Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1163 results
CVE-2021-20323 preview

CVE-2021-20323

GitHubndmalc/cve-2021-20323

Proof-of-concept and analysis for CVE-2021-20323, a reflected XSS vulnerability in Keycloak's clients-registrations endpoint, with exploitation…

educationpapers-researchpenetration-testing+3
13
3 years ago
CVE-2026-34835-Black-box-Analysis preview

CVE-2026-34835-Black-box-Analysis

GitHubcyber-note/cve-2026-34835-black-box-analysis

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

dns-analysiseducationpenetration-testing+3
62 months ago
cve-2025-55182-react2shell-analysis preview

cve-2025-55182-react2shell-analysis

GitHubaisha-jimoh/cve-2025-55182-react2shell-analysis

Technical analysis of CVE-2025-55182 (React2Shell), covering vulnerability mechanics, root cause, controlled PoC testing, impact, and mitigation…

educationexploitationvulnerability-analysis+2
21 days ago
honeypotscan preview

honeypotscan

GitHubteycir/honeypotscan

Free honeypot token scanner for Ethereum, Polygon & Arbitrum. Detect scam tokens before you buy. Instant analysis of smart contracts using 13…

api-securityeducationprivacy+3
105 months ago
grav-cve-2024-28116 preview

grav-cve-2024-28116

GitHubbebarossi/grav-cve-2024-28116

Analysis and Docker reproduction of CVE-2024-28116 - SSTI with sandbox bypass in Grav CMS

educationexploitationlabs-practice+3
15 days ago
CVE-2026-19264 preview

CVE-2026-19264

GitHubdarklycn1976/cve-2026-19264

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

code-analysiseducationexploitation+3
24 days ago
CVE-2026-26211 preview

CVE-2026-26211

GitHublindhunt/cve-2026-26211

Public disclosure and proof-of-concept for CVE-2026-26211, a stored XSS vulnerability in Ekushey Project Manager CRM v5.0, including technical…

educationexploitationpapers-research+2
8 days ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub0xblackash/cve-2026-32475

Technical analysis and detection guidance for critical unrestricted file upload in Elementor Pro (CVE-2026-32475) leading to remote code execution.

educationpenetration-testingvulnerability-analysis+2
12 days ago
CVE-2026-9833 preview

CVE-2026-9833

GitHubaj2108/cve-2026-9833

Technical analysis of a reflected XSS vulnerability in the Tag Groups WordPress plugin before 2.2.0, covering root cause, attack flow, impact,…

educationvulnerability-analysisweb-application-exploitation+1
1 month ago
boa-cve-2009-4496-analysis preview

boa-cve-2009-4496-analysis

GitHubenriquenegri-cyberlaw/boa-cve-2009-4496-analysis

Defensive analysis of CVE-2009-4496 in Boa 0.94.14rc21, including source-code review, patch analysis, severity assessment, and ethical scope.

code-analysiseducationosint+3
19 days ago
Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation preview

Incident-Analysis-Response-Check-Point-Security-Gateway-CVE-2024-24919-LFI-Exploitation

GitHubzedocun/incident-analysis-response-check-point-security-gateway-cve-2024-24919-lfi-exploitation

Incident Response (IR) case study documenting the investigation of an exploitation attempt targeting CVE-2024-24919 (Arbitrary File Read) on a Check…

digital-forensicseducationincident-response+7
11 month ago
CVE-2025-57833 preview

CVE-2025-57833

GitHubsw0rd1ight/cve-2025-57833

Analysis and reproduction of CVE-2025-57833

database-securityeducationexploitation+3
69 months ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubdr-d25/cve-2026-49049

Technical analysis and Proof of Concept (PoC) for CVE-2026-49049, an unauthenticated arbitrary file write vulnerability in JoomShaper Helix3 for…

educationexploitationpenetration-testing+3
1 month ago
cve-2024-23897-jenkins-poc preview

cve-2024-23897-jenkins-poc

GitHubrivaedoardo62-boop/cve-2024-23897-jenkins-poc

Self-contained Docker reproduction and analysis of CVE-2024-23897, the Jenkins CLI arbitrary file read via the args4j @-syntax argument expansion.

educationexploitationpapers-research+3
2 months ago
CVE-2026-48908-Joomla-SP-Page-Builder-RCE preview

CVE-2026-48908-Joomla-SP-Page-Builder-RCE

GitHubimxur/cve-2026-48908-joomla-sp-page-builder-rce

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

educationpapers-researchvulnerability-analysis+1
21 month ago
CVE-2026-37196 preview

CVE-2026-37196

GitHubpavanvootla-sec/cve-2026-37196

Stored XSS vulnerability disclosure for nirix traq v3.9.0 with PoC, root cause analysis, and mitigation guidance for security researchers and…

educationpapers-researchvulnerability-analysis+2
2 months ago
cve-writeups preview

cve-writeups

GitHubvadlareddysai/cve-writeups

Multiple CVEs (CVE-2026-38934, CVE-2026-38935, CVE-2026-38936) discovered in diskover-community including CSRF and XSS vulnerabilities with…

educationexploitationpenetration-testing+2
1 month ago
CVE-2024-4367-Analysis preview

CVE-2024-4367-Analysis

GitHubmasamuneee/cve-2024-4367-analysis

Analysis and PoC for CVE-2024-4367: arbitrary JavaScript execution (XSS) in PDF.js

educationexploitationpapers-research+3
41 year ago
Previous123…65Next