Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
7426 results
cve-2026-85706 preview

cve-2026-85706

GitHub0xenesbayram/cve-2026-85706

Root-cause analysis, vulnerable Docker lab, and PoC scripts for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab via parser…

educationexploitationlabs-practice+4
1 day ago
Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526- preview

Gitea-template-sync-Path-Traversal-Privilege-Escalation-CVE-2026-38526-

GitHubshirouuu/gitea-template-sync-path-traversal-privilege-escalation-cve-2026-38526-

PoC and write-up for the HackTheBox "Nexus" privilege escalation: root-run Gitea template-sync service vulnerable to path traversal via forged Git…

ctfeducationexploitation+7
1 day ago
metasploitable3-pentest-writeup preview

metasploitable3-pentest-writeup

GitHubadfortunato/metasploitable3-pentest-writeup

Home-lab penetration test report of Metasploitable3 covering Nmap recon, Drupalgeddon RCE, SQL injection, SSH credential reuse, sudo privilege…

ctfeducationexploitation+8
1 day ago
Mandating-Honeypots-Project preview

Mandating-Honeypots-Project

GitHubtori-tech/mandating-honeypots-project

This repository conducts security audits on digital identity verification systems, identifies vulnerabilities through whitepapers and technical POCs,…

cryptographydefensive-toolseducation+6
228 days ago
CVE-2024-31666 preview

CVE-2024-31666

GitHubshijx1024/cve-2024-31666

Documents CVE-2024-31666, a remote code execution vulnerability in Flusity-CMS v2.33 via the edit_addon_post.php component, including impact and…

exploitationpapers-researchvulnerability-analysis+2
16 months ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubbrigadeops32/cve-2026-85706

Python PoC exploiting CVE-2026-85706, an unauthenticated path traversal and arbitrary file read in GitLab CE/EE via the create-commit endpoint, with…

data-exfiltrationexploitationinformation-gathering+5
1 day ago
Interpreter-HackTheBox preview

Interpreter-HackTheBox

GitHubledksv/interpreter-hackthebox

HackTheBox Interpreter walkthrough: CVE-2023-43208 Mirth Connect deserialization RCE, PBKDF2 hash cracking, and eval() injection privilege escalation…

ctfeducationexploitation+7
3 months ago
cctv preview

cctv

GitHubledksv/cctv

HackTheBox CCTV walkthrough chaining CVE-2024-51482 ZoneMinder SQL injection, bcrypt hash cracking, and CVE-2025-60787 motionEye RCE to obtain root.

ctfeducationexploitation+6
2 days ago
devarea preview

devarea

GitHubledksv/devarea

HackTheBox DevArea walkthrough chaining CVE-2022-46364 Apache CXF SSRF, CVE-2025-54123 Hoverfly RCE, and SUID bash hijacking for root escalation.

ctfeducationexploitation+6
2 months ago
monitorsfour preview

monitorsfour

GitHubledksv/monitorsfour

HackTheBox MonitorsFour walkthrough covering credential leak, CVE-2025-24367 Cacti RCE, and CVE-2025-9074 Docker Desktop API container escape to root.

container-escapectfeducation+7
3 months ago
pterodactyl preview

pterodactyl

GitHubledksv/pterodactyl

HackTheBox Pterodactyl walkthrough chaining CVE-2025-49132 path traversal, hash cracking, and CVE-2025-6018/6019 PAM and XFS race for root.

ctfeducationexploitation+6
2 days ago
wingdata preview

wingdata

GitHubledksv/wingdata

HackTheBox Wingdata walkthrough covering WingFTP CVE-2025-47812 command injection for initial access and tar path traversal sudo privilege escalation…

ctfeducationexploitation+7
2 days ago
CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter preview

CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

GitHubsneakynachos/cve-2026-87491-and-cve-2026-85046-the-bagel-fell-off-the-counter

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

binary-exploitationexploitationmemory-forensics+3
14 days ago
CVE-2026-82222-PoC preview

CVE-2026-82222-PoC

GitHubsajjadsiam/cve-2026-82222-poc

Proof-of-concept and local DDEV lab for CVE-2026-82222, an unauthenticated PHP object injection to RCE in the GiveWP WordPress plugin, with cURL and…

educationexploitationlabs-practice+6
4 days ago
cve-2026-85706-poc-exploit-gitlab preview

cve-2026-85706-poc-exploit-gitlab

GitHub0xlyvio/cve-2026-85706-poc-exploit-gitlab

PoC exploit and writeup for CVE-2026-85706, an unauthenticated arbitrary local file read in GitLab CE/EE via Workhorse path-encoding bypass.

educationexploitationinformation-gathering+4
2 days ago
CVE-2026-33439-Python-PoC preview

CVE-2026-33439-Python-PoC

GitHubinfernosalex/cve-2026-33439-python-poc

Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization

exploitationpenetration-testingremote-access-tool+2
12 days ago
cotonti-commentswidget-poc preview

cotonti-commentswidget-poc

GitHubharshrajsinghania/cotonti-commentswidget-poc

Safe local proof of concept for the Cotonti CommentsWidget PHP object injection vulnerability (CAN-2026-2035973 / CVE-2026-71294).

educationexploitationvulnerability-analysis+1
2 days ago
CVE-2026-77770 preview

CVE-2026-77770

GitHubcflowsec/cve-2026-77770

Python PoC for CVE-2026-77770, an unauthenticated arbitrary WordPress option deletion flaw in the miniOrange 2FA plugin (<= 6.3.0) via the…

exploitationpenetration-testingvulnerability-analysis+2
2 days ago
Previous12…100Next