Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
3022 results
CVE-2026-63292 preview

CVE-2026-63292

GitHub0xblackash/cve-2026-63292

Documents CVE-2026-63292, a stack-based buffer overflow in Apache mod_vhost_alias, with affected versions, safe version and configuration checks, and…

configuration-auditingdefensive-toolseducation+4
16h 41m ago
CVE-2026-18143 preview

CVE-2026-18143

GitHubwayang1337/cve-2026-18143

Request a Quote for WooCommerce (Addify) <= 2.9.2 Unauthenticated arbitrary file upload via afrfq_submit_quote_via_popup

exploitationvulnerability-analysisweb-application-exploitation+2
4 days ago
CVE-2026-20817 preview

CVE-2026-20817

GitHubzerodayevil/cve-2026-20817

Repository dedicated to CVE-2026-20817, providing vulnerability details and exploitation material for this specific security flaw.

exploitationpapers-researchvulnerability-analysis+1
244 days ago
CVE-2026-73570 preview

CVE-2026-73570

GitHub0xblackash/cve-2026-73570

Advisory and detection guidance for CVE-2026-73570, an unauthenticated OS command injection in Zimbra SNMP notification processing leading to remote…

defensive-toolseducationemail-security+6
12 days ago
CVE-2026-30951 preview

CVE-2026-30951

GitHubyym8538/cve-2026-30951

Proof-of-concept and vulnerable Node.js/Express/Sequelize app demonstrating CVE-2026-30951, a JSON cast-type SQL injection in Sequelize v6 where…

database-securityeducationexploitation+4
11 month ago
CVE-2026-42980-PoC preview

CVE-2026-42980-PoC

GitHubzerodayevil/cve-2026-42980-poc

Proof-of-concept code demonstrating CVE-2026-42980, providing a reproducible test case to validate the vulnerability and verify patched or mitigated…

exploitationpenetration-testingvulnerability-analysis+2
304 days ago
CVE-2026-39987-Marimo-Preauth-RCE preview

CVE-2026-39987-Marimo-Preauth-RCE

GitHublaarana12/cve-2026-39987-marimo-preauth-rce

Reproduction and root cause analysis of CVE-2026-39987 Marimo pre-auth WebSocket RCE in a local Docker lab.

container-securityeducationexploitation+5
13 days ago
CVE-2026-10817 preview

CVE-2026-10817

GitHubhorkimhab/cve-2026-10817

Educational security research repository for CVE-2026-10817, providing proof-of-concept material and lab guidance for authorized vulnerability…

curated-resourcesdefensive-toolseducation+5
3 days ago
security-harness preview

security-harness

GitHubdmdhrumilmistry/security-harness

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

ai-securitycode-analysisdevsecops+9
225 days ago
VulnForge preview

VulnForge

GitHubrootless-ghost/vulnforge

Vulnerability & exploit intelligence — ExploitDB, NVD, Metasploit search with CVE→ATT&CK mapping and LogNorm/HuntForge integration | Part of Nebula…

exploitationinformation-gatheringred-teaming+5
12 months ago
YellowKey-BitLocker-CVE-2026-45585 preview

YellowKey-BitLocker-CVE-2026-45585

GitHubyellowkeybitlocker-cve/yellowkey-bitlocker-cve-2026-45585

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for…

configuration-auditingdata-recoverydefensive-tools+5
25 days ago
CVE-2026-46595-proof preview

CVE-2026-46595-proof

GitHubsdodson/cve-2026-46595-proof

Go proof-of-concept demonstrating CVE-2026-46595 in golang.org/x/crypto/ssh, using symbol inspection of stripped binaries and image scans to verify…

binary-analysiscode-analysiscontainer-security+4
7 days ago
CVE-2026-48842 preview

CVE-2026-48842

GitHub4minx/cve-2026-48842

Python PoC for CVE-2026-48842, a pre-auth SQL injection in Roundcube's virtuser_query plugin. Confirms the flaw via time-based differential and…

database-securityexploitationpenetration-testing+4
4 days ago
akca preview

akca

GitHubakha-security/akca

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

api-security-testingdefensive-toolsdynamic-analysis-sandboxing+9
1776 days ago
CVE-2026-87915-PoC-pwnVader preview

CVE-2026-87915-PoC-pwnVader

GitHubpwnvader/cve-2026-87915-poc-pwnvader

Shell PoC for CVE-2026-87915, an unauthenticated stored XSS in the Popup Maker WordPress plugin (<=1.24.0). Fingerprints the plugin and demonstrates…

exploitationpenetration-testingvulnerability-analysis+4
10 days ago
CVE-2025-9974 preview

CVE-2025-9974

GitHubhorkimhab/cve-2025-9974

Educational security research repository for CVE-2025-9974, providing vulnerability awareness material and authorized lab guidance for controlled…

curated-resourceseducationexploitation+3
7 days ago
CVE-2026-65660 preview

CVE-2026-65660

GitHubhorkimhab/cve-2026-65660

Educational security research repository documenting CVE-2026-65660 with setup guidance for authorized lab testing and vulnerability awareness.

curated-resourceseducationexploitation+4
8 days ago
VectorFreed preview

VectorFreed

GitHubrafabd1/vectorfreed

Documents the VectorFreed librsvg use-after-free RCE chain (CVE-2026-96889) with an SVG generator PoC and remediation guidance for librsvg, Next.js,…

binary-exploitationexploitationinformation-gathering+4
171 day ago
Previous12…100Next