Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
307 results
aegisagent preview

aegisagent

GitHubhuzjie/aegisagent

Runtime security gateway for AI agents: cryptographically attests tool calls, enforces policies, sandboxes execution, and logs tamper-evident audit…

ai-securityanomaly-detectionapi-security+4
22 days ago
CVE-2025-6514 preview

CVE-2025-6514

GitHubcyberency/cve-2025-6514

mcp-remote exposed to OS command injection

api-securityauthenticationcommand-and-control+3
79 months ago
CVE-2023-27587-PoC preview

CVE-2023-27587-PoC

GitHubvagnerd/cve-2023-27587-poc

The simple PoC of CVE-2023-27587

api-securityexploitationinformation-gathering+3
53 years ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
CVE-2020-17518 preview

CVE-2020-17518

GitHubmurataydemir/cve-2020-17518

[CVE-2020-17518] Apache Flink RESTful API Arbitrary File Upload via Directory Traversal

api-securityexploitationpenetration-testing+3
35 years ago
CVE-2021-37580 preview

CVE-2021-37580

GitHubrabbitsafe/cve-2021-37580

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

api-securityauthentication-authorizationexploitation+3
44 years ago
zappzarapp-php-security preview

zappzarapp-php-security

GitLabmarcstraube/zappzarapp-php-security

PHP 8.4+ security library (mirror)

api-securityauthentication-authorizationcode-analysis+6
15h 32m ago
Argus preview

Argus

GitHubdozermx/argus

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

api-securityfuzzinginformation-gathering+9
55 months ago
poc-h2-CVE-2026-71554 preview

poc-h2-CVE-2026-71554

GitHubsunandm/poc-h2-cve-2026-71554

PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

adversarial-attackapi-securityapi-security-testing+4
124 days ago
CVE-2022-24112_POC preview

CVE-2022-24112_POC

GitHubacczdy/cve-2022-24112_poc

CVE-2022-24112_POC

api-securityexploitationpenetration-testing+3
53 years ago
CVE-2018-25031 preview

CVE-2018-25031

GitHubafine-com/cve-2018-25031

.json and .yaml files used to exploit CVE-2018-25031

api-securityexploitationphishing-tools+3
211 months ago
vuln_apps preview

vuln_apps

GitHubclickswave/vuln_apps

Runs a fleet of intentionally vulnerable web/API apps in isolated Docker stacks for local penetration testing and validating scanner findings with…

api-securityeducationlabs-practice+3
124 days ago
cve-2023-34035-mitigations preview

cve-2023-34035-mitigations

GitHubjzheaux/cve-2023-34035-mitigations

Demonstrates CVE-2023-34035 vulnerability in Spring Security with vulnerable and mitigated sample applications, teaching proper servlet mapping and…

api-securitycode-analysiseducation+3
43 years ago
CVE-2026-53959 preview

CVE-2026-53959

GitHubanirbala98/cve-2026-53959

4gaBoards < 3.3.9 - User Information Disclosure

api-securityeducationexploitation+5
114 days ago
PwnedCheck preview

PwnedCheck

GitHubmohamedation/pwnedcheck

A command-line tool to check if passwords have been exposed in data breaches using the Have I Been Pwned (HIBP) API.

api-securityencryption-decryption-toolspassword-cracking+3
32 months ago
Mahoraga-Webapp-Defender preview

Mahoraga-Webapp-Defender

GitHubageofalgorithms/mahoraga-webapp-defender

AI-powered reactive website defense system that detects attacks, analyzes them, and autonomously patches source code in real-time using LLM agents.

ai-securityapi-securityctf+6
44 months ago
enforcement-coverage preview

enforcement-coverage

GitHubarian-gogani/enforcement-coverage

Finds API routes carrying weaker authorization than their siblings. Recovered CVE-2026-45316 from source. Includes the negative results.

api-securitycode-analysisdevsecops+3
19 days ago
Metabase-Setup-Endpoint-SQLi-Fix preview

Metabase-Setup-Endpoint-SQLi-Fix

GitHububitquity/metabase-setup-endpoint-sqli-fix

Fixes unauthenticated SQL injection in a setup endpoint by replacing raw JDBC queries with ORM parameterization and constant-time token validation.

api-securityauthenticationdatabase-security+3
118 days ago
Previous1…101112…18Next