Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
CVE-2026-5201 preview

CVE-2026-5201

GitHubkagancapar/cve-2026-5201

CVE-2026-5201: Heap-based buffer overflow in gdk-pixbuf JPEG loader (CWE-122, CVSS 7.5)

binary-analysiseducationexploitation+3
13
11 days ago
CVE-2020-25042-PoC preview

CVE-2020-25042-PoC

GitHubgroppoxx/cve-2020-25042-poc

PoC for CVE-2020-25042: automated Mara CMS 7.5 authenticated PHP upload to RCE, with login hash handling, shell reuse, custom payload support, and…

exploitationpayload-developmentpenetration-testing+3
53 months ago
CVE-2026-9290 preview

CVE-2026-9290

GitHubshinthink/cve-2026-9290

Pre-auth Local File Inclusion in WP User Manager <= 2.9.17 via path traversal in tab parameter (CVSS 7.5)

educationexploitationinformation-gathering+3
1 month ago
CVE-2025-32044 preview

CVE-2025-32044

GitHubshinthink/cve-2025-32044

Moodle 4.5.0-4.5.2 Unauthenticated REST API User Data Exposure via Stack Trace Args Leak | CVSS 7.5

educationexploitationinformation-gathering+4
1 month ago
CVE-2008-1613 preview

CVE-2008-1613

GitHubsecforce/cve-2008-1613

RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in…

database-securityexploitationpenetration-testing+2
29 years ago
CVE-2026-31899 preview

CVE-2026-31899

GitHubsnailsploit/cve-2026-31899

CVE-2026-31899: Exponential DoS via Recursive <use> Element Amplification in CairoSVG (CVSS 7.5 High)

educationexploitationpapers-research+2
3 months ago
CVE-2025-61301 preview

CVE-2025-61301

GitHubegkritsis/cve-2025-61301

High Vulnerability (7.5) - CAPEv2 reporting/mongodb.py and reporting/jsondump.py allow denial-of-analysis when deeply nested or oversized behavior…

dynamic-analysis-sandboxingexploitationmalware-analysis+2
28 months ago
bigint-buffer-safe preview

bigint-buffer-safe

GitHubloserlab/bigint-buffer-safe

Safe, pure-JS drop-in replacement for bigint-buffer. Fixes CVE-2025-3194 (CVSS 7.5). Zero dependencies, no native bindings.

educationencryption-decryption-toolsgeneral-purpose-utilities+2
15 months ago
CVE-2021-43798 preview

CVE-2021-43798

GitHublongwayhomie/cve-2021-43798

CVE-2021-43798 is a vulnerability marked as High priority (CVSS 7.5) leading to arbitrary file read via installed plugins in Grafana application.

exploitationinformation-gatheringpenetration-testing+2
14 years ago
CVE-2021-43798 preview

CVE-2021-43798

GitHub0xf3d0rq/cve-2021-43798

CVE-2021-43798 is a high-severity path traversal vulnerability (CVSS 3.1 score: 7.5) affecting Grafana versions 8.0.0-beta1 through 8.3.0. It allows…

exploitationinformation-gatheringreconnaissance+2
8 months ago
APOLOGEE preview
Archived

APOLOGEE

GitHubrosesecurity/apologee

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

authenticationexploitationexploit-frameworks+8
501 year ago
wp2shell preview

wp2shell

GitHubikow/wp2shell

wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.

educationexploitationlabs-practice+4
101 month ago
CVE-2025-54100 preview

CVE-2025-54100

GitHubosman1337-security/cve-2025-54100
command-and-controlexploitationremote-access-tool+2
237 months ago
CVE-2026-39363 preview

CVE-2026-39363

GitHubsunynov/cve-2026-39363

方便实用的CVE-2026-39363利用工具

data-exfiltrationexploitationpenetration-testing+2
17 days ago
two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal preview

two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

GitHubhunt-benito/two-dots-and-a-slash-cve-2026-18907-tecno-hi-browser-download-path-traversal

Python PoC for CVE-2026-18907 path traversal in TECNO Hi Browser's download handler. Includes malicious HTTP server and naive downloader to…

android-securityexploitationmobile-app-pentesting+4
10 days ago
CVE-2026-63720-datamodel-code-generator preview

CVE-2026-63720-datamodel-code-generator

GitHubrahulreddykarne/cve-2026-63720-datamodel-code-generator

Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)

educationexploitationpayload-development+2
18 days ago
cve-2026-34486-tomcat_encrypt_bypass_reproduction preview

cve-2026-34486-tomcat_encrypt_bypass_reproduction

GitHubrazureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

CVE Reproduction: cve-2026-34486-tomcat_encrypt_bypass_reproduction

educationexploitationpenetration-testing+3
29 days ago
DoS-Braces-3.03 preview

DoS-Braces-3.03

GitHubcyeezy08/dos-braces-3.03

CVE-Candidate: DoS in [email protected] via comma-separated brace expansion (CVE-2024-4068 incomplete fix)

code-analysisexploitationfuzzing+2
20 days ago
Previous123Next