Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
48 results
file-notification-attacks preview

file-notification-attacks

GitHubisec-tugraz/file-notification-attacks

Research artifacts for file-notification side-channel attacks on Linux, Windows, and macOS, demonstrating inotify/FSEvents leakage, keystroke timing,…

android-securityeducationexploitation+6
1
10 days ago
zte-smartlife-app-pwned preview

zte-smartlife-app-pwned

GitHubminanagehsalalma/zte-smartlife-app-pwned

ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.

android-securityapi-securitycryptography+7
10 days ago
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day preview

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

android-securityeducationexploitation+7
314 days ago
the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss preview

the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

GitHubhunt-benito/the-callback-that-outlived-the-page-cve-2026-78997-uc-browser-android-universal-xss

PoC for CVE-2026-78997, a Universal XSS in UC Browser for Android. Includes a crafted URL builder, a callback-dispatch oracle, and Frida hooks to…

android-securitydynamic-analysis-sandboxingexploitation+6
20 days ago
CVE-2026-28576-poc preview

CVE-2026-28576-poc

GitHubmobilehackinglab/cve-2026-28576-poc

Educational proof-of-concept demonstrating a SQL injection vulnerability in Android 17's Contacts Provider, allowing a zero-permission app to…

android-securityeducationexploitation+4
4024 days ago
poc-CVE-2026-0073 preview

poc-CVE-2026-0073

GitHubadityatelange/poc-cve-2026-0073

CVE-2026-0073 - ADB Wireless Mutual Authentication Bypass PoC

android-securityexploitationmobile-security+3
664 months ago
CVE-2026-5281-CVE-2026-11057-fullchain preview

CVE-2026-5281-CVE-2026-11057-fullchain

GitHubjaf0rk/cve-2026-5281-cve-2026-11057-fullchain

Full-chain exploit for Android Chromium combining CVE-2026-11057 info leak and CVE-2026-5281 use-after-free to achieve vtable hijack and arbitrary…

android-securitybinary-exploitationexploitation+4
1 month ago
meesho-android-improper-encryption-cve-2026-5682 preview

meesho-android-improper-encryption-cve-2026-5682

GitHubhonestcorrupt/meesho-android-improper-encryption-cve-2026-5682

Proof of concept demonstrating insecure AES-CBC encryption with MD5 key derivation in the Meesho Android app, enabling ciphertext tampering and…

android-securitycryptographymobile-security+3
6 months ago
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal preview

two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

GitHubhunt-benito/two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

android-securityexploitationmobile-app-pentesting+4
1 month ago
ConscryptTrustUserCerts preview

ConscryptTrustUserCerts

GitHubnccgroup/conscrypttrustusercerts

Magisk module for Android 14 that adds user-installed CA certificates to the system's Conscrypt trust store, enabling HTTPS interception with proxy…

android-securitymobile-app-pentestingpenetration-testing+1
1642 years ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1031 year ago
nextcloud_android preview

nextcloud_android

GitHubshanika04/nextcloud_android

SQLi CVE-2019-5454

android-securitymobile-securitypenetration-testing+2
5 years ago
CVE-2019-8389 preview

CVE-2019-8389

GitHubshawarkhanethicalhacker/cve-2019-8389

[CVE-2019-8389] An exploit code for exploiting a local file read vulnerability in Musicloud v1.6 iOS Application

exploitationios-securitymobile-security+2
107 years ago
xiaomi-cve-2024-45352 preview

xiaomi-cve-2024-45352

GitHubedwins907/xiaomi-cve-2024-45352

Reporte técnico sobre vulnerabilidad crítica de Xiaomi

android-securityexploitationmobile-security+2
1 year ago
AOSP-DownloadProviderDbDumperSQLiLimit preview

AOSP-DownloadProviderDbDumperSQLiLimit

GitHubioactive/aosp-downloadproviderdbdumpersqlilimit

PoC Exploiting SQL Injection in Android's Download Provider in Sort Parameter (CVE-2019-2196)

android-securityexploitationmobile-security+3
36 years ago
AOSP-DownloadProviderDbDumperSQLiWhere preview

AOSP-DownloadProviderDbDumperSQLiWhere

GitHubioactive/aosp-downloadproviderdbdumpersqliwhere

PoC Exploiting SQL Injection in Android's Download Provider in Selection Parameter (CVE-2019-2198)

android-securityexploitationmobile-security+3
356 years ago
ekoparty preview

ekoparty

GitHubactuator/ekoparty

Ekoparty Miami | Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers

android-securityeducationexploitation+5
3 months ago
CVE-2017-17692 preview

CVE-2017-17692

GitHubspecloli/cve-2017-17692

Proof-of-concept exploit for Same-Origin Policy bypass in Samsung Internet Browser for Android, demonstrating a cross-origin data access…

android-securityexploitationmobile-security+1
8 years ago
Previous123Next