Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2268 results
fastgpt-sandbox-audit preview

fastgpt-sandbox-audit

GitHubqianlijaingshan/fastgpt-sandbox-audit

FastGPT Python sandbox escape chain audit tool (CVE-2026-32128 related, v4.14.8 inspect chain)

ai-securitycontainer-escapedynamic-analysis-sandboxing+4
1
1 month ago
PNGboomer-CVE-2026-77622 preview

PNGboomer-CVE-2026-77622

GitHubsqu1shification/pngboomer-cve-2026-77622

Sliver HTTP(S) C2 PNG bomb DoS exploit — GHSA-663m-7x7m-g4fw (CVE-2026-77622)

command-and-controlexploitationpenetration-testing+2
11 month ago
CVE-2026-5061 preview

CVE-2026-5061

GitHub0xmrma/cve-2026-5061

Consul Template validated where a symlink pointed during template evaluation, but its later dependency fetch read the original path. Retargeting the…

code-analysisdata-exfiltrationeducation+2
12 months ago
cve-2022-42475-poc preview

cve-2022-42475-poc

GitHubull0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

exploitationpenetration-testingred-teaming+3
11 month ago
cve-2026-49352-poc preview

cve-2026-49352-poc

GitHubcovepseng/cve-2026-49352-poc

Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)

authentication-authorizationeducationexploitation+4
12 months ago
CVE-2026-56782-Gorse-Auth-Bypass preview

CVE-2026-56782-Gorse-Auth-Bypass

GitHubbiitts/cve-2026-56782-gorse-auth-bypass

CVE-2026-56782 — Gorse <0.5.10 unauthenticated DB dump/restore (admin_api_key fail-open). Lab + PoC, verified e2e.

authenticationctfdata-exfiltration+6
13 months ago
CVE2_Jenkins_RCE preview

CVE2_Jenkins_RCE

GitHubdavidmgaviria/cve2_jenkins_rce

A proof of concept cross-site WebSocket hijacking exploit for CVE-2024-23898 — a vulnerability affecting Jenkins versions 2.217-2.441. For…

educationexploitationpenetration-testing+3
21 year ago
HLF_TxTime_spoofing preview

HLF_TxTime_spoofing

GitHubshanker-sec/hlf_txtime_spoofing

PoC covering the problem of transaction time manipulation (CVE-2024-45244) in the Hyperledger Fabric blockchain.

cryptographyeducationexploitation+1
22 years ago
attestos preview

attestos

GitHubplunder707/attestos

Bazzite plus a TPM boot attestation layer. Work in progress: builds unverified, UKI mechanism unresolved. Spec: github.com/plunder707/attested-gaming

authenticationcryptographydefensive-tools+2
11 month ago
CVE-2026-52813-Gogs-RCE preview

CVE-2026-52813-Gogs-RCE

GitHubiqx6889/cve-2026-52813-gogs-rce

CVE-2026-52813 (Gogs Path Traversal → Git Hooks RCE) defensive writeup: root-cause & patch analysis, Sigma/SIEM detection rules, IOCs, non-intrusive…

educationincident-responseioc-management+6
12 months ago
CVE-2026-43284---DirtyFrag-Analysis-THM- preview

CVE-2026-43284---DirtyFrag-Analysis-THM-

GitHubrevyhub/cve-2026-43284---dirtyfrag-analysis-thm-

TryHackMe Dirty Frag (CVE-2026-43284) — Linux LPE writeup

ctfeducationexploitation+3
12 months ago
gha-lab-2f775f277c preview

gha-lab-2f775f277c

GitHubpvharmo2/gha-lab-2f775f277c

Authorized lab reproduction of CVE-2025-47928 (spotipy-dev/spotipy pull_request_target secrets exfiltration) — snapshot at vulnerable commit 4f5759d

cloud-securitycurated-resourcesdevsecops+2
28 days ago
cve-2019-5736-exp preview

cve-2019-5736-exp

GitHubmilloni/cve-2019-5736-exp

Exploit for the CVE-2019-5736 runc vulnerability

container-escapeeducationexploitation+2
17 years ago
CVE-2019-19871-AuditGuide preview

CVE-2019-19871-AuditGuide

GitHubvdisec/cve-2019-19871-auditguide

Audit Guide for the Citrix ADC Vulnerability CVE-2019-19871. Collected from multiple sources and threat assessments. Will be updated as new methods…

curated-resourceseducationforensics+3
26 years ago
CVE-2016-3714.ansible.role preview

CVE-2016-3714.ansible.role

GitHubchusiang/cve-2016-3714.ansible.role

Fix ImageMagick Command Injection (CVE-2016-3714) with Ansible.

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
110 years ago
zeek-caldera-detector preview

zeek-caldera-detector

GitHubcorelight/zeek-caldera-detector

A Zeek based Mitre Caldera detector.

anomaly-detectioncommand-and-controlintrusion-detection+2
21 year ago
gotigate preview

gotigate

GitHubgustavorobertux/gotigate

Go-based exploit for CVE-2022-40684 targeting Fortinet FortiGate devices. Automates authentication bypass to gain administrative access via the web…

command-and-controlexploitationpenetration-testing+3
23 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubdevengpk/cve-2022-1388

Exploit and mass-check script for CVE-2022-1388 targeting F5 BIG-IP iControl REST unauthenticated remote command execution. Supports single host,…

command-and-controlexploitationpenetration-testing+3
23 years ago
Previous1…99100Next