Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1402 results
XcInspector preview

XcInspector

GitLabswiftdevcollective/xcodeprojectsecurity

A macOS app to scan Xcode project files for possible security issues.

code-analysisconfiguration-auditingdefensive-tools+4
9
1 year ago
Public_Exploit-1--Wordpress-CVE-2021-29447 preview

Public_Exploit-1--Wordpress-CVE-2021-29447

GitHubkashyapghodasara/public_exploit-1--wordpress-cve-2021-29447

CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress

exploitationinformation-gatheringpenetration-testing+3
5 days ago
CVE-2025-57231 preview

CVE-2025-57231

GitHubanirbala98/cve-2025-57231

Python PoC exploit for CVE-2025-57231, an unauthenticated path traversal in Docmost < 0.22.0 that reads arbitrary files via the avatar endpoint.

exploitationinformation-gatheringpenetration-testing+3
15 days ago
Aegis-releases preview

Aegis-releases

GitHubadarsh14734/aegis-releases

Sandbox and MCP proxy that blocks AI coding agents from reading SSH keys, AWS credentials, and .env files, with deny-by-default policy and…

ai-securityauthentication-authorizationconfiguration-auditing+5
6 days ago
CVE-2026-43783 preview

CVE-2026-43783

GitHubandrd3v/cve-2026-43783

Proof-of-concept and technical writeup for CVE-2026-43783, a macOS local privilege escalation via DesktopServicesHelper XPC arbitrary chown to gain…

binary-analysisexploitationpapers-research+4
212 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubsolivaquaant/cve-2026-85706

Proof-of-concept and reproduction lab for CVE-2026-85706, an unauthenticated path-traversal file read in GitLab CE/EE repository commits and files…

data-exfiltrationexploitationinformation-gathering+7
10 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubmhtsec/cve-2026-85706

Python PoC for CVE-2026-85706, an unauthenticated path traversal in GitLab CE/EE Repository Commits API that leaks arbitrary local files via a…

data-exfiltrationexploitationinformation-gathering+5
1010 days ago
CVE-2026-85706-PoC preview

CVE-2026-85706-PoC

GitHubsolivaquaant/cve-2026-85706-poc

PoC for CVE-2026-85706: GitLab CE/EE unauthenticated arbitrary local file read

data-exfiltrationexploitationinformation-gathering+4
10 days ago
CVE-2026-77578 preview

CVE-2026-77578

GitHubsoskalai/cve-2026-77578

Python proof-of-concept exploiting CVE-2026-77578, an authenticated path traversal in Xibo CMS that reads arbitrary local files via crafted XML…

exploitationpenetration-testingvulnerability-analysis+2
12 days ago
CVE-2022-0847 preview

CVE-2022-0847

GitHubvudangducminh/cve-2022-0847

Proof-of-concept exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel race condition enabling unprivileged writes to read-only files and privilege…

binary-exploitationeducationexploitation+3
7 days ago
zotlit-PoC preview

zotlit-PoC

GitHubsqueeze440/zotlit-poc

PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

data-exfiltrationexploitationinformation-gathering+3
10 days ago
CVE-2026-67401 preview

CVE-2026-67401

GitHubaxedos/cve-2026-67401

Python proof-of-concept for CVE-2026-67401, an authenticated SQL injection in cPanel EmailTrack that allows arbitrary file write as root via SQLite…

exploitationpayload-developmentpenetration-testing+2
212 days ago
CVE-2026-83991-writeup-and-poc preview

CVE-2026-83991-writeup-and-poc

GitHubkarollooool/cve-2026-83991-writeup-and-poc

Proof-of-concept demonstrating a Windows Cloud Files access-check bypass (CVE-2026-83991) that converts a read-only file into a cloud placeholder via…

binary-exploitationexploitationprivilege-escalation+1
159 days ago
DNSlivery preview

DNSlivery

GitHubsamybaiwir/dnslivery

Easy files and payloads delivery over DNS

command-and-controldata-exfiltrationdns-analysis+2
4268 months ago
spookyssl-pcaps preview

spookyssl-pcaps

GitHubfox-it/spookyssl-pcaps

PCAPs and Suricata signatures for detecting OpenSSL CVE-2022-3602 exploitation attempts, including malicious client/server traffic and legitimate…

intrusion-detectionnetwork-securitypacket-sniffing-analysis+2
103 years ago
efiSeek preview

efiSeek

GitHubdsecurity/efiseek

Ghidra plugin that automates UEFI firmware analysis by identifying known GUIDs, protocols, SMI handlers, and interrupt functions, with headless…

binary-analysisembedded-systems-securityfirmware-analysis+3
4082 years ago
CVE-2026-56718 preview

CVE-2026-56718

GitHubhellkkid/cve-2026-56718

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

embedded-systems-securityexploitationiot-security+3
18 days ago
gha-lab-d14c91f1bb preview

gha-lab-d14c91f1bb

GitHubpvharmo2/gha-lab-d14c91f1bb

Security-research lab: reproduction of CVE-2025-58371 (GitHub Actions command injection via PR title in Discord PR Notifier), snapshot of…

curated-resourceseducationexploitation+1
17 days ago
Previous12…78Next