Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
241 results
CVE-2026-33032 preview

CVE-2026-33032

GitHubkeraattin/cve-2026-33032

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

api-securityexploitationnetwork-security+4
5
4 months ago
CVE-2026-35616-detector.py preview

CVE-2026-35616-detector.py

GitHubfevar54/cve-2026-35616-detector.py

Detector de CVE-2026-35616: identifica servidores FortiClient EMS vulnerables (7.4.5-7.4.6).

api-securitynetwork-securitypenetration-testing+2
4 months ago
cve-2026-33032-scanner preview

cve-2026-33032-scanner

GitHubtwinson333/cve-2026-33032-scanner

Non-destructive vulnerability scanner for Nginx-UI MCP Endpoint Authentication Bypass (CVE-2026-33032)

api-securityauthenticationexploitation+3
34 months ago
CVE-2021-45232 preview

CVE-2021-45232

GitHubyggcwhat/cve-2021-45232

Batch vulnerability scanner that integrates FOFA to discover and test Apache APISIX Dashboard instances for CVE-2021-45232 unauthorized access.

api-securityexploitationinformation-gathering+2
14 years ago
CVE-2026-0915-json-Patch.-V2.0 preview

CVE-2026-0915-json-Patch.-V2.0

GitHubcyberwulfy200-dev/cve-2026-0915-json-patch.-v2.0

Enterprise-grade JSON validator security patch that fixes CVE-2026-0915 with strict schema validation, input sanitization, rate limiting, and…

api-securitycode-analysisdevsecops+3
6 months ago
CVE-2026-13736 preview

CVE-2026-13736

GitHubminhhk68/cve-2026-13736

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

api-securityexploitationinformation-gathering+3
7 days ago
CVE-2026-58231 preview

CVE-2026-58231

GitHubwildandeveloper/cve-2026-58231

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

api-securityauthenticationinformation-gathering+4
7 days ago
CVE-2026-52616 preview

CVE-2026-52616

GitHubs1ko/cve-2026-52616

Advisory and benign PoC for OS command injection in an nmap MCP server, with duplicate CVE tracking, detection guidance, and mitigation.

api-securityexploitationnetwork-security+1
7 days ago
api-security-audit-action preview

api-security-audit-action

GitHub42crunch/api-security-audit-action

Automates static API security auditing of OpenAPI contracts in CI/CD, running 300+ checks for authentication, authorization, and data constraints,…

api-securityapi-security-testingdefensive-tools+3
3619 days ago
cover preview

cover

GitHubdavidcarliez/cover

Local privacy proxy that replaces secrets and PII before AI requests leave your machine.

ai-securityapi-securitydefensive-tools+3
226 days ago
opa preview

opa

GitHubopen-policy-agent/opa

Declarative policy engine that enables authorization and policy enforcement across services, Kubernetes, Terraform, Docker, and APIs using the Rego…

api-securityauthenticationauthentication-authorization+10
12.2k1 day ago
Argus preview

Argus

GitHubdozermx/argus

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

api-securityfuzzinginformation-gathering+9
55 months ago
sentrymcp preview

sentrymcp

GitHubzaydmulani09/sentrymcp

A static + runtime security scanner for MCP (Model Context Protocol) servers

ai-securityapi-securitymisconfiguration+3
10 days ago
CVE-2026-53959 preview

CVE-2026-53959

GitHubanirbala98/cve-2026-53959

4gaBoards < 3.3.9 - User Information Disclosure

api-securityeducationexploitation+5
110 days ago
CVE-2026-19478-PoC preview

CVE-2026-19478-PoC

GitHubdavkharrr/cve-2026-19478-poc

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

api-securityexploitationinformation-gathering+3
1111 days ago
CVE-2026-19650-CVE-2026-19478 preview

CVE-2026-19650-CVE-2026-19478

GitHubhorkimhab/cve-2026-19650-cve-2026-19478

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

api-securityeducationexploitation+4
12 days ago
CVE-2026-71203-PoC preview

CVE-2026-71203-PoC

GitHubnel-droid/cve-2026-71203-poc

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

api-securityapi-security-testingexploitation+4
13 days ago
CVE-2026-73519-WolfStack-PoC preview

CVE-2026-73519-WolfStack-PoC

GitHubsqueeze440/cve-2026-73519-wolfstack-poc

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

api-securityauthenticationcontainer-security+3
11 days ago
Previous12…14Next