Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
10507 results
ghostlock-pfem10 preview

ghostlock-pfem10

GitHubcxlfhx/ghostlock-pfem10

GhostLock (CVE-2026-43499 / IonStack) research for OPPO Find X5 Pro (PFEM10): exploit chain, progress, blocker log, and OPPO 5-series kernel notes

android-securitybinary-exploitationexploitation+7
7 days ago
galaxy-a37-root preview

galaxy-a37-root

GitHubimeiplus/galaxy-a37-root

CVE-2026-43499 exploit payload for Samsung Galaxy A37 (A376BXXS4AZG4, kernel 6.1.138-android14-11)

android-securitybinary-exploitationexploitation+5
9 days ago
lenovo_y700_tb320fc_on_CVE-2025-21479 preview

lenovo_y700_tb320fc_on_CVE-2025-21479

GitHubxjoker/lenovo_y700_tb320fc_on_cve-2025-21479

In-memory kernel privilege escalation for Lenovo Legion Y700 2023 (TB320FC) exploiting CVE-2025-21479, a Qualcomm Adreno GPU SMMU flaw, with ReSukiSU…

android-securitybinary-exploitationexploitation+6
20h 46m ago
CVE-2026-89026 preview

CVE-2026-89026

GitHubcflowsec/cve-2026-89026

Python PoC that forges a hard-coded HS256 JWT to exploit CVE-2026-89026 in Issabel pbxapi, enabling unauthenticated remote OS command execution via…

authenticationcommand-and-controlexploitation+5
16h 11m ago
asus-i005-cve-2026-43499 preview

asus-i005-cve-2026-43499

GitHubhuaguiqi/asus-i005-cve-2026-43499

CVE-2026-43499 (GhostLock) adaptation for ASUS ROG Phone 5S — UAF trigger + pselect stack reclaim, KASLR leak blocked

android-securitybinary-exploitationexploitation+7
16h 30m ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubctdal/cve-2026-41940-poc

Exploits CVE-2026-41940, a cPanel/WHM authentication bypass, to gain root WHM access and run post-exploitation commands, account listing, and…

authenticationcommand-and-controlexploitation+7
4419h 57m ago
Dubbo-deserialization preview

Dubbo-deserialization

GitHubkeloke/dubbo-deserialization

[CVE-2020-1948] Apache Dubbo Provider default deserialization cause RCE

exploitationpenetration-testingvulnerability-analysis+1
6 years ago
Aresius preview

Aresius

GitHub0xmarik/aresius

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

api-security-testingfuzzinginformation-gathering+6
23 days ago
ActGuard preview

ActGuard

GitHubbinzhwang/actguard

Pre-execution action-auditing defense that detects and masks indirect prompt injection in tool-using LLM agents using embedding retrieval and…

ai-securitydefensive-toolsmachine-learning+2
3 days ago
CVE-2026-86218 preview

CVE-2026-86218

GitHubudyz/cve-2026-86218

Proof-of-concept exploit for CVE-2026-86218, an unauthenticated RCE in N-able N-central via Struts BeanUtils, with version detection and command…

exploitationpayload-developmentpenetration-testing+3
3 days ago
CVE-2026-92247 preview

CVE-2026-92247

GitHubd1n3sh-0x3/cve-2026-92247

Python PoC for CVE-2026-92247, an authenticated RCE in SynaptikCMS file manager via PHP upload and rename validation bypass.

exploitationpayload-developmentpenetration-testing+3
11 day ago
zte-blade-v40-vita-unlock preview

zte-blade-v40-vita-unlock

GitHubredzrush101/zte-blade-v40-vita-unlock

Unlocking the ZTE Blade V40 Vita (P606F02 / Unisoc UMS9230 / UFS) bootloader via CVE-2022-38694 - Linux scripts, the FBE post-unlock hang fix, and…

android-securityembedded-systems-securityexploitation+6
1 day ago
cve-2026-43499-aak-an00 preview

cve-2026-43499-aak-an00

GitHubhui191/cve-2026-43499-aak-an00

Honor WIN RT (AAK-AN00) CVE-2026-43499 temporary root - research notes

android-securitybinary-exploitationexploitation+6
5 days ago
ghostlock-s26 preview

ghostlock-s26

GitHub1ndevelopment/ghostlock-s26

GhostLock (CVE-2026-43499) app for the Galaxy S26 series

android-securityexploitationmobile-app-pentesting+5
15 days ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubbardlaudian/cve-2025-24071

Dependency-free Python PoC generator for CVE-2025-24071 that crafts a malicious .library-ms file in a ZIP to trigger Windows Explorer NTLM hash…

exploitationinformation-gatheringlateral-movement+5
3 days ago
CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day preview

CVE-2026-82090-18-Years-All-Versions-CVSS-9.2-CRITICAL-The-Pocket-Forever-Day

GitHubfunfactor1/cve-2026-82090-18-years-all-versions-cvss-9.2-critical-the-pocket-forever-day

CVE-2026-82090 · CVSS 9.2 CRITICAL · 0-click stored XSS in Mozilla Pocket — all versions (v0 → v8.33.0.0) · 18-year forever-day · no patch · MITRE…

android-securityeducationexploitation+7
21 day ago
langflow-CVE-2026-17633-PoC preview

langflow-CVE-2026-17633-PoC

GitHuboscar-collado/langflow-cve-2026-17633-poc

PoC for CVE-2026-17633 — Authenticated RCE in IBM Langflow OSS 1.0.0–1.10.3 via custom_component endpoint. Includes CVE-2026-17632 AST scanner bypass…

code-analysisexploitationpenetration-testing+2
1 day ago
pentest-i021-poc-1789486727 preview

pentest-i021-poc-1789486727

GitHubqq1111111111/pentest-i021-poc-1789486727

Temporary proof-of-concept verification artifacts for CVE-2024-4367, a PDF.js arbitrary JavaScript execution vulnerability.

exploitationpapers-researchpenetration-testing+2
1 day ago
Previous12…100Next