Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
257 results
CVE-2026-42945-nginx-rift-poc preview

CVE-2026-42945-nginx-rift-poc

GitHubf2u0a0d3/cve-2026-42945-nginx-rift-poc

PoC for CVE-2026-42945 (nginx Rift) — heap buffer overflow in ngx_http_rewrite_module. Includes detect/probe/exploit modes, dual-fixture Docker lab,…

binary-exploitationdynamic-analysis-sandboxingeducation+6
1
4 months ago
CVE-2026-32201-exploit preview

CVE-2026-32201-exploit

GitHubb1tbit/cve-2026-32201-exploit

Python exploit for CVE-2026-32201, a reflected XSS in Microsoft SharePoint Server, enabling unauthenticated spoofing and data modification via…

exploitationpenetration-testingphishing-tools+3
15 months ago
nginx-cve-2026-42945-poc preview

nginx-cve-2026-42945-poc

GitHubforxiucn/nginx-cve-2026-42945-poc

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via…

binary-exploitationcontainer-securitydynamic-analysis-sandboxing+5
14 months ago
Shocker-TJNULL-OSCP- preview

Shocker-TJNULL-OSCP-

GitHubr3fr4kt/shocker-tjnull-oscp-

Structured HTB walkthrough demonstrating Shellshock (CVE-2014-6271) exploitation via CGI directory fuzzing and privilege escalation through…

educationexploitationlabs-practice+6
3 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubredcrazyghost/cve-2026-42945

Go-based exploit tool for CVE-2026-42945 (nginx HTTP/2) with detection, crash probing, command execution, and reverse shell capabilities for…

binary-exploitationexploitationfuzzing+3
14 months ago
Popcorn-TJNULL-OSCP- preview

Popcorn-TJNULL-OSCP-

GitHubr3fr4kt/popcorn-tjnull-oscp-

Popcorn HTB write-up covering advanced directory fuzzing, file upload bypass via magic numbers/extension spoofing using Burp Suite, and privilege…

ctfeducationexploitation+7
3 months ago
CVE-2025-0851 preview

CVE-2025-0851

GitHubskrkcb2/cve-2025-0851

Proof-of-concept exploit for CVE-2025-0851, a file traversal vulnerability in Deep Java Library's tar/zip model extraction utility, enabling…

binary-analysisexploitationfuzzing+3
11 year ago
CTF-Web-Exploitation preview

CTF-Web-Exploitation

GitHubarnavps/ctf-web-exploitation

A comprehensive collection of 12 containerized web exploitation challenges covering CVE-2023-25690, WebAuthn bypasses, HTTP/3 smuggling, and advanced…

container-securityctfeducation+8
15 months ago
text4shell-scan preview

text4shell-scan

GitHubkiralab/text4shell-scan

A fully automated, accurate, and extensive scanner for finding text4shell RCE CVE-2022-42889

exploitationfuzzingpenetration-testing+3
3 years ago
CVE-2018-18912 preview

CVE-2018-18912

GitHubthemalwareguardian/cve-2018-18912

SEH-based buffer overflow in Easy File Sharing Web Server 7.2 demonstrating how an authenticated HTTP POST parameter can corrupt the exception…

binary-exploitationdebuggerseducation+6
16 months ago
CVE-2017-14980 preview

CVE-2017-14980

GitHubthemalwareguardian/cve-2017-14980

Stack-based buffer overflow in Sync Breeze Enterprise 10.0.28 reachable through the /login handler, demonstrating how unchecked input length can…

binary-exploitationdebuggerseducation+7
16 months ago
CVE-2025-63667 preview

CVE-2025-63667

GitHubremenis/cve-2025-63667

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

api-securityauthenticationembedded-systems-security+4
110 months ago
CVE-2016-3627 preview

CVE-2016-3627

GitHuboneton429/cve-2016-3627

PoC of CVE-2016-3627

exploitationfuzzingstatic-analysis+2
111 months ago
Log4j_scan_Advance preview

Log4j_scan_Advance

GitHubrk-000/log4j_scan_advance

A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228

exploitationfuzzingvulnerability-scanners+3
14 years ago
CVE-2024-5124 preview

CVE-2024-5124

GitHubgogo2464/cve-2024-5124

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

cryptographyexploitationfuzzing+3
11 year ago
ClaimJumper preview

ClaimJumper

GitHubfevra-dev/claimjumper

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

authenticationcryptographyexploitation+6
18 months ago
CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation preview

CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

GitHubackemed/cve-2026-1529-poc-keycloak-unauthorized-registration-via-improper-invitation-token-validation

Exploit tool for CVE-2026-1529, demonstrating unauthorized organization registration in Keycloak via JWT token manipulation. Includes token…

api-securityauthenticationexploitation+3
7 months ago
CVE-2023-52235-PoC-SPACEX-STARLINK-DNS-Rebinding preview

CVE-2023-52235-PoC-SPACEX-STARLINK-DNS-Rebinding

GitHubhackintoanetwork/cve-2023-52235-poc-spacex-starlink-dns-rebinding

Proof-of-concept exploit for CVE-2023-52235 demonstrating DNS rebinding attack against SpaceX Starlink user terminals to bypass network security…

dns-analysisdns-fuzzingexploitation+3
6 months ago
Previous1…111213…15Next