Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
Enigm-Writeup preview

Enigm-Writeup

GitHubabdelhakimgafernetworksec/enigm-writeup

Comprehensive penetration testing write-up and exploit details for Hack The Box - Enigma machine, covering local enumeration, OliveTin CVE-2026-27626…

ctfeducationexploitation+7
1
13 days ago
tomcat-cve-2025-24813-lab preview

tomcat-cve-2025-24813-lab

GitHubmega-starmie/tomcat-cve-2025-24813-lab

Local reproduction lab for Apache Tomcat CVE-2025-24813, documenting exploitation conditions and AI-assisted verification of the vulnerability.

educationexploitationlabs-practice+4
24 days ago
CVE-2026-3854-lab preview

CVE-2026-3854-lab

GitHubroyaleybovich/cve-2026-3854-lab

Local intentionally vulnerable lab with a guided workshop and CTF challenges for practicing Git push-option RCE, unsafe deserialization,…

ctfeducationexploitation+4
92 months ago
cve-2026-40072-ssrf-lab preview

cve-2026-40072-ssrf-lab

GitHubu1tr0nex/cve-2026-40072-ssrf-lab

Hands-on lab for CVE-2026-40072 — SSRF vulnerability in web3.py via CCIP Read (EIP-3668)

educationlabs-practicepenetration-testing+3
4 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHublucastran05/cve-2026-29000

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

authenticationctfeducation+3
4 months ago
liffy preview

liffy

GitHubmzfr/liffy

Local file inclusion exploitation tool

payload-developmentpenetration-testingvulnerability-analysis+2
1k4 months ago
CVE-2025-27407 preview

CVE-2025-27407

GitHublogggg2402/cve-2025-27407

Local lab and proof-of-concept exploit for CVE-2025-27407, targeting GitLab's GraphQL introspection schema loader via the Direct Transfer HTTP path.…

educationexploitationlabs-practice+3
5 months ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
5 months ago
LFI-Destruction preview

LFI-Destruction

GitHubrevshellxd/lfi-destruction

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

ctfeducationexploitation+8
47 months ago
Mohnad-AL-saif-CVE-2020-11107-XAMPP-Local-Privilege-Escalation preview

Mohnad-AL-saif-CVE-2020-11107-XAMPP-Local-Privilege-Escalation

GitHubmohnad-al-saif/mohnad-al-saif-cve-2020-11107-xampp-local-privilege-escalation

CVE-2020-11107-Local-Privilege-Escalation-XAMPP-7.2.29-7.3.x-7.3.16-7.4.x-7.4.4

exploitationpayload-generationpenetration-testing+3
8 months ago
CVE-2026-22804 preview

CVE-2026-22804

GitHubthemehackers/cve-2026-22804

This repository contains a Proof of Concept (PoC) exploit for the Stored Cross-Site Scripting (XSS) vulnerability in Termix, which can lead to Local…

data-exfiltrationexploitationpayload-development+2
28 months ago
CVE-2025-57457 preview

CVE-2025-57457

GitHubrestdone/cve-2025-57457

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

command-and-controlexploitationpenetration-testing+2
0 years ago
web-threat-mitigation preview

web-threat-mitigation

GitHubbrunoh6/web-threat-mitigation

Hands-on lab on detecting and mitigating web app threats using OWASP ZAP, Burp Suite, and ModSecurity WAF (with OWASP CRS). Case study: Spring4Shell…

configuration-auditingdevsecopseducation+8
1 year ago
CVE-2023-4357-Chrome-XXE preview

CVE-2023-4357-Chrome-XXE

GitHubxcanwin/cve-2023-4357-chrome-xxe

[漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.

ctfcurated-resourceseducation+3
2301 year ago
CVE-2020-13424 preview

CVE-2020-13424

GitHubmkelepce/cve-2020-13424

Joomla! Plugin XCloner Backup 3.5.3 - Local File Inclusion (Authenticated)

exploitationinformation-gatheringpenetration-testing+2
6 years ago
vulnerability-exploitation preview

vulnerability-exploitation

GitHubtharana/vulnerability-exploitation

Local Root vulnerability- CVE-2019-13272 / Security Bypass Vulnerability – CVE-2019-14287/Google Android - 'Stagefright' Remote Code Execution -…

binary-exploitationexploitationmobile-security+3
36 years ago
sagemcom-fast-3890-exploit preview

sagemcom-fast-3890-exploit

GitHublyrebirds/sagemcom-fast-3890-exploit

Exploit for Sagemcom F@ST 3890 cable modem implementing Cable Haunt vulnerability to achieve remote code execution via WebSocket-based buffer…

binary-exploitationembedded-systems-securityexploitation+4
2256 years ago
LFISuite preview

LFISuite

GitHubd35m0nd142/lfisuite

Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

exploitationpayload-generationpenetration-testing+3
2.0k8 years ago
Previous12Next