Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
CVE-2025-4476-Exploit preview

CVE-2025-4476-Exploit

GitHubsoltanali0/cve-2025-4476-exploit

Python test client that sends HTTP GET requests with oversized Authorization headers to trigger header-parsing bugs like CVE-2025-4476. For…

educationexploitationvulnerability-analysis+1
11 months ago
CVE-2021-40346 preview

CVE-2021-40346

GitHubalexoarga/cve-2021-40346

Proof-of-concept for CVE-2021-40346, demonstrating HTTP request smuggling in HAProxy via integer overflow, with Docker-based environment to bypass…

exploitationpenetration-testingvulnerability-analysis+2
4 years ago
CVE-2026-51416 preview

CVE-2026-51416

GitHubrenio-wow/cve-2026-51416

Analyzes a specific CVE in WeChat OAuth handler, identifying unbounded HTTP response reads leading to denial of service, with remediation guidance.

code-analysisstatic-analysisvulnerability-analysis+1
5 months ago
CVE-2026-76564 preview

CVE-2026-76564

GitHubtoanln-cov/cve-2026-76564

Stored XSS via User-Agent in Admin Order View in PhocaCart

code-analysisexploitationpapers-research+3
1 month ago
CVE-2026-1010-WebSocket-Connection-Smuggling-via-Malformed-Upgrade-Header preview

CVE-2026-1010-WebSocket-Connection-Smuggling-via-Malformed-Upgrade-Header

GitHubgeorge0papasotiriou/cve-2026-1010-websocket-connection-smuggling-via-malformed-upgrade-header

Proof-of-concept exploit for CVE-2026-1010, demonstrating WebSocket connection smuggling and request splitting through a malformed Upgrade header…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
crlfi-scanner preview

crlfi-scanner

GitHubcappricio-securities/crlfi-scanner

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

fuzzingpenetration-testingweb-application-exploitation+2
46 months ago
CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille- preview

CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille-

GitHubtheopaid/cve-2026-66746-http-response-splitting-via-unvalidated-response-header-values-rouille-

Security Advisory: HTTP Response Splitting via Unvalidated Response Header Values (rouille)

code-analysispenetration-testingvulnerability-analysis+2
1 month ago
CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http- preview

CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-

GitHubtheopaid/cve-2026-66752-http-request-smuggling-via-unparsed-transfer-encoding-values-tiny_http-

Security Advisory: HTTP Request Smuggling via Unparsed Transfer-Encoding Values (tiny_http)

papers-researchvulnerability-analysisweb-application-exploitation+1
1 month ago
CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http- preview

CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-

GitHubtheopaid/cve-2026-66753-http-header-injection-via-unvalidated-cr-and-lf-in-header-values-tiny_http-

Security Advisory: HTTP Header Injection via Unvalidated CR and LF in Header Values (tiny_http)

code-analysiscurated-resourceseducation+2
1 month ago
CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille- preview

CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-

GitHubtheopaid/cve-2026-67181-http-request-smuggling-via-transfer-encoding-desynchronization-rouille-

Security Advisory: HTTP Request Smuggling via Transfer-Encoding Desynchronization (rouille)

exploitationvulnerability-analysisweb-application-exploitation+1
11 month ago
CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille- preview

CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille-

GitHubtheopaid/cve-2026-67182-http-request-smuggling-enables-front-end-access-control-bypass-rouille-

Security Advisory: HTTP Request Smuggling Enables Front-End Access Control Bypass (rouille)

educationpapers-researchvulnerability-analysis+2
1 month ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubliaoziqi-gzfls/cve-2026-42945

CVE-2026-42945 Nginx Rift

binary-exploitationexploitationfuzzing+6
13 months ago
CVE-2025-60876 preview
Archived

CVE-2025-60876

GitHubsirredbeard/cve-2025-60876

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

exploitationfuzzingpenetration-testing+3
3 months ago
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubw2hcorp/cve-2025-29927-poc

Here is a simple but effective exploit for CVE-2025-29927.

exploitationpenetration-testingred-teaming+3
11 year ago
CVE-2025-29927-NextJs-Middleware-Simulation preview

CVE-2025-29927-NextJs-Middleware-Simulation

GitHubknotsecurity/cve-2025-29927-nextjs-middleware-simulation

Simulates CVE-2025-29927, a critical Next.js vulnerability allowing attackers to bypass middleware authorization by exploiting the internal…

educationmisconfigurationpenetration-testing+3
1 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubrubbxalc/cve-2025-29927

Functional exploit for CVE-2025-29927, a critical Next.js middleware authorization bypass. Sends crafted HTTP requests with the…

authentication-authorizationexploitationpenetration-testing+3
11 year ago
CVE-2023-3519 preview

CVE-2023-3519

GitHubkr0n-security/cve-2023-3519

NetScaler (Citrix ADC) CVE-2023-3519 Scanner

exploitationinformation-gatheringreconnaissance+2
13 years ago
CVE-2022-2466---Request-Context-not-terminated-with-GraphQL preview

CVE-2022-2466---Request-Context-not-terminated-with-GraphQL

GitHubyuxblank/cve-2022-2466---request-context-not-terminated-with-graphql

Proof-of-concept for CVE-2022-2466 demonstrating unauthenticated GraphQL request context termination in Quarkus/SmallRye, bypassing authorization…

api-securityauthenticationpenetration-testing+2
14 years ago
Previous12Next