Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
172 results
CVE-2014-0160. preview

CVE-2014-0160.

GitHubtungduongnt/cve-2014-0160.

Docker-based lab environment for exploiting CVE-2014-0160 (Heartbleed) to leak sensitive memory from nginx web servers, with Snort IDS detection…

educationexploitationintrusion-detection+3
2 months ago
CVE-2026-73633 preview

CVE-2026-73633

GitHubcuteecat/cve-2026-73633

Proof-of-concept exploit for Apache Struts S2-072 (CVE-2026-73633), demonstrating CPU and memory exhaustion by sending crafted JSON requests to the…

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
CVE-2026-3055---Citrix-NetScaler-Memory-Overread-PoC preview

CVE-2026-3055---Citrix-NetScaler-Memory-Overread-PoC

GitHubfevar54/cve-2026-3055---citrix-netscaler-memory-overread-poc

PoC de CVE-2026-3055: memory overread en Citrix NetScaler ADC/Gateway para filtrar session IDs.

exploitationpenetration-testingred-teaming+2
16 months ago
CVE-2026-8452-check preview

CVE-2026-8452-check

GitHubbishopfox/cve-2026-8452-check

Behavioral patch-state detector for Citrix NetScaler CVE-2026-8452. Sends crafted SAML requests to determine whether the PrefixList size check is…

network-securityvulnerability-analysisvulnerability-scanners+1
11 month ago
CVE-2026-49975-HTTP-2-Bomb preview

CVE-2026-49975-HTTP-2-Bomb

GitHubrenzi25031469/cve-2026-49975-http-2-bomb

Disclosed on June 3, 2026, the "HTTP/2 Bomb" is an unauthenticated remote DoS that combines an HPACK compression bomb with a Slowloris-style hold to…

information-gatheringnetwork-securitypenetration-testing+3
23 months ago
CVE-2026-54519 preview

CVE-2026-54519

GitHubchaitanyagarware/cve-2026-54519

Public advisory landing page for CVE-2026-54519: missing ownership checks in ai-agent-automation memory APIs enabling cross-user memory read and…

ai-securityauthentication-authorizationcurated-resources+3
12 months ago
CVE-2023-45802 preview

CVE-2023-45802

GitHubmehranturk/cve-2023-45802

CVE-2023-45802 - Apache HTTP/2 Memory Exhaustion DoS Apache versions: 2.4.17 through 2.4.57 Target: Apache/2.4.52 (Ubuntu) - VULNERABLE MehranTurk…

exploitationpenetration-testingvulnerability-analysis+1
5 months ago
CVE-2026-3055 preview

CVE-2026-3055

GitHubnetvanguard-cmd/cve-2026-3055

Proof-of-concept exploit for CVE-2026-3055, a memory overread in NetScaler ADC and Gateway when configured as SAML IDP, with detection and mitigation…

exploitationpenetration-testingvulnerability-analysis+1
5 months ago
cve-2026-24514-Kubernetes-Dos preview

cve-2026-24514-Kubernetes-Dos

GitHubmbanyamer/cve-2026-24514-kubernetes-dos

Proof-of-concept exploit for CVE-2026-24514, a memory exhaustion denial-of-service in ingress-nginx validating admission webhook, allowing…

cloud-securitycontainer-securityexploitation+2
7 months ago
triton-cve-2025-23320 preview

triton-cve-2025-23320

GitHubthere-was-a-bird/triton-cve-2025-23320

Docker-based proof-of-concept demonstrating CVE-2025-23320 in NVIDIA Triton inference server, exploiting shared memory key leakage to trigger an…

cloud-securitycontainer-securityexploitation+3
11 months ago
Tomcat-CVE-2025-31650 preview

Tomcat-CVE-2025-31650

GitHubb1gn0se/tomcat-cve-2025-31650

Proof-of-concept exploit for Apache Tomcat HTTP/2 DoS vulnerability (CVE-2025-31650). Sends malformed priority headers to trigger memory exhaustion.…

educationexploitationpenetration-testing+2
1 year ago
CVE-2014-0160 preview

CVE-2014-0160

GitHub22imer/cve-2014-0160

Dockerized training lab for exploiting Heartbleed (CVE-2014-0160) via TLS heartbeat to leak nginx memory, plus Snort rule to detect attacks.

educationexploitationintrusion-detection+3
8 months ago
CVE-2019-16279 preview

CVE-2019-16279

GitHubianxtianxt/cve-2019-16279

Shell script exploit for CVE-2019-16279 that triggers a denial-of-service via memory corruption by sending excessive CRLF sequences to an HTTP server.

exploitationvulnerability-analysisweb-security
6 years ago
CVE-2006-20001 preview

CVE-2006-20001

GitHubr1az4r/cve-2006-20001

A carefully crafted If: request header can cause a memory read, or write of a single zero byte, in a pool (heap) memory location beyond the header…

curated-resourceseducationexploitation+2
3 years ago
CVE-2025-5777 preview

CVE-2025-5777

GitHub0xgh057r3c0n/cve-2025-5777

Citrix NetScaler Memory Leak PoC

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2023-4966 preview

CVE-2023-4966

GitHub0xkayala/cve-2023-4966

CVE-2023-4966 - NetScaler ADC and NetScaler Gateway Memory Leak Exploit

exploitationinformation-gatheringpenetration-testing+2
2 years ago
bleeding-heart preview

bleeding-heart

GitHubpierceoneill/bleeding-heart

The Heartbleed bug `CVE-2014-0160` is a severe implementation flaw in the OpenSSL library, which enables attackers to steal data from the memory of…

cryptographyeducationexploitation+3
5 years ago
CVE-2014-0160-HeartBleed preview

CVE-2014-0160-HeartBleed

GitHubyashfren/cve-2014-0160-heartbleed

Python exploit for CVE-2014-0160 (Heartbleed) that extracts memory contents from vulnerable OpenSSL servers, adapted for Python 3 compatibility.

exploitationinformation-gatheringpenetration-testing+2
2 years ago
Previous1…8910Next