Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
446 results
CVE-2026-23947-PoC preview

CVE-2026-23947-PoC

GitHubboroeurnprach/cve-2026-23947-poc

Proof-of-concept demonstrating arbitrary code execution in Orval via malicious OpenAPI fields, with setup, exploit steps, and remediation guidance.

code-analysisexploitationsupply-chain-security+2
7 months ago
log4shell-scanner preview

log4shell-scanner

GitHubarpitgupta369/log4shell-scanner

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.

defensive-toolseducationlog-analysis+3
1 month ago
vulns-2026-fatfs-chance preview

vulns-2026-fatfs-chance

GitHubrunzeroinc/vulns-2026-fatfs-chance

Documented security vulnerabilities in the FatFs embedded filesystem library with CVE details, fuzzing harness, exploit disk-image generator, and…

binary-analysiseducationembedded-systems-security+8
411 month ago
Kaspersky_CVE-2024-3094 preview

Kaspersky_CVE-2024-3094

GitHubvesjolyjd/kaspersky_cve-2024-3094

Security review of CVE-2024-3094 (XZ Utils backdoor) including threat modeling, static/dynamic code analysis, fuzzing with AFL++, and a…

code-analysisdynamic-analysis-sandboxingeducation+7
4 months ago
appsec-forge preview

appsec-forge

GitLabappsec-forge/appsec-forge

Structured security knowledge base with production-inspired cases: vulnerability analysis, exploit explanation, remediation, and DevSecOps for…

ai-securitycloud-securitycontainer-security+7
8 days ago
Reports preview

Reports

GitHubj4ck3lsyn-gen2/reports

Curated collection of cybersecurity research reports covering CVE analysis, exploit research, threat intelligence, and offensive security from…

binary-exploitationcurated-resourcesexploitation+8
21 month ago
Owasp-top-10-k8s-2025 preview

Owasp-top-10-k8s-2025

GitHubhac01/owasp-top-10-k8s-2025

Hands-on capture-the-flag lab for the OWASP Kubernetes Top 10 (2025). Exploit 11 real-world cluster weaknesses, capture flags, then apply fixes and…

cloud-securitycontainer-securityctf+8
481 month ago
CVE-2026-44590 preview

CVE-2026-44590

GitHubastaruf/cve-2026-44590

Proof-of-concept exploit for CVE-2026-44590, a command injection in Sherlock's GitHub Actions workflow enabling RCE and GITHUB_TOKEN exfiltration via…

educationexploitationred-teaming+3
3 months ago
malicious-devfile-registry preview

malicious-devfile-registry

GitHubdoyensec/malicious-devfile-registry

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

exploitationpenetration-testingred-teaming+3
151 year ago
CVE-2025-69599 preview

CVE-2025-69599

GitHubwise-security/cve-2025-69599

Proof-of-concept exploit for CVE-2025-69599, demonstrating uncontrolled search path element in RayVentory Scan Engine's rvia and ndtrack binaries,…

binary-analysisexploitationpenetration-testing+3
4 months ago
CVE-2024-32002-Exploit preview

CVE-2024-32002-Exploit

GitHubbfengj/cve-2024-32002-exploit

Proof-of-concept exploit for CVE-2024-32002, a Git submodule vulnerability enabling arbitrary code execution via crafted repositories and symlinks.

exploitationpayload-generationpenetration-testing+3
22 years ago
CVE-2024-5082 preview

CVE-2024-5082

GitHubh4mr3r/cve-2024-5082

Proof-of-concept exploit for CVE-2024-5082, a remote code execution vulnerability in Sonatype Nexus Repository Manager 2 via crafted Maven artifacts…

exploitationpayload-developmentpenetration-testing+3
1 month ago
joniles__mpxj_CVE-2020-35460_8-3-4 preview

joniles__mpxj_CVE-2020-35460_8-3-4

GitHubshoucheng3/joniles__mpxj_cve-2020-35460_8-3-4

Exploit for CVE-2020-35460 targeting MPXJ project management library, enabling arbitrary code execution via crafted project files in Java, .Net, and…

code-analysisexploitationstatic-analysis+2
1 year ago
jenkinsci__workflow-cps-global-lib-plugin_CVE-2022-25174_544-vff04fa68714d preview

jenkinsci__workflow-cps-global-lib-plugin_CVE-2022-25174_544-vff04fa68714d

GitHubshoucheng3/jenkinsci__workflow-cps-global-lib-plugin_cve-2022-25174_544-vff04fa68714d

Exploit for CVE-2022-25174 in Jenkins Pipeline Shared Libraries plugin, demonstrating code injection via crafted library definitions for security…

code-analysisdevsecopseducation+2
1 year ago
CVE-2026-38945 preview

CVE-2026-38945

GitHubwise-security/cve-2026-38945

Proof-of-concept exploit for CVE-2026-38945, demonstrating path traversal in RayVentory Scan Engine's Java detection to execute arbitrary binaries.

binary-exploitationeducationexploitation+3
3 months ago
go-get-RCE preview

go-get-RCE

GitHubsaptaktdk/go-get-rce

This is the exploit of CVE-2018-6574: go get RCE

exploitationpayload-generationpenetration-testing+2
1 year ago
xzk8s preview

xzk8s

GitHubr0binak/xzk8s

Dockerfile and Kubernetes manifests for reproduce CVE-2024-3094

cloud-securitycontainer-securityexploitation+3
142 years ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubjvr2022/cve-2026-31802

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

exploitationsupply-chain-securityvulnerability-analysis+1
15 months ago
Previous1…678…25Next