Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2072 results
waybend preview

waybend

GitHubprinciplebreach/waybend

Self-hosted SSRF redirect, payload, callback, and DNS workbench

command-and-controldns-analysisinformation-gathering+9
513 days ago
seclab-taskflows-fuzzing preview

seclab-taskflows-fuzzing

GitHubgithubsecuritylab/seclab-taskflows-fuzzing

An LLM-driven fuzzing pipeline powered by the GitHub Security Lab Taskflow Agent

ai-securitycode-analysisdynamic-analysis-sandboxing+7
14 days ago
CVE-2026-79417 preview

CVE-2026-79417

GitHubconnorjaydunn/cve-2026-79417

Proof-of-concept exploit for CVE-2026-79417, a local denial-of-service vulnerability in Argus Monitor <= 7.4.02, triggered via a signed binary path.

binary-exploitationexploitationvulnerability-analysis
1 day ago
Magento-CVE-2019-7139-SQLi-PoC preview

Magento-CVE-2019-7139-SQLi-PoC

GitHub0xsemz/magento-cve-2019-7139-sqli-poc

Python proof-of-concept exploit for CVE-2019-7139, an unauthenticated SQL injection in Magento's product_frontend_action endpoint, enumerating…

database-securityeducationexploitation+4
81 day ago
netis-cve-2026-36539 preview

netis-cve-2026-36539

GitHubkhaleedbt/netis-cve-2026-36539

Python script that checks Netis routers for CVE-2026-36539, detecting vulnerable devices on a network.

embedded-systems-securityhardware-iot-securityiot-security+4
1 day ago
deleting-the-trace preview

deleting-the-trace

GitHubusama1002/deleting-the-trace

Experiments for control-token chain-of-thought suppression and parser-leniency attacks on tool-using LLM agents

adversarial-attackai-securityexploitation+3
3 days ago
security-portfolio preview

security-portfolio

GitHubmitsu-bis/security-portfolio

Security portfolio of original responsible-disclosure findings, CTF and lab write-ups, methodology notes, and purpose-built pentest tooling covering…

ctfcurated-resourceseducation+6
4 days ago
CVE-2026-94127 preview

CVE-2026-94127

GitHubfurkankayapinar/cve-2026-94127

Read-only defensive detector for CVE-2026-94127 in F5 BIG-IP APM. Fingerprints hosts, checks versions via iControl REST, and verifies OAuth…

configuration-auditingdefensive-toolsincident-response+4
2 days ago
MicroTrick preview

MicroTrick

GitHubdigiprosec/microtrick

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

authenticationembedded-systems-securityexploitation+7
2 days ago
CVE-2026-23921 preview

CVE-2026-23921

GitHubqucklecrabik/cve-2026-23921

Proof-of-concept exploit for CVE-2026-23921, a time-based blind SQL injection in Zabbix API via the sortfield parameter, enabling data extraction…

database-securityexploitationpenetration-testing+3
3 days ago
DROS-VEP-lite preview

DROS-VEP-lite

GitHubtop-celestial-company-ltd/dros-vep-lite

Open-source, 100% reproducible AI Agent Runtime Security Benchmark & Sandbox Environment (RFC-010 Draft Protocol).

ai-securitydefensive-toolsdynamic-analysis-sandboxing+8
113 days ago
cve-2026-28576 preview

cve-2026-28576

GitHubaayushbankar/cve-2026-28576

PoC and red team app for CVE-2026-28576, a zero-permission SQL injection in the Android Contacts Provider enabling full contacts database…

android-securitydata-exfiltrationexploitation+6
4 days ago
radioguard preview

radioguard

GitHubpushkarreddyy/radioguard

Zero-Trust Cellular Defense Sub-Service for Android (IMSI-Catcher, 2G SMS Blaster, and 4G aLTEr Detection & Safe Routing)

android-securityanomaly-detectiondefensive-tools+7
5 days ago
CVE-2026-41089-Netlogon-RCE-PoC preview

CVE-2026-41089-Netlogon-RCE-PoC

GitHubgillarchnganasan2735/cve-2026-41089-netlogon-rce-poc

Automate Netlogon CVE-2026-41089 validation and defensive testing through integrated AI security workflows, enabling rapid risk assessment and…

defensive-toolseducationexploitation+5
4 days ago
Magnohost-Vulnerabilities-pentest preview

Magnohost-Vulnerabilities-pentest

GitHub0ord/magnohost-vulnerabilities-pentest

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

exploitationinformation-gatheringnetwork-security+8
14 months ago
CVE-2026-19586 preview

CVE-2026-19586

GitHubmattgsys/cve-2026-19586

Python PoC exploiting CVE-2026-19586, an unauthenticated command injection in TP-Link Omada SSL VPN that executes arbitrary commands as root via…

command-and-controlcryptographyembedded-systems-security+6
11 month ago
CVE-2026-68121 preview

CVE-2026-68121

GitHubhorkimhab/cve-2026-68121

Proof-of-concept for CVE-2026-68121 (PPPoEject), providing a Python exploit implementation for authorized security research and lab testing.

educationexploitationlabs-practice+4
5 days ago
CVE-2026-77635 preview

CVE-2026-77635

GitHubabraxas/cve-2026-77635

Disclosure pack and Python PoC for CVE-2026-77635, an unauthenticated SQL injection in CakePHP's jsonValue() with PostgresDriver, including a…

database-securityexploitationlabs-practice+5
6 days ago
Previous12…100Next