Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
405 results
CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass. preview

CVE-2026-87575-CVE-2026-87606-CVE-2026-87491-and-CVE-2026-85046.-Escape-the-v8-carcass.

GitHubsneakynachos/cve-2026-87575-cve-2026-87606-cve-2026-87491-and-cve-2026-85046.-escape-the-v8-carcass.

Chained Chrome V8 renderer escape proof-of-concept exploiting four CVEs: Float64Array corruption, Wasm overwrite, popup navigation retargeting, and…

binary-exploitationexploitationpapers-research+5
5
12 days ago
VectorFreed preview

VectorFreed

GitHubrafabd1/vectorfreed

Documents the VectorFreed librsvg use-after-free RCE chain (CVE-2026-96889) with an SVG generator PoC and remediation guidance for librsvg, Next.js,…

binary-exploitationexploitationinformation-gathering+4
82 days ago
CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM- preview

CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM-

GitHubg4sp4rcs/cve-2019-11707-from-an-ionmonkey-type-confusion-to-system-

Windows proof-of-concept exploit chain for CVE-2019-11707, a Firefox IonMonkey type confusion, combining browser RCE with sandbox escape to achieve…

binary-exploitationeducationexploitation+6
4 days ago
CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter preview

CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

GitHubsneakynachos/cve-2026-87491-and-cve-2026-85046-the-bagel-fell-off-the-counter

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

binary-exploitationexploitationmemory-forensics+3
316 days ago
Writeups preview

Writeups

GitHubserotav/writeups

Collection of detailed and optimized(?) write-ups for various CTF challenges

binary-exploitationctfeducation+5
116 days ago
CVE-2024-2961-XXE-Exploit preview

CVE-2024-2961-XXE-Exploit

GitHubqinglove777/cve-2024-2961-xxe-exploit

CVE-2024-2961 (CNEXT) PHP file-read to RCE exploit adapted to an XXE/CTF channel

binary-exploitationctfexploitation+3
18 days ago
CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm preview

CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm

GitHubsneakynachos/cve-2026-85046-who-put-the-silverback-guerilla-in-the-wasm

Proof-of-concept exploit for CVE-2026-85046 in Chrome 152.0.7977.75, demonstrating type confusion in sort() to achieve arbitrary code execution via a…

binary-exploitationexploitationvulnerability-analysis+1
119 days ago
misfortune-cookie preview

misfortune-cookie

GitHubluel-4013/misfortune-cookie

Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with…

binary-exploitationembedded-systems-securityexploitation+6
20 days ago
EXPLOIT-CVE-2026-22778 preview

EXPLOIT-CVE-2026-22778

GitHubjoaovicdev/exploit-cve-2026-22778

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

binary-exploitationeducationexploitation+5
22 days ago
CVE-2026-33453 preview

CVE-2026-33453

GitHubdinosn/cve-2026-33453

Provides working proof-of-concept exploits and detailed analysis for three critical Apache Camel vulnerabilities, including CoAP header injection and…

binary-exploitationeducationexploitation+4
5 months ago
CVE-2026-82592 preview

CVE-2026-82592

GitHubhackspeak/cve-2026-82592

Proof-of-concept exploit for D-Link DIR-825M stack buffer overflow and command injection in /boafrm/formDiskFormat, enabling remote code execution as…

binary-exploitationexploitationhardware-iot-security+4
226 days ago
cve-2025-20333 preview

cve-2025-20333

GitHubcobbbex/cve-2025-20333

Complete research and exploitation toolkit for CVE-2025-20333, a critical stack buffer overflow in Cisco ASA/FTD WebVPN. Includes detailed binary…

binary-exploitationeducationexploitation+4
27 days ago
cve-2026-42945 preview

cve-2026-42945

GitHubfranklinf25/cve-2026-42945

Analyzes CVE-2026-42945, an NGINX rewrite heap overrun, providing a differential detector, deterministic DoS PoC, and a credited RCE port with…

binary-exploitationeducationexploitation+3
28 days ago
CVE-2026-82539 preview

CVE-2026-82539

GitHubxernary/cve-2026-82539

Security advisory for TOTOLINK a720r buffer overflow vulnerability

binary-exploitationembedded-systems-securityexploitation+5
415 days ago
CitrixBleedCVE-2026-8452-2025-5777 preview

CitrixBleedCVE-2026-8452-2025-5777

GitHubmaxprog-svg/citrixbleedcve-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

exploitationinformation-gatheringpenetration-testing+3
28 days ago
log4j2-rce preview

log4j2-rce

GitHubhypnguyen1209/log4j2-rce

Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

binary-exploitationexploitationpayload-development+2
371 month ago
PAN-OS-User-ID-Buffer-Overflow-PoC preview

PAN-OS-User-ID-Buffer-Overflow-PoC

GitHubqassam-315/pan-os-user-id-buffer-overflow-poc

A research-grade Proof-of-Concept (PoC) for CVE-2026-0300, targeting the Buffer Overflow vulnerability in Palo Alto Networks PAN-OS User-ID™…

binary-exploitationexploitationpenetration-testing+2
34 months ago
CVE-2026-42778-POC preview

CVE-2026-42778-POC

GitHubakinfue/cve-2026-42778-poc

CVE-2026-42778 EUVD-2026-26492 Deserialization of Untrusted Data (CWE-502)

binary-exploitationexploitationpayload-development+2
4 months ago
Previous12…23Next