Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
440 results
CVE-2026-40175 preview

CVE-2026-40175

GitHub0xblackash/cve-2026-40175

CVE-2026-40175

cloud-securityeducationexploitation+3
5 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubliaoziqi-gzfls/cve-2026-42945

CVE-2026-42945 Nginx Rift

binary-exploitationexploitationfuzzing+6
13 months ago
CVE-2019-20372 preview

CVE-2019-20372

GitHubmoften/cve-2019-20372

Nginx CVE-2019-20372 PoC, Unauthenticated File Upload Exploit

exploitationpayload-generationpenetration-testing+3
11 year ago
CVE-2025-60752 preview

CVE-2025-60752

GitHubzer0matt/cve-2025-60752

PoC of CVE-2025-60752

binary-exploitationexploitationpenetration-testing+2
13 months ago
nginx-cve-2026-42945-check preview

nginx-cve-2026-42945-check

GitHubbyezero/nginx-cve-2026-42945-check

Local read-only scanner for CVE-2026-42945 (NGINX Rift) that checks NGINX, OpenResty, and Tengine instances for vulnerable rewrite configurations…

configuration-auditingscripting-automationstatic-analysis+3
4 months ago
CVE-2026-Mastodon-Streaming-CRLF-Injection preview

CVE-2026-Mastodon-Streaming-CRLF-Injection

GitHub1402307692/cve-2026-mastodon-streaming-crlf-injection

Mastodon Streaming Server Security Vulnerability PoC - CVE-2026-Mastodon-Streaming-CRLF-Injection

educationexploitationpenetration-testing+3
4 months ago
CVE-2026-32913 preview

CVE-2026-32913

GitHubrickidevs/cve-2026-32913

I Found a Zero-Day Vulnerability in OpenClaw — Here’s How It Went

curated-resourceseducationvulnerability-analysis+1
5 months ago
CVE-2026-42533 preview

CVE-2026-42533

GitHubjelasin/cve-2026-42533

Proof-of-concept reproduction of an nginx heap overflow and info leak (CVE-2026-42533) with two attack surfaces, debug analysis, and a full RCE chain.

binary-exploitationcode-analysisdebuggers+4
1 month ago
auth-header-trust-rules preview

auth-header-trust-rules

GitHubbk-security/auth-header-trust-rules

Semgrep rules that flag header-trust auth bypass patterns (CVE-2025-29927 class). Companion to bk-security.github.io.

authentication-authorizationcode-analysiseducation+3
4 months ago
apache-web-log-analysis-lab preview

apache-web-log-analysis-lab

GitHubpedrofbrm/apache-web-log-analysis-lab

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

educationlabs-practicelog-analysis+1
4 months ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubhnytgl/cve-2026-34197

这是一个面向防守和内网排查的 Apache ActiveMQ Classic 暴露面检测工具,用于辅助评估 CVE-2026-34197 相关风险。

configuration-auditingdefensive-toolsinformation-gathering+3
13 months ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubhnytgl/cve-2026-42945

这是一个面向防守和内网排查的 CVE-2026-42945 静态检测工具,用于检查 NGINX ngx_http_rewrite_module 相关配置是否存在高风险 rewrite 组合。

configuration-auditingdefensive-toolsdevsecops+3
13 months ago
wazuh-nginx-cve-2026-42945-sca-lab preview

wazuh-nginx-cve-2026-42945-sca-lab

GitHubsoksofos/wazuh-nginx-cve-2026-42945-sca-lab

Centralized Wazuh SCA Assessment for CVE-2026-42945 on NGINX Servers

configuration-auditingdefensive-toolseducation+3
4 months ago
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubw2hcorp/cve-2025-29927-poc

Here is a simple but effective exploit for CVE-2025-29927.

exploitationpenetration-testingred-teaming+3
11 year ago
CVE-2022-2466---Request-Context-not-terminated-with-GraphQL preview

CVE-2022-2466---Request-Context-not-terminated-with-GraphQL

GitHubyuxblank/cve-2022-2466---request-context-not-terminated-with-graphql

Proof-of-concept for CVE-2022-2466 demonstrating unauthenticated GraphQL request context termination in Quarkus/SmallRye, bypassing authorization…

api-securityauthenticationpenetration-testing+2
14 years ago
CVE-2022-41741-742-Nginx-Vulnerability-Scanner preview

CVE-2022-41741-742-Nginx-Vulnerability-Scanner

GitHubmoften/cve-2022-41741-742-nginx-vulnerability-scanner

CVE-2022-41741/742 Nginx Vulnerability Scanner

information-gatheringpenetration-testingreconnaissance+3
18 months ago
react2shell_analyzer preview

react2shell_analyzer

GitHubbenrich127n/react2shell_analyzer

a dart package to analyze CVE-2025-55182 react2shell

dynamic-analysis-sandboxingpenetration-testingvulnerability-analysis+3
19 months ago
ai-vuln-rediscovery-nginx-cve-2026-42945 preview

ai-vuln-rediscovery-nginx-cve-2026-42945

GitHubchamsbouzaiene/ai-vuln-rediscovery-nginx-cve-2026-42945

Reproducible AI-assisted vulnerability rediscovery of CVE-2026-42945 in nginx, including technical analysis, PoC trigger, and patch validation for…

ai-securitybinary-exploitationeducation+3
4 months ago
Previous1…22232425Next