Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17584 results
sast-scan-action preview

sast-scan-action

GitHuboffensive360/sast-scan-action

GitHub Action: Offensive360 SAST scan with SARIF output for code scanning. 60+ languages. Free for open source.

api-security-testingcloud-securitycode-analysis+4
1 month ago
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

api-security-testingcloud-securitycode-analysis+3
1 month ago
CVE-2026-73309 preview

CVE-2026-73309

GitHubbombobombone/cve-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

authentication-authorizationexploitationpapers-research+2
15h 2m ago
CVE-2026-73310 preview

CVE-2026-73310

GitHubbombobombone/cve-2026-73310

Proof of concept and technical write-up for CVE-2026-73310, an OAuth2 authorization code redirect URI binding flaw in XenForo before 2.3.13,…

authenticationexploitationvulnerability-analysis+2
15h 1m ago
CVE-2026-73311 preview

CVE-2026-73311

GitHubbombobombone/cve-2026-73311

Proof-of-concept exploit demonstrating OAuth2 authorization code reuse in XenForo before 2.3.13, allowing token replay and multiple token families.

authenticationexploitationvulnerability-analysis+2
15h 1m ago
CVE-2026-73314 preview

CVE-2026-73314

GitHubbombobombone/cve-2026-73314

Proof-of-concept exploit for CVE-2026-73314, a PayPal REST webhook signature verification bypass in XenForo before 2.3.13, allowing unauthorized…

exploitationvulnerability-analysisweb-application-exploitation+1
15h 1m ago
CVE-2026-73315 preview

CVE-2026-73315

GitHubbombobombone/cve-2026-73315

Proof-of-concept and technical write-up for CVE-2026-73315, an SSRF in XenForo's PayPal REST webhook handler allowing blind server-side HTTP requests.

exploitationvulnerability-analysisweb-application-exploitation+1
15h 1m ago
CVE-2026-73316 preview

CVE-2026-73316

GitHubbombobombone/cve-2026-73316

Proof-of-concept and technical write-up for CVE-2026-73316, a PayPal REST webhook replay vulnerability in XenForo before 2.3.13, including…

educationexploitationpapers-research+2
15h 1m ago
CVE-2026-73317 preview

CVE-2026-73317

GitHubbombobombone/cve-2026-73317

Proof-of-concept exploit and technical write-up for CVE-2026-73317, an authorization bypass in XenForo allowing limited admins to approve content as…

authentication-authorizationexploitationmisconfiguration+3
15h 1m ago
CVE-2026-73318 preview

CVE-2026-73318

GitHubbombobombone/cve-2026-73318

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…

authentication-authorizationexploitationmisconfiguration+3
15h 1m ago
CVE-2026-73319 preview

CVE-2026-73319

GitHubbombobombone/cve-2026-73319

Proof-of-concept exploit and technical write-up for CVE-2026-73319, a same-host javascript: URI XSS in XenForo before 2.3.13, including reproduction…

educationexploitationpapers-research+2
15h 1m ago
CVE-2026-74239 preview

CVE-2026-74239

GitHubbombobombone/cve-2026-74239

Proof of concept and technical write-up for CVE-2026-74239, a path traversal vulnerability in XenForo style archive imports on Windows, allowing file…

exploitationpenetration-testingvulnerability-analysis+2
15 hours ago
CVE-2026-82222 preview

CVE-2026-82222

GitHubghostlyrootb2h/cve-2026-82222

Exploit framework for CVE-2026-82222, an unauthenticated RCE in GiveWP WordPress plugin. Supports mass scanning, auto-detection, multi-threading,…

command-and-controlexploitationinformation-gathering+5
12h 12m ago
CVE-2026-77276-PoC preview

CVE-2026-77276-PoC

GitHubmorzan6/cve-2026-77276-poc

CVE-2026-77276 pre-auth macro RCE via convert-to on Collabora Online

exploitationpenetration-testingred-teaming+2
1 day ago
CVE-2026-84118-who-labeled-the-crit-as-a-high preview

CVE-2026-84118-who-labeled-the-crit-as-a-high

GitHubsneakynachos/cve-2026-84118-who-labeled-the-crit-as-a-high

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

binary-exploitationexploitationmemory-forensics+2
115h 31m ago
CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm preview

CVE-2026-85046-who-put-the-silverback-guerilla-in-the-wasm

GitHubsneakynachos/cve-2026-85046-who-put-the-silverback-guerilla-in-the-wasm

Proof-of-concept exploit for CVE-2026-85046 in Chrome 152.0.7977.75, demonstrating type confusion in sort() to achieve arbitrary code execution via a…

binary-exploitationexploitationvulnerability-analysis+1
112h 34m ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubth3purge/cve-2026-39987

Proof-of-concept exploit for CVE-2026-39987, a pre-authentication RCE in Marimo's terminal WebSocket endpoint. Demonstrates unauthenticated command…

educationexploitationpenetration-testing+3
111h 51m ago
CVE-2026-85046 preview

CVE-2026-85046

GitHubatiilla/cve-2026-85046

Proof-of-concept and technical analysis for CVE-2026-85046, a V8 type confusion in inline Array.prototype.sort, including root cause, patch diff, and…

binary-analysiseducationexploitation+3
12h 18m ago
Previous12…100Next