Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
CVE-2026-23002-5G-NAS-Message-Buffer-Overflow-in-gNodeB preview

CVE-2026-23002-5G-NAS-Message-Buffer-Overflow-in-gNodeB

GitHubgeorge0papasotiriou/cve-2026-23002-5g-nas-message-buffer-overflow-in-gnodeb

Simulated 5G gNodeB NAS parser with stack buffer overflow PoC for CVE-2026-23002; a crafted NAS message triggers remote code execution.

binary-exploitationembedded-systems-securityexploitation+2
20 days ago
CVE-2014-4481 preview

CVE-2014-4481

GitHubfeliam/cve-2014-4481

Proof-of-concept exploit for Apple CoreGraphics CCITT heap overflow (CVE-2014-4481) enabling arbitrary code execution in Mobile Safari via crafted…

binary-exploitationexploitationios-security+3
511 years ago
CVE-2022-21971-Windows-Runtime-RCE preview

CVE-2022-21971-Windows-Runtime-RCE

GitHubtufanturhan/cve-2022-21971-windows-runtime-rce

Proof-of-concept exploit for CVE-2022-21971, an uninitialized pointer free vulnerability in Windows Runtime's prauthproviders.dll, triggered via…

binary-exploitationdebuggersexploitation+3
24 years ago
CVE-2019-12086 preview

CVE-2019-12086

GitHubal1ex/cve-2019-12086

Exploit for CVE-2019-12086, a Jackson deserialization vulnerability, using a rogue MySQL server to read arbitrary files from vulnerable applications.

database-securityexploitationpayload-generation+2
16 years ago
CVE-2024-55968 preview

CVE-2024-55968

GitHubwi1dn00b/cve-2024-55968

Proof-of-concept exploit for CVE-2024-55968, a macOS local privilege escalation via an unvalidated XPC helper in DTEX Event Forwarder, abusing the…

binary-exploitationexploitationpenetration-testing+2
21 year ago
CVE-2025-66849 preview

CVE-2025-66849

GitHubwojtekchwala/cve-2025-66849

Proof-of-concept exploit for a stored XSS vulnerability in Ghost CMS (CVE-2025-66849) enabling privilege escalation from Contributor to Owner via…

exploitationpayload-developmentpenetration-testing+3
4 months ago
CVE-2026-5203 preview

CVE-2026-5203

GitHubcaginkyr/cve-2026-5203

Exploit for CVE-2026-5203 in CMS Made Simple, leveraging path traversal and arbitrary file upload to achieve remote code execution with an…

exploitationpayload-generationpenetration-testing+2
3 months ago
CVE-2023-51764-POC preview

CVE-2023-51764-POC

GitHubd4op/cve-2023-51764-poc

Python 3 proof-of-concept for CVE-2023-51764 SMTP smuggling vulnerability, enabling email spoofing via crafted SMTP sessions.

email-securityexploitationpayload-development+2
12 years ago
CVE-2025-56499 preview

CVE-2025-56499

GitHubcherrling/cve-2025-56499

Proof-of-concept exploit for CVE-2025-56499, demonstrating arbitrary file read via missing path validation in mihomo's rule-provider configuration,…

exploitationinformation-gatheringlog-analysis+3
9 months ago
CVE-2022-45299 preview

CVE-2022-45299

GitHuboffalltn/cve-2022-45299

Proof-of-concept exploit for CVE-2022-45299, demonstrating arbitrary command execution via unfiltered URL input in the webbrowser-rs library before…

command-and-controlexploitationpayload-development+2
11 year ago
CVE-2025-63914 preview

CVE-2025-63914

GitHubwxdou/cve-2025-63914

Public disclosure and patch for CVE-2025-63914, a zip bomb vulnerability in Cinnamon/kotaemon, including PoC and mitigation.

exploitationvulnerability-analysisweb-security
8 months ago
cve-2019-5737 preview

cve-2019-5737

GitHubbeelzebruh/cve-2019-5737

Exploit for CVE-2019-5737, a Docker runc container escape vulnerability, with build and run instructions for Linux and Windows.

cloud-securitycontainer-escapecontainer-security+3
7 years ago
CVE-2013-3664_BMP preview

CVE-2013-3664_BMP

GitHubdefrancescojp/cve-2013-3664_bmp

Proof-of-concept exploit for CVE-2013-3664: heap overflow in SketchUp BMP RLE4 texture parsing enabling arbitrary code execution via malicious .skp…

binary-exploitationexploitationfuzzing+2
6 years ago
CVE-2019-5736 preview

CVE-2019-5736

GitHubsi1ent-le/cve-2019-5736

Proof-of-concept exploit for CVE-2019-5736, a Docker container escape via runc binary overwrite, enabling host shell access through libseccomp…

binary-exploitationcontainer-escapeexploitation+3
4 years ago
CVE-2022-21974 preview
Archived

CVE-2022-21974

GitHub0vercl0k/cve-2022-21974

PoC and root-cause analysis for CVE-2022-21974, an uninitialized pointer free in RMSRoamingSecurity that yields remote code execution via crafted RTF…

binary-exploitationdebuggersexploitation+3
574 years ago
CVE-2022-21971 preview
Archived

CVE-2022-21971

GitHub0vercl0k/cve-2022-21971

Proof-of-concept exploit for CVE-2022-21971, demonstrating an uninitialized pointer free in Windows prauthproviders that triggers remote code…

binary-exploitationdebuggersexploitation+3
3024 years ago
ALPC-Enumerator preview

ALPC-Enumerator

GitHubtalha-nazeef-ahmed/alpc-enumerator

A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes.

digital-forensicsinformation-gatheringmalware-analysis+4
2413 days ago
HTTP3ONSTEROIDS preview

HTTP3ONSTEROIDS

GitHubdhmosfunk/http3onsteroids

PoC and lab environment for CVE-2023-25950: HTTP request smuggling via malformed header fields in HAProxy's HTTP/3 implementation, enabling DoS and…

educationlabs-practicevulnerability-analysis+1
111 year ago
Previous1234567Next