Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
66 results
VLC_CVE-2021-25804_Analysis preview

VLC_CVE-2021-25804_Analysis

GitHubdshankle/vlc_cve-2021-25804_analysis

In-depth technical analysis of CVE-2021-25804, a VLC AVI parser vulnerability. Includes root cause, patch diff, and exploitation primitives for…

binary-analysiscode-analysiseducation+3
4 years ago
aegisgraph preview

aegisgraph

GitHub577industries/aegisgraph

AegisGraph: graph-based application-layer assessment evidence platform for Secure Messaging Applications (SMAs). DARPA ASEMA HR0011SB20254-12 Tier 3…

binary-analysiscryptographycurated-resources+8
21 days ago
CVE-2023-21716 preview

CVE-2023-21716

GitHubfeatherstark/cve-2023-21716

Technical analysis and proof-of-concept exploit for CVE-2023-21716, a heap corruption vulnerability in Microsoft Word's RTF font table parser…

binary-exploitationexploitationpayload-generation+2
43 years ago
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability preview

CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability

GitHubgraysignal/cve-2024-23897-jenkins-arbitrary-read-file-vulnerability

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

data-exfiltrationexploitationinformation-gathering+4
32 years ago
poc-cve-2024-23897 preview

poc-cve-2024-23897

GitHubvmtyan/poc-cve-2024-23897

Proof-of-concept exploit for CVE-2024-23897 enabling remote code execution on Jenkins instances via vulnerable args4j command-line parser. Written in…

exploitationpenetration-testingred-teaming+3
22 years ago
CVE-2016-4437 preview

CVE-2016-4437

GitHubm3terpreter/cve-2016-4437

Proof-of-concept exploit for CVE-2016-4437, an Apache Struts2 remote code execution vulnerability. Demonstrates exploitation of the Jakarta Multipart…

exploitationvulnerability-analysisweb-application-exploitation
5 years ago
samsung-exynos-sms-stack-overflow-cve-2025-54328-critical-zero-click-baseband-rce preview

samsung-exynos-sms-stack-overflow-cve-2025-54328-critical-zero-click-baseband-rce

GitHubhunt-benito/samsung-exynos-sms-stack-overflow-cve-2025-54328-critical-zero-click-baseband-rce

Conceptual PoC for CVE-2025-54328, a critical zero-click stack buffer overflow in Samsung Exynos baseband firmware's SMS RP-DATA parser, enabling…

binary-exploitationeducationembedded-systems-security+5
12 months ago
CVE-2023-24329-lab preview

CVE-2023-24329-lab

GitHubjithinodattu/cve-2023-24329-lab

Self-contained Docker lab demonstrating CVE-2023-24329, a Python urllib parser differential that bypasses URL scheme and host filters, with…

ctfeducationexploitation+4
4 months ago
IAMActionHunter preview

IAMActionHunter

GitHubrhinosecuritylabs/iamactionhunter

An AWS IAM policy statement parser and query tool.

cloud-infrastructure-securitycloud-securityconfiguration-auditing+4
2001 year ago
CVE-2021-36934 preview

CVE-2021-36934

GitHubpreventions/cve-2021-36934

C# PoC for CVE-2021-36934/HiveNightmare/SeriousSAM

binary-exploitationexploitationprivilege-escalation+1
35 years ago
CVE-2020-5903 preview

CVE-2020-5903

GitHubltvthang/cve-2020-5903

Exploit for CVE-2020-5902 targeting F5 BIG-IP RCE via path traversal and JDBC deserialization, enabling command execution, file read/write, and…

exploitationpayload-developmentpenetration-testing+3
6 years ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubmritunjay-k/cve-2017-5638

An exploit for CVE-2017-5638

exploitationpayload-developmentpenetration-testing+2
3 years ago
oletools preview

oletools

GitHubdecalage2/oletools

Python toolkit for analyzing MS OLE2 and Office documents, extracting VBA macros, detecting exploits, and performing forensic analysis of structured…

code-analysisdigital-forensicsforensics+3
3.4k7 months ago
whispers preview
Archived

whispers

GitHubskyscanner/whispers

Identify hardcoded secrets in static structured text

code-analysisconfiguration-auditingdevsecops+4
5052 years ago
Nessus_Map preview

Nessus_Map

GitHubebryx/nessus_map

Parse .nessus file(s) and shows output in interactive UI

information-gatheringvulnerability-analysisvulnerability-scanners
1654 months ago
CVE-2017-8759 preview

CVE-2017-8759

GitHubvysecurity/cve-2017-8759

CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.

exploitationpayload-developmentpenetration-testing+3
1768 years ago
CVE-2023-20052 preview

CVE-2023-20052

GitHubnokn0wthing/cve-2023-20052

CVE-2023-20052, information leak vulnerability in the DMG file parser of ClamAV

exploitationfuzzinginformation-gathering+2
293 years ago
CVE-2026-64638-WordPress-Core-XSS2Shell preview

CVE-2026-64638-WordPress-Core-XSS2Shell

GitHubrenzi25031469/cve-2026-64638-wordpress-core-xss2shell

Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos…

penetration-testingvulnerability-analysisvulnerability-scanners+2
323 days ago
Previous1234Next