Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1668 results
CVE-2026-63292 preview

CVE-2026-63292

GitHub0xblackash/cve-2026-63292

Documents CVE-2026-63292, a stack-based buffer overflow in Apache mod_vhost_alias, with affected versions, safe version and configuration checks, and…

configuration-auditingdefensive-toolseducation+4
16h 42m ago
CVE-2026-20817 preview

CVE-2026-20817

GitHubzerodayevil/cve-2026-20817

Repository dedicated to CVE-2026-20817, providing vulnerability details and exploitation material for this specific security flaw.

exploitationpapers-researchvulnerability-analysis+1
244 days ago
CVE-2026-30951 preview

CVE-2026-30951

GitHubyym8538/cve-2026-30951

Proof-of-concept and vulnerable Node.js/Express/Sequelize app demonstrating CVE-2026-30951, a JSON cast-type SQL injection in Sequelize v6 where…

database-securityeducationexploitation+4
11 month ago
CVE-2026-42980-PoC preview

CVE-2026-42980-PoC

GitHubzerodayevil/cve-2026-42980-poc

Proof-of-concept code demonstrating CVE-2026-42980, providing a reproducible test case to validate the vulnerability and verify patched or mitigated…

exploitationpenetration-testingvulnerability-analysis+2
304 days ago
security-harness preview

security-harness

GitHubdmdhrumilmistry/security-harness

Multi-agent static application-security review harness for AI coding agents: maps codebases, hunts vulnerability classes, chains and verifies…

ai-securitycode-analysisdevsecops+9
225 days ago
VulnForge preview

VulnForge

GitHubrootless-ghost/vulnforge

Vulnerability & exploit intelligence — ExploitDB, NVD, Metasploit search with CVE→ATT&CK mapping and LogNorm/HuntForge integration | Part of Nebula…

exploitationinformation-gatheringred-teaming+5
12 months ago
YellowKey-BitLocker-CVE-2026-45585 preview

YellowKey-BitLocker-CVE-2026-45585

GitHubyellowkeybitlocker-cve/yellowkey-bitlocker-cve-2026-45585

YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for…

configuration-auditingdata-recoverydefensive-tools+5
25 days ago
CVE-2026-46595-proof preview

CVE-2026-46595-proof

GitHubsdodson/cve-2026-46595-proof

Go proof-of-concept demonstrating CVE-2026-46595 in golang.org/x/crypto/ssh, using symbol inspection of stripped binaries and image scans to verify…

binary-analysiscode-analysiscontainer-security+4
7 days ago
CVE-2026-48842 preview

CVE-2026-48842

GitHub4minx/cve-2026-48842

Python PoC for CVE-2026-48842, a pre-auth SQL injection in Roundcube's virtuser_query plugin. Confirms the flaw via time-based differential and…

database-securityexploitationpenetration-testing+4
4 days ago
akca preview

akca

GitHubakha-security/akca

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

api-security-testingdefensive-toolsdynamic-analysis-sandboxing+9
1776 days ago
CVE-2026-87915-PoC-pwnVader preview

CVE-2026-87915-PoC-pwnVader

GitHubpwnvader/cve-2026-87915-poc-pwnvader

Shell PoC for CVE-2026-87915, an unauthenticated stored XSS in the Popup Maker WordPress plugin (<=1.24.0). Fingerprints the plugin and demonstrates…

exploitationpenetration-testingvulnerability-analysis+4
10 days ago
CVE-2024-47875 preview

CVE-2024-47875

GitHubd154573r-4v3r73d/cve-2024-47875

Repository dedicated to CVE-2024-47875, providing proof-of-concept material and analysis for this specific vulnerability.

exploitationvulnerability-analysisvulnerability-scanners+1
8 days ago
CVE-2026-94545-nextjs-og-poc preview

CVE-2026-94545-nextjs-og-poc

GitHubhassham1/cve-2026-94545-nextjs-og-poc

Isolated Docker lab and non-destructive Python scanner reproducing CVE-2026-94545, the Next.js next/og ImageResponse SVG injection, with vulnerable…

exploitationlabs-practicevulnerability-analysis+3
19 days ago
CVE-2026-87902-Toolkit preview

CVE-2026-87902-Toolkit

GitHubtc4dy/cve-2026-87902-toolkit

WordPress CVE-2026-87902 LFI-to-RCE toolkit with a weaponized exploit chain (PEAR RCE, webshell, admin creation, loot) and a non-intrusive…

defensive-toolseducationexploitation+8
105 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubzer0dayf/cve-2026-87902

Python PoC script for CVE-2026-87902 that performs basic checks against a target WordPress URL with configurable page, depth, prefix, and timeout…

exploitationpenetration-testingvulnerability-analysis+3
9 days ago
CVE-2026-93485 preview

CVE-2026-93485

GitHub0xblackash/cve-2026-93485

Defensive research repository for CVE-2026-93485, a WordPress core stored XSS flaw, with version-check scanner, technical analysis, and patch…

defensive-toolseducationpapers-research+3
10 days ago
CVE-2026-18322 preview

CVE-2026-18322

GitHubi3it/cve-2026-18322

Root-cause analysis, passive version checker, and lab PoC for CVE-2026-18322, an unauthenticated privilege escalation in the Smart Popup by Supsystic…

exploitationlabs-practicepapers-research+7
1 month ago
CVE-2026-5118 preview

CVE-2026-5118

GitHubsangsenimanwartefak/cve-2026-5118

Detection tooling for CVE-2026-5118, an unauthenticated privilege escalation in Divi Form Builder <= 5.1.2, identifying affected WordPress…

defensive-toolseducationinformation-gathering+5
10 days ago
Previous12…93Next