Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
250 results
CVE-2026-89026 preview

CVE-2026-89026

GitHubaranfarzami/cve-2026-89026

PoC exploit and scanner for CVE-2026-89026, validating the Issabel PBXAPI authentication bypass via forged HS256 JWTs across single or listed targets.

authenticationexploitationpenetration-testing+5
1
5 days ago
FullscreenBrowserPhishing preview

FullscreenBrowserPhishing

GitHubgmh5225/fullscreenbrowserphishing

PoC of the phishing through setting browser in the fullscreen mode

educationphishingphishing-tools+3
3 years ago
CVE-2024-31218-WEBHOOD-LAB preview

CVE-2024-31218-WEBHOOD-LAB

GitHubchandrimanath04-hue/cve-2024-31218-webhood-lab

Docker-based lab reproducing CVE-2024-31218, an unauthenticated PocketBase admin creation flaw in Webhood, with PoC, detection, and remediation…

authenticationeducationexploitation+4
6 days ago
CVE-2023-27163-lab preview

CVE-2023-27163-lab

GitHubamulyakaushik/cve-2023-27163-lab

Docker-based lab reproducing CVE-2023-27163 SSRF in Request-Baskets, with exploitation verification, detection script, and network-isolation…

container-securitydefensive-toolseducation+6
5 days ago
CVE-2026-76460 preview

CVE-2026-76460

GitHubs3v3n-jg/cve-2026-76460

Educational Flask lab simulating CVE-2026-76460 authentication bypass, with vulnerable, secure, and strict modes plus a PoC exploit script and…

api-securityauthenticationdefensive-tools+5
19 days ago
nuclei-CVE-2025-24813 preview

nuclei-CVE-2025-24813

GitHubsebastianmautner/nuclei-cve-2025-24813

University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting…

exploitationpenetration-testingreconnaissance+4
13 days ago
GitLabSniper preview

GitLabSniper

GitHubynsmroztas/gitlabsniper

Single-file Python scanner and exploit for CVE-2026-85706, an unauthenticated arbitrary file read in self-managed GitLab CE/EE, with project…

data-exfiltrationexploitationinformation-gathering+6
714 days ago
Internet-Security-Project preview

Internet-Security-Project

GitHubmattia-maria-scivoletto/internet-security-project

Academic report and LaTeX sources analyzing Maltego vulnerability CVE-2020-24656, an XXE injection enabling data exfiltration, written for an…

curated-resourceseducationpapers-research+2
5 years ago
CVE-2026-36392 preview

CVE-2026-36392

GitHubmoksh-nfsu/cve-2026-36392

Proof-of-concept for stored XSS in RISE CRM item title field (CVE-2026-36392), demonstrating session hijacking and account takeover with remediation…

exploitationpenetration-testingvulnerability-analysis+2
118 days ago
CVE-2026-19516 preview

CVE-2026-19516

GitHubhorkimhab/cve-2026-19516

Proof-of-concept for CVE-2026-19516, demonstrating session spoofing and SSRF in Grafana MCP. Intended for authorized security research and education…

curated-resourceseducationexploitation+2
22 days ago
CVE-2026-85046 preview

CVE-2026-85046

GitHubhorkimhab/cve-2026-85046

Proof-of-concept for Chrome V8 zero-day CVE-2026-85046, providing educational exploit code and setup instructions for authorized security research in…

curated-resourceseducationexploitation+2
122 days ago
CVE-2026-PSA-2026-00043-1 preview

CVE-2026-PSA-2026-00043-1

GitHubhorkimhab/cve-2026-psa-2026-00043-1

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

authenticationeducationexploitation+3
24 days ago
CVE-2026-27541-Analysis-Lab preview

CVE-2026-27541-Analysis-Lab

GitHubrootdirective-sec/cve-2026-27541-analysis-lab

Docker lab for reproducing CVE-2026-27541, an authenticated privilege escalation in WooCommerce Wholesale Prices. Compares vulnerable and patched…

educationexploitationlabs-practice+4
6 months ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubeqstlab/cve-2026-19478

Proof-of-concept exploit for CVE-2026-19478, an unauthenticated GraphQL injection in GitLab CE/EE allowing arbitrary method invocation and project…

exploitationpenetration-testingred-teaming+3
41 month ago
browser-security-project preview

browser-security-project

GitHubowasp/browser-security-project

Community-driven project providing guidance and resources to improve browser security, including best practices and educational materials for…

curated-resourceseducationweb-security
516 days ago
CVE-2026-26211 preview

CVE-2026-26211

GitHublindhunt/cve-2026-26211

Public disclosure and proof-of-concept for CVE-2026-26211, a stored XSS vulnerability in Ekushey Project Manager CRM v5.0, including technical…

educationexploitationpapers-research+2
115 days ago
CVE-2025-61456 preview

CVE-2025-61456

GitHubtansique-17/cve-2025-61456

Public disclosure and proof-of-concept for a reflected XSS vulnerability (CVE-2025-61456) in an e-commerce project, including technical details, CVSS…

educationexploitationpapers-research+3
11 months ago
CVE-2025-61455 preview

CVE-2025-61455

GitHubtansique-17/cve-2025-61455

Public disclosure and proof-of-concept for CVE-2025-61455, a critical SQL injection in E-commerce Project v1.0, including technical details, PoC, and…

curated-resourceseducationexploitation+2
11 months ago
Previous12…14Next