Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
ironcurtain preview

ironcurtain

GitHubprovos/ironcurtain

A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)

ai-securitycontainer-securitydynamic-analysis-sandboxing+3
613
8h 46m ago
Tyr preview

Tyr

GitLabcyberactivity/tyr

Tools collection to explore CVE and theirs associated data.

information-gatheringthreat-intelligenceutilities-frameworks+1
20h 29m ago
PurpleLlama preview

PurpleLlama

GitHubmeta-llama/purplellama

Set of tools to assess and improve LLM security.

adversarial-attackai-securitycode-analysis+4
4.4k7 days ago
CVE-2026-100381 preview

CVE-2026-100381

GitHubbombobombone/cve-2026-100381

Report and PoC for CVE-2026-100381, a DOM XSS in MediaWiki UploadWizard Flickr collection and set titles, with patch verification notes and a local…

exploitationvulnerability-analysisweb-application-exploitation+1
8 days ago
CVE-2026-34990-poc preview

CVE-2026-34990-poc

GitHubkhush-613/cve-2026-34990-poc

Proof-of-concept exploit for CVE-2026-34990, a CUPS 2.4.16 local privilege escalation via arbitrary file write through CUPS_CREATE_LOCAL_PRINTER and…

exploitationpayload-developmentpenetration-testing+4
29 days ago
CVE-2026-100740 preview

CVE-2026-100740

GitHubmurrez/cve-2026-100740

Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and…

embedded-systems-securityexploitationfirmware-analysis+6
110 days ago
CVE-2026-92680 preview

CVE-2026-92680

GitHubgrepstrength/cve-2026-92680

Proof-of-concept decrypting Araxis Merge's DPAPI-protected server credentials (CVE-2026-92680), demonstrating insufficiently protected credential…

cryptographyexploitationpassword-cracking+1
113 days ago
gosentry preview

gosentry

GitHubtrailofbits/gosentry

Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.

binary-analysiscode-analysisdevsecops+5
12215 days ago
Grafana-Final-Scanner preview

Grafana-Final-Scanner

GitHubzierax/grafana-final-scanner

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

configuration-auditinginformation-gatheringvulnerability-analysis+3
24326 days ago
weakrng-sweep preview

weakrng-sweep

GitHubbrendonlee20042004-sys/weakrng-sweep

Weak-RNG stream-sweep research (CVE-2026-71851 class): PRNG schemes x seeds -> BIP39 -> victim set membership

cryptographycurated-resourceseducation+1
1 month ago
CVE-2026-4692-trust-me-im-in-rdm preview

CVE-2026-4692-trust-me-im-in-rdm

GitHubsneakynachos/cve-2026-4692-trust-me-im-in-rdm

Proof-of-concept exploit for Firefox BrowsingContext authorization bypass (CVE-2026-4692), demonstrating forged IPC messages to set InRDMPane and…

exploitationexploit-frameworkspayload-development+4
11 month ago
Exploit-For-CVE-2026-18963 preview

Exploit-For-CVE-2026-18963

GitHubblackhatexploitation/exploit-for-cve-2026-18963

Exploit for CVE-2026-18963, a critical unauthenticated account takeover in Keycloak's reset-credentials flow, chaining two bugs to bypass email…

authenticationexploitationpenetration-testing+3
1 month ago
SAFE preview

SAFE

GitHubnanda-rani/safe

A contextual security auditing system for research artifacts

ai-securitycode-analysiseducation+2
1 month ago
sitedorks preview

sitedorks

GitHubzarcolio/sitedorks

Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.

dns-subdomain-enumerationinformation-gatheringosint+3
1.1k1 month ago
CVE-2025-7384 preview

CVE-2025-7384

GitHubdungsocool/cve-2025-7384

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

educationexploitationlabs-practice+2
2 months ago
CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb- preview

CVE-2026-67184-Unauthenticated-NULL-Pointer-Dereference-Crashes-the-Server-TinyWeb-

GitHubtheopaid/cve-2026-67184-unauthenticated-null-pointer-dereference-crashes-the-server-tinyweb-

Security Advisory: Unauthenticated NULL Pointer Dereference Crashes the Server (TinyWeb)

educationexploitationpapers-research+2
12 months ago
CloudPrivs preview

CloudPrivs

GitHubabstractclass/cloudprivs

Determine privileges from cloud credentials via brute-force testing.

cloud-securityinformation-gatheringpenetration-testing+2
692 months ago
exim-rce-cve-2018-6789 preview

exim-rce-cve-2018-6789

GitHubmartinclauss/exim-rce-cve-2018-6789

This repository provides a learning environment to understand how an Exim RCE exploit for CVE-2018-6789 works.

binary-exploitationdebuggerseducation+3
112 months ago
Previous12…8Next