Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
148 results
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
1
7 days ago
CVE-2026-81000 preview

CVE-2026-81000

GitHubhorkimhab/cve-2026-81000

Educational CVE-2026-81000 proof-of-concept repository for authorized security research, vulnerability awareness, and controlled lab testing.

educationexploitationlabs-practice+4
8 days ago
news-8.6.0-cve-2026-8726-backport preview

news-8.6.0-cve-2026-8726-backport

GitHubshentao83/news-8.6.0-cve-2026-8726-backport

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

database-securitydefensive-toolsstatic-code-analysis+3
10 days ago
GoCD_PoC_Supply_Chain_Attack preview

GoCD_PoC_Supply_Chain_Attack

GitHubhigorgabrieldcf/gocd_poc_supply_chain_attack

CVE-2021-43287 CVE-2021-43288 CVE-2021-43289 CVE-2021-43290

educationexploitationpayload-generation+7
212 days ago
CVE-2026-19975 preview

CVE-2026-19975

GitHubhorkimhab/cve-2026-19975

Proof-of-concept and research repository for CVE-2026-19975 in Azuriom, with setup instructions and a linked technical writeup for authorized…

educationexploitationlabs-practice+3
12 days ago
XXStrike preview

XXStrike

GitHubanonmoty/xxstrike

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

dynamic-code-analysisfuzzingpenetration-testing+5
314 days ago
CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter preview

CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

GitHubsneakynachos/cve-2026-87491-and-cve-2026-85046-the-bagel-fell-off-the-counter

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

binary-exploitationexploitationmemory-forensics+3
317 days ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
1113 days ago
CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184 preview

CVE-2026-13181-CVE-2026-13182-CVE-2026-13183-CVE-2026-13184

GitHubhorkimhab/cve-2026-13181-cve-2026-13182-cve-2026-13183-cve-2026-13184

Educational proof-of-concept for Telerik padding oracle vulnerabilities (CVE-2026-13181-184) with scripts for authorized security testing and…

curated-resourceseducationexploitation+3
22 days ago
CVE-Chamilo-LMS preview

CVE-Chamilo-LMS

GitHubhorkimhab/cve-chamilo-lms

CVE-2026-61578, CVE-2026-61582, CVE-2026-61583, CVE-2026-61584, CVE-2026-61585, CVE-2026-61587, CVE-2026-61600, CVE-2026-61601, CVE-2026-61602,…

curated-resourceseducationexploitation+3
25 days ago
admin-panel-finder preview

admin-panel-finder

GitHubbdblackhat/admin-panel-finder

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

information-gatheringpenetration-testingreconnaissance+2
1914 years ago
CVE-2023-27350-CVE-2023-27351 preview

CVE-2023-27350-CVE-2023-27351

GitHubhorkimhab/cve-2023-27350-cve-2023-27351

Educational proof-of-concept for PaperCut pre-auth RCE chain (CVE-2023-27350, CVE-2023-27351) with setup scripts and authorized testing guidance.

educationexploitationpenetration-testing+2
1 month ago
CVE-2021-21017 preview

CVE-2021-21017

GitHubtzwlhack/cve-2021-21017

Proof-of-concept exploit for CVE-2021-21017, an Adobe Reader type confusion leading to out-of-bounds read and heap overflow, with technical analysis…

binary-analysisexploitationmemory-forensics+2
4 years ago
CVE-2026-33555 preview

CVE-2026-33555

GitHubr3verii/cve-2026-33555

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users…

exploitationnetwork-securitypapers-research+3
25 months ago
CVE-2026-1281-Ivanti-EPMM-RCE preview

CVE-2026-1281-Ivanti-EPMM-RCE

GitHubmehdiledeaut/cve-2026-1281-ivanti-epmm-rce

Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion

exploitationpayload-developmentpenetration-testing+3
67 months ago
CVE-2026-19912-CVE-2026-19913-CVE-2026-19914 preview

CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

GitHubhorkimhab/cve-2026-19912-cve-2026-19913-cve-2026-19914

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

educationexploitationpenetration-testing+3
1 month ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubcyber-niz/cve-2020-9496

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

exploitationpayload-generationpenetration-testing+2
5 years ago
gf preview

gf

GitHubtomnomnom/gf

A wrapper around grep, to help you grep for things

code-analysisdynamic-code-analysisgeneral-purpose-utilities+7
2.1k6 years ago
Previous12…9Next