Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
cve-2022-42475 preview

cve-2022-42475

GitHubamir-hy/cve-2022-42475

FortiOS buffer overflow vulnerability

binary-exploitationeducationexploitation+2
7
3 years ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubfranckferman/cve-2026-24061

GNU InetUtils telnetd - Unauthenticated Remote Root via NEW-ENVIRON Variable Injection.

authenticationeducationexploitation+5
55 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubharygovind/cve-2026-24061

CVE-2026-24061-PoC

authenticationexploitationnetwork-security+3
2 months ago
CVE-2011-2523 preview

CVE-2011-2523

GitHublynk4/cve-2011-2523

Python exploit for vsftpd 2.3.4 - Backdoor Command Execution

command-and-controlexploitationpayload-development+3
43 years ago
CVE-2026-41651 preview

CVE-2026-41651

GitHublutfifakee-project/cve-2026-41651

Local privilege escalation exploit targeting PackageKit's TOCTOU race condition (CVE-2026-41651). Escalates from unprivileged user to root via polkit…

binary-exploitationeducationexploitation+3
43 months ago
vsFTPd-2.3.4-Exploit preview

vsFTPd-2.3.4-Exploit

GitHubjun41ds2709/vsftpd-2.3.4-exploit

Python exploit for the vsFTPd 2.3.4 backdoor (CVE-2011-2523).

binary-exploitationctfeducation+3
113 days ago
CVE-2026-41940-analysis preview

CVE-2026-41940-analysis

GitHuboguz-kagan-akar/cve-2026-41940-analysis

Technical analysis of the cPanel/WHM auth bypass

authentication-authorizationeducationexploitation+5
1 month ago
CVE-2026-0073 preview

CVE-2026-0073

GitHubfredevsec/cve-2026-0073

0-Click RCE Android Adb TLS Wireless Debugging

android-securityauthentication-authorizationexploitation+3
13 months ago
CVE-2007-5962 preview

CVE-2007-5962

GitHubantogit-sys/cve-2007-5962

vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption

educationexploitationlabs-practice+2
13 years ago
CVE-2025-32433 preview

CVE-2025-32433

GitHub0xblackash/cve-2025-32433

CVE-2025-32433

exploitationpenetration-testingred-teaming+3
5 months ago
mini-shai-hulud-detector preview

mini-shai-hulud-detector

GitHubprashanthnataraj/mini-shai-hulud-detector

One-command scanner for the Mini Shai-Hulud npm supply-chain worm (CVE-2026-45321). Detect before rotating tokens.

forensicsincident-responsemalware-analysis+3
3 months ago
heartbleed preview

heartbleed

GitHubbelmind/heartbleed

A collection of scripts and instructions to test CVE-2014-0160 (heartbleed). ❤️ 🩸

exploitationinformation-gatheringpenetration-testing+2
15 years ago
CVE-2026-0073-Android-client-TLS-auth-bypass preview

CVE-2026-0073-Android-client-TLS-auth-bypass

GitHubm00ddy/cve-2026-0073-android-client-tls-auth-bypass

translating original python exploit to C

android-securitybinary-exploitationexploitation+3
3 months ago
Harmonic preview

Harmonic

GitLabrunik/harmonic

Suite for reverse shell handling geared toward working within the native shell

command-and-controlinformation-gatheringpayload-development+7
8 years ago
CVE-2021-42756 preview

CVE-2021-42756

GitHub3ndorph1n/cve-2021-42756

Proof-of-concept for a stack-based buffer overflow in FortiWeb, demonstrating unauthenticated remote code execution via crafted HTTP requests when…

exploitationpenetration-testingred-teaming+2
3 years ago
CVE-2024-47176 preview

CVE-2024-47176

GitHubworkabhiwin09/cve-2024-47176

CUPS Browsd Check_CVE-2024-47176

exploitationnetwork-securitypenetration-testing+2
1 year ago
Vulnerability-DLink-CVE-2025-14659 preview

Vulnerability-DLink-CVE-2025-14659

GitHubpeterlinccl/vulnerability-dlink-cve-2025-14659

Static analysis (Ghidra) and custom packet-crafting (Scapy) demonstrating a root-level DHCP command injection vulnerability (CVE-2025-14659) in…

embedded-systems-securityexploitationfirmware-analysis+6
2 days ago
CVE-2026-88899 preview

CVE-2026-88899

GitHubuziii2208/cve-2026-88899

Knowns 0.30.0: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

ai-securityauthentication-authorizationexploitation+4
1 day ago
Previous12345Next