Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
486 results
CVE-2024-53677-Exploitation preview

CVE-2024-53677-Exploitation

GitHubhopsypopsy8/cve-2024-53677-exploitation

Step-by-step walkthrough for exploiting Apache Struts CVE-2024-53677 RCE via file upload manipulation, including OGNL injection, payload embedding,…

code-analysiseducationexploitation+6
1 year ago
CVE-2024-57484 preview

CVE-2024-57484

GitHubyogeswaran6383/cve-2024-57484

Proof-of-concept for CVE-2024-57484: directory listing vulnerability in FoxyProxy extension exposing internal file structure and metadata, enabling…

information-gatheringmisconfigurationvulnerability-analysis+1
1 year ago
Preproduce-CVE-2021-41773 preview

Preproduce-CVE-2021-41773

GitHubluongchivi/preproduce-cve-2021-41773

PoC and exploit for CVE-2021-41773 path traversal in Apache HTTP Server 2.4.49, with Docker setup and curl-based exploitation commands for file…

educationexploitationpenetration-testing+3
1 year ago
cve-2024-38819 preview

cve-2024-38819

GitHubskrkcb2/cve-2024-38819

In-depth analysis of CVE-2024-38819, a Spring WebFlux file traversal vulnerability, with code-level breakdown, PoC, and mitigation strategies…

educationexploitationpapers-research+3
1 year ago
CVE-2023-47668 preview

CVE-2023-47668

GitHubrandomrobbiebf/cve-2023-47668

Restrict Content <= 3.2.7 - Information Exposure via legacy log file

information-gatheringlog-analysismisconfiguration+2
2 years ago
CVE-2024-24919-Incident-Report.md preview

CVE-2024-24919-Incident-Report.md

GitHubcyprianatsyor/cve-2024-24919-incident-report.md

Detailed incident report analyzing CVE-2024-24919 arbitrary file read exploit on Check Point Security Gateway, including technical analysis, response…

digital-forensicseducationincident-response+3
1 year ago
CVE-2026-35492 preview

CVE-2026-35492

GitHubredyank/cve-2026-35492

Demonstrates CVE-2026-35492, a path traversal vulnerability in kedro-datasets PartitionedDataset allowing arbitrary file write, with impact analysis…

curated-resourceseducationexploitation+2
4 months ago
CVE-2026-7482-PoC preview

CVE-2026-7482-PoC

GitHub0x0oz/cve-2026-7482-poc

Proof-of-concept exploit for CVE-2026-7482, an unauthenticated heap out-of-bounds read in Ollama's GGUF loader, demonstrating memory exfiltration via…

binary-analysiseducationexploitation+2
63 months ago
Ashwesker-CVE-2026-21440 preview

Ashwesker-CVE-2026-21440

GitHubredpack-kr/ashwesker-cve-2026-21440

Proof-of-concept exploit for CVE-2026-21440, a critical path traversal in AdonisJS multipart uploads enabling arbitrary file write and remote code…

educationexploitationpenetration-testing+3
7 months ago
CVE-2026-19912-CVE-2026-19913-CVE-2026-19914 preview

CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

GitHubhorkimhab/cve-2026-19912-cve-2026-19913-cve-2026-19914

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

educationexploitationpenetration-testing+3
3 days ago
CVE-2026-66907 preview

CVE-2026-66907

GitHuboscerd/cve-2026-66907

Proof-of-concept reproducers for Apache Camel camel-google-storage path traversal (CVE-2026-66907), demonstrating arbitrary file write via…

educationexploitationpapers-research+2
5 days ago
hakrawler preview

hakrawler

GitHubhakluke/hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

crawlerinformation-gatheringpenetration-testing+2
5.1k25 days ago
HaE preview

HaE

GitHuboverspace-labs/hae

Modular Burp Suite extension for fine-grained highlighting and extraction of sensitive data from HTTP and WebSocket traffic, enabling efficient…

information-gatheringutilities-frameworksweb-security
4.4k8 days ago
Bug_Bounty_writeups preview

Bug_Bounty_writeups

GitHubalexbieber/bug_bounty_writeups

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

curated-resourceseducationvulnerability-analysis+1
8524 years ago
0l4bs preview

0l4bs

GitHubtegal1337/0l4bs

Cross-site scripting labs for web application security enthusiasts

ctfeducationlabs-practice+1
3485 years ago
DATA preview

DATA

GitHubhadojae/data

Credential Phish Analysis and Automation

information-gatheringosintphishing+2
998 years ago
mkpath preview

mkpath

GitHubtrickest/mkpath

Make URL path combinations using a wordlist

fuzzinginformation-gatheringpenetration-testing+2
1762 years ago
tetsuo-pulse preview

tetsuo-pulse

GitHub7etsuo/tetsuo-pulse

Tetsuo Socket Library

api-securitycryptographydns-analysis+6
706 months ago
Previous1…252627Next