Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
257 results
CVE-2026-27344 preview

CVE-2026-27344

GitHubac8999/cve-2026-27344

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

api-securityauthentication-authorizationmisconfiguration+3
1 month ago
CVE-2026-3030-Prototype-Pollution-in-JSON-Merge-Patch preview

CVE-2026-3030-Prototype-Pollution-in-JSON-Merge-Patch

GitHubgeorge0papasotiriou/cve-2026-3030-prototype-pollution-in-json-merge-patch

Demonstrates CVE-2026-3030 prototype pollution in a Node.js JSON merge patch REST API, including a vulnerable server and exploit script for privilege…

api-securityeducationexploitation+4
1 month ago
CVE-2026-19650-CVE-2026-19478 preview

CVE-2026-19650-CVE-2026-19478

GitHubhorkimhab/cve-2026-19650-cve-2026-19478

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

api-securityeducationexploitation+4
1 month ago
cve-2026-25994_PJSIP preview

cve-2026-25994_PJSIP

GitHubvabismo/cve-2026-25994_pjsip

PJSIP cve-2026-25994 BUFFER OVERFLOW POC

binary-exploitationeducationexploitation+3
25 months ago
CVE-2026-53959 preview

CVE-2026-53959

GitHubanirbala98/cve-2026-53959

4gaBoards < 3.3.9 - User Information Disclosure

api-securityeducationexploitation+5
11 month ago
AudioCaptchaBypass-CVE-2008-2019 preview

AudioCaptchaBypass-CVE-2008-2019

GitHubtherook/audiocaptchabypass-cve-2008-2019

Exploit for CVE-2008-2019 bypassing audio captcha in Simple Machines Forum 1.1.4 using hamming distance and levenshtein distance to compare PCM audio…

captcha-bypassexploitationfuzzing+2
26 years ago
CVE-2026-3909 preview

CVE-2026-3909

GitHubjaf0rk/cve-2026-3909

Proof-of-concept exploit for CVE-2026-3909, a Chromium Skia out-of-bounds vulnerability, with patches and crash analysis for reliable triggering in…

binary-analysisexploitationfuzzing+2
25 months ago
CVE-2026-35616 preview

CVE-2026-35616

GitHubwa6n3r/cve-2026-35616

Exploit script for CVE-2026-35616 that bypasses certificate chain verification in Fortinet API by discovering valid CNs, generating a forged client…

api-securityexploitationpenetration-testing+2
15 months ago
Log4ShellAuditor preview

Log4ShellAuditor

GitHubc00ln3t/log4shellauditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and…

devsecopsexploitationlabs-practice+6
11 month ago
poc-h2-CVE-2026-71554 preview

poc-h2-CVE-2026-71554

GitHubsunandm/poc-h2-cve-2026-71554

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

adversarial-attackapi-securityapi-security-testing+4
11 month ago
CVE-2026-33186 preview

CVE-2026-33186

GitHubjohanneslks/cve-2026-33186

gRPC-Go RBAC Authorization Policy Bypass via Missing `:path` Slash (Auth Bypass)

api-securityauthentication-authorizationeducation+3
12 months ago
cve-2026-69243-poc-aiohttp-smuggling preview

cve-2026-69243-poc-aiohttp-smuggling

GitHubjvbotelho/cve-2026-69243-poc-aiohttp-smuggling

Reproduces aiohttp CWE-444 request smuggling via rejected WebSocket upgrades, with Python/Rust payloads and Docker lab demonstrating proxy…

exploitationfuzzingpayload-generation+3
11 month ago
CVE-2019-5096-GoAhead-Web-Server-Dos-Exploit preview

CVE-2019-5096-GoAhead-Web-Server-Dos-Exploit

GitHubianxtianxt/cve-2019-5096-goahead-web-server-dos-exploit

Python exploit for CVE-2019-5096, a use-after-free vulnerability in GoAhead web server's upload handler, causing denial of service via double-free.

binary-exploitationexploitationfuzzing+2
16 years ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubx48ps/cve-2026-8181

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

api-securityauthenticationexploitation+3
4 months ago
CVE-2026-27739-POC preview

CVE-2026-27739-POC

GitHubmr-redoo7/cve-2026-27739-poc

Python PoC exploiting CVE-2026-27739 in Angular SSR: header injection via prototype pollution and SSRF chaining to AWS IMDS/GCP metadata for…

api-securityexploitationinformation-gathering+4
5 months ago
POC_CVE-2024-36420 preview

POC_CVE-2024-36420

GitHubfineman999/poc_cve-2024-36420

Local reproduction lab and Nuclei template for CVE-2024-36420, an arbitrary file read vulnerability in Flowise via unsanitized fileName parameter.…

educationexploitationfuzzing+3
4 months ago
nginx-rce-cve-2026-42945 preview

nginx-rce-cve-2026-42945

GitHubwebdev75950-ux/nginx-rce-cve-2026-42945

Proof-of-concept exploit for CVE-2026-42945, a critical heap buffer overflow in NGINX rewrite module enabling remote code execution via crafted URI…

binary-exploitationexploitationfuzzing+3
4 months ago
CVE-Wazuh preview

CVE-Wazuh

GitHubhorkimhab/cve-wazuh

Enrolled agent can smuggle arbitrary OpenSearch _bulk operations via DataValue.index. GHSA-ff9g-85jq-r3g3. Draft

api-securityeducationexploitation+3
3 months ago
Previous1…101112…15Next