Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2902 results
CVE-2026-14856-TastyIgniter preview

CVE-2026-14856-TastyIgniter

GitHubjonas-fernandez-as/cve-2026-14856-tastyigniter

CVE-2026-14856 TastyIgniter v4.3.0

educationexploitationpenetration-testing+3
1 month ago
cve-2025-29927 preview

cve-2025-29927

GitHubfomovet/cve-2025-29927

POC for CVE-2025-29927

exploitationpenetration-testingvulnerability-analysis+2
2 months ago
CVE-2011-3192-apache-exploit preview

CVE-2011-3192-apache-exploit

GitHubbluedragonsecurity/cve-2011-3192-apache-exploit

CVE-2011-3192 - Remote Apache DOS for Apache versions 1.3.x, 2.0.64 and below and 2.2.19 and below. Developed in 2011 by Antonius (ev1lut10n / w1sdom)

exploitationpenetration-testingvulnerability-analysis+1
21 month ago
CVE-2026-53959 preview

CVE-2026-53959

GitHubanirbala98/cve-2026-53959

4gaBoards < 3.3.9 - User Information Disclosure

api-securityeducationexploitation+5
118 days ago
CVE-2026-51592 preview

CVE-2026-51592

GitHubardakrg/cve-2026-51592

Path Traversal vulnerability in TahaBakhtari/SubtitleGenerator - CVE-2026-51592

curated-resourceseducationpapers-research+2
1 month ago
CVE-2026-15718-who-put-ptrs-in-my-wasm preview

CVE-2026-15718-who-put-ptrs-in-my-wasm

GitHubsneakynachos/cve-2026-15718-who-put-ptrs-in-my-wasm

PoC exploit chain for CVE-2026-15718: SpiderMonkey wasm baseline compiler array.fill missing-sync -> invalid pointer -> addrOf/fakeobj -> arbitrary…

binary-exploitationexploitationpayload-development+3
114 days ago
CVE-2026-44402 preview

CVE-2026-44402

GitHubvirgula0/cve-2026-44402

Pre-Authenticated Full Root Remote Command Execution in Voltronic Power SNMP Web Pro 1.1

embedded-systems-securityexploitationiot-security+5
125 days ago
Mahoraga-Webapp-Defender preview

Mahoraga-Webapp-Defender

GitHubageofalgorithms/mahoraga-webapp-defender

AI-powered reactive website defense system that detects attacks, analyzes them, and autonomously patches source code in real-time using LLM agents.

ai-securityapi-securityctf+6
44 months ago
CVE-2026-64638 preview

CVE-2026-64638

GitHub4minx/cve-2026-64638

CVE-2026-64638 (XSS2shell) POC.

exploitationpayload-developmentpenetration-testing+3
129 days ago
CVE-2026-25991 preview

CVE-2026-25991

GitHubdrkim-dev/cve-2026-25991

Proof-of-concept exploit for CVE-2026-25991, a blind SSRF in Tandoor Recipes' Cookmate import, allowing authenticated users to access internal…

exploitationpenetration-testingred-teaming+3
25 months ago
CVE-2026-33033-PoC preview

CVE-2026-33033-PoC

GitHubch4n3-yoon/cve-2026-33033-poc

Proof-of-concept exploit for CVE-2026-33033, a denial-of-service vulnerability in Django's MultiPartParser via base64 whitespace CPU amplification,…

exploitationpenetration-testingvulnerability-analysis+1
24 months ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubeqstlab/cve-2024-34102

Adobe Commerce XXE exploit

educationexploitationlabs-practice+3
51 year ago
CVE-2021-38699 preview

CVE-2021-38699

GitHubjustin-1993/cve-2021-38699

TastyIgniter 3.0.7 allows XSS via the name field during user-account creation

exploitationpenetration-testingvulnerability-analysis+2
45 years ago
heartbleed preview

heartbleed

GitHubcheese-hub/heartbleed

Educational Docker-based lab demonstrating the Heartbleed bug (CVE-2014-0160) with hacker, victim, and server containers for hands-on exploitation…

container-securityctfeducation+4
27 years ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubrecorded-texteditor120/cve-2026-31802

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

curated-resourceseducationexploitation+3
122h 2m ago
Metabase-Setup-Endpoint-SQLi-Fix preview

Metabase-Setup-Endpoint-SQLi-Fix

GitHububitquity/metabase-setup-endpoint-sqli-fix

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

api-securityauthenticationdatabase-security+3
122 days ago
CVE-2024-0406-POC preview

CVE-2024-0406-POC

GitHubwalidpyh/cve-2024-0406-poc

CVE-2024-0406 POC using symlinks

binary-exploitationeducationexploitation+3
51 year ago
CVE-2024-38473 preview

CVE-2024-38473

GitHubabdurahmon3236/cve-2024-38473

Proof-of-concept demonstrating an encoding flaw in Apache HTTP Server mod_proxy that can bypass authentication via crafted encoded URLs.

authentication-authorizationexploitationpenetration-testing+3
32 years ago
Previous1…969798…100Next