Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Vulnerability Analysis | Kitploit
Categories

Vulnerability Analysis

Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

NewestRelevanceMost popularRecently updated
25173 results
Crawlector preview

Crawlector

GitHubmfmokbel/crawlector

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

osintvulnerability-scannersthreat-feeds-aggregators+5
1238 months ago
mzap preview

mzap

GitHubhahwul/mzap

⚡️ Multiple target ZAP Scanning

vulnerability-scannersdynamic-analysis-sandboxingapi-security-testing+3
11228 days ago
AD-PathFinder preview

AD-PathFinder

GitHubnetspi/ad-pathfinder

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

password-crackingprivilege-escalationreconnaissance+7
9512 days ago
installer preview

installer

GitHubmondoohq/installer

Linux, macOS and Windows Install scripts for cnquery & cnspec

general-purpose-utilitiesvulnerability-scannerscontainer-security+1
8321h 49m ago
CVE-2026-20637-AppleSEPKeyStore-UAF preview

CVE-2026-20637-AppleSEPKeyStore-UAF

GitHub0xjohnnydev/cve-2026-20637-applesepkeystore-uaf

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

ios-securityvulnerability-analysisexploitation+2
541 month ago
CentralizedFirewall preview

CentralizedFirewall

GitHubadriyansyah-mf/centralizedfirewall

provides a Firewall Manager API designed to centralize and streamline the management of firewall configurations

configuration-auditingnetwork-securitydevsecops+1
101 year ago
Pegasus---Forbidden-Buster preview

Pegasus---Forbidden-Buster

GitHubsobri3195/pegasus---forbidden-buster

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

vulnerability-scannersids-ips-evasioninformation-gathering+3
31 year ago
CVE-2023-26692 preview

CVE-2023-26692

GitHubbigzooooz/cve-2023-26692

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

vulnerability-analysisexploitationweb-application-exploitation+2
13 years ago
MongoBleed-exploit preview

MongoBleed-exploit

GitHubeljoamy/mongobleed-exploit

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

memory-forensicsvulnerability-analysisexploitation+5
7 months ago
certighost preview

certighost

GitHubl0u7r3/certighost

Proof-of-concept exploit code for CVE-2026-54121, adapted and edited for validating the vulnerability in affected environments.

vulnerability-analysisexploitationpenetration-testing
1 day ago
CVE-2026-16723 preview

CVE-2026-16723

GitHubsuperman-l/cve-2026-16723

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

payload-generationvulnerability-analysisexploitation+4
2 days ago
CVE-2026-19598-PoC preview

CVE-2026-19598-PoC

GitHubdeadexpl0it/cve-2026-19598-poc

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

privilege-escalationvulnerability-analysisexploitation+3
2 days ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

vulnerability-scannersexploitationweb-application-exploitation+3
12 years ago
CVE-2026-6837-zyxel-export-cgi-command-injection preview

CVE-2026-6837-zyxel-export-cgi-command-injection

GitHubminanagehsalalma/cve-2026-6837-zyxel-export-cgi-command-injection

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

embedded-systems-securityvulnerability-analysisexploitation+3
4 days ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationosintpenetration-testing-frameworks+8
735 days ago
linux preview

linux

GitHubtorvalds/linux

Linux kernel source tree

embedded-systems-securitygeneral-purpose-utilitiesiot-security+9
240.8k2 days ago
PayloadsAllTheThings preview

PayloadsAllTheThings

GitHubswisskyrepo/payloadsallthethings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

privilege-escalationpayload-generationvulnerability-analysis+7
79.9k11 days ago
ghidra preview

ghidra

GitHubnationalsecurityagency/ghidra

Ghidra is a software reverse engineering (SRE) framework

static-analysisdynamic-analysis-sandboxingexploit-frameworks+8
71.1k3 days ago
Previous1…345…1399Next