Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
148 results
CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter preview

CVE-2026-87491-and-CVE-2026-85046-the-bagel-fell-off-the-counter

GitHubsneakynachos/cve-2026-87491-and-cve-2026-85046-the-bagel-fell-off-the-counter

Chrome 152 V8 exploit chaining CVE-2026-85046 and CVE-2026-87491 to corrupt the heap, forge Wasm metadata, and execute native code from the renderer.

binary-exploitationexploitationmemory-forensics+3
3
18 days ago
Cassowary-CVE-2024-23222-x86_64 preview

Cassowary-CVE-2024-23222-x86_64

GitHubfuzzysecurity/cassowary-cve-2024-23222-x86_64

Adaptation of Cassowary CVE-2024-23222 for Linux x86_64

binary-exploitationexploitationmemory-forensics+4
116 months ago
CVE-2022-22947 preview

CVE-2022-22947

GitHubsijido/cve-2022-22947

Python-based memory shell injection tool for CVE-2022-22947, supporting Spring, Netty, and Godzilla memory shells with simple CLI usage.

exploitationmemory-forensicsvulnerability-analysis+1
94 years ago
news-8.6.0-cve-2026-8726-backport preview

news-8.6.0-cve-2026-8726-backport

GitHubshentao83/news-8.6.0-cve-2026-8726-backport

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

database-securitydefensive-toolsstatic-code-analysis+3
11 days ago
CVE-2022-22620 preview

CVE-2022-22620

GitHubspringsec/cve-2022-22620

Webkit (Safari) - Exploit

binary-exploitationexploitationmemory-forensics+2
64 years ago
CVE-2026-13158 preview

CVE-2026-13158

GitHubminhhk68/cve-2026-13158

Proof-of-concept exploit and technical advisory for an Admin+ arbitrary file upload to remote code execution vulnerability in Everest Toolkit…

exploitationpayload-developmentpenetration-testing+4
2 months ago
CVE-2021-30573 preview

CVE-2021-30573

GitHubkh4sh3i/cve-2021-30573

Proof-of-concept exploit for CVE-2021-30573, a use-after-free vulnerability in Google Chrome's GPU component allowing remote heap corruption via…

exploitationmemory-forensicsvulnerability-analysis+1
24 years ago
CVE-2026-64638-PoC-Exploit preview

CVE-2026-64638-PoC-Exploit

GitHubtc4dy/cve-2026-64638-poc-exploit

🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment &…

command-and-controlexploitationmemory-forensics+6
11 month ago
CVE-2025-12135 preview

CVE-2025-12135

GitHubd0n601/cve-2025-12135

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

authenticationcode-analysismisconfiguration+3
11 months ago
CVE-2021-3129 preview

CVE-2021-3129

GitHubhupe1980/cve-2021-3129

Laravel debug mode - Remote Code Execution (RCE)

code-analysisdynamic-code-analysisexploitation+3
4 years ago
CVE-2021-21017 preview

CVE-2021-21017

GitHubtzwlhack/cve-2021-21017

Proof-of-concept exploit for CVE-2021-21017, an Adobe Reader type confusion leading to out-of-bounds read and heap overflow, with technical analysis…

binary-analysisexploitationmemory-forensics+2
4 years ago
cve-2018-8389 preview

cve-2018-8389

GitHubsandi-go/cve-2018-8389

Technical analysis and proof-of-concept for CVE-2018-8389, a use-after-free vulnerability in Internet Explorer's jscript.dll allowing remote code…

binary-exploitationexploitationmemory-forensics+2
6 years ago
XXStrike preview

XXStrike

GitHubanonmoty/xxstrike

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

dynamic-code-analysisfuzzingpenetration-testing+5
315 days ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubg33xter/cve-2020-9496

Apache OFBiz unsafe deserialization of XMLRPC arguments

command-and-controlexploitationpayload-development+4
75 years ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubs4dbrd/cve-2020-9496

Exploit script for Apache OFBiz CVE-2020-9496 unsafe deserialization vulnerability, enabling remote code execution via crafted XML-RPC requests with…

exploitationpayload-developmentremote-access-tool+2
45 years ago
CVE-2020-9496 preview

CVE-2020-9496

GitHubcyber-niz/cve-2020-9496

Manual exploit for CVE-2020-9496, an unauthenticated Java deserialization RCE in Apache OFBiz XML-RPC, with step-by-step instructions for payload…

exploitationpayload-generationpenetration-testing+2
5 years ago
CVE-2019-0708-poc preview

CVE-2019-0708-poc

GitHubhook-s3c/cve-2019-0708-poc

proof of concept exploit for Microsoft Windows 7 and Server 2008 RDP vulnerability

exploitationpenetration-testingremote-access-tool+2
477 years ago
Wing-FTP-Server-7.4.4-RCE-Authenticated preview

Wing-FTP-Server-7.4.4-RCE-Authenticated

GitHubnouvexr/wing-ftp-server-7.4.4-rce-authenticated

Wing FTP Server provides an administrative Lua scripting console accessible via its web interface. Authenticated administrators are able to execute…

exploitationpayload-developmentpenetration-testing+3
21 year ago
Previous1…567…9Next