer for CVE-2023-3635 in Okio 2.9.0, demonstrating how React Native's version catalog pins a vulnerable dependency, affecting Android apps.

android-securityeducationmobile-security+2
8 days ago
CVE-2026-44590 preview

CVE-2026-44590

GitHubastaruf/cve-2026-44590

Proof-of-concept exploit for CVE-2026-44590, a command injection in Sherlock's GitHub Actions workflow enabling RCE and GITHUB_TOKEN exfiltration via…

educationexploitationred-teaming+3
3 months ago
audit-axios preview

audit-axios

GitHubsurri/audit-axios

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

code-analysisconfiguration-auditingdevsecops+3
4 months ago
MCPwnfluence preview

MCPwnfluence

GitHubplutosecurity/mcpwnfluence

Information about CVE-2026-27825 & CVE-2026-27826 discovered by Pluto Security and a bash script for identifying vulnerable mcp-atlassian instances…

configuration-auditingdevsecopseducation+3
76 months ago
CVE-2026-2395 preview

CVE-2026-2395

GitHubopen-flaw/cve-2026-2395

Proof-of-concept demonstrating a race condition in the tar npm package (v7.5.3) causing file collisions during parallel extraction, leading to data…

educationexploitationsupply-chain-security+1
7 months ago
log4j preview

log4j

GitHubopen-aims/log4j

Patched Log4j 1.2.17 library with the vulnerable JMSAppender class removed to mitigate CVE-2021-4104, intended as a drop-in replacement for affected…

devsecopssupply-chain-securityvulnerability-analysis
4 years ago
Previous12…26Next