Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
janusec preview

janusec

GitHubjanusec/janusec

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

api-securityauthenticationcloud-security+8
1.2k
2 months ago
layerleak preview

layerleak

GitHubbrumbelow/layerleak

layerleak the Docker Hub Secret Scanner

api-securitycloud-securitycontainer-security+3
4419 days ago
kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed preview

kubernetes-client__java_CVE-2020-8570_client-java-parent-9_0_2_fixed

GitHubshoucheng3/kubernetes-client__java_cve-2020-8570_client-java-parent-9_0_2_fixed

Java client library for the Kubernetes API, enabling programmatic management of clusters, pods, deployments, and other resources with support for…

api-securityauthentication-authorizationcloud-infrastructure-security+3
10 months ago
CVE-2026-46456 preview

CVE-2026-46456

GitHuboscerd/cve-2026-46456

Reproducer for CVE-2026-46456 — Apache Camel camel-aws2-sqs inbound message-attribute header injection (Camel control-header injection via…

api-securitycloud-securityexploitation+3
2 months ago
externalip-webhook preview
Archived

externalip-webhook

GitHubrancher/externalip-webhook

CVE-2020-8554: Man in the middle using LoadBalancer or ExternalIPs

api-securitycloud-securityconfiguration-auditing+3
34 years ago
laravel-framework preview

laravel-framework

GitHubderrickschoen/laravel-framework

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

api-securityauthenticationemail-security+3
3 months ago
Rocket.Chat preview

Rocket.Chat

GitHubrocketchat/rocket.chat

The Secure CommsOS™ for mission-critical operations

api-securityauthentication-authorizationcloud-security+4
46.2k9h 30m ago
DevSecOpsGuideline preview

DevSecOpsGuideline

GitHubowasp/devsecopsguideline

The OWASP DevSecOps Guideline can help us to embedding security as a part of the development pipeline.

api-securitycloud-securitycontainer-security+6
1.1k5 days ago
aquaman preview

aquaman

GitHubtech4242/aquaman

🔱 The only independent credential proxy for AI agents: bring-your-own-vault isolation & least-privilege request policies. Your keys stay where you…

api-securityauthentication-authorizationcloud-security+7
373 days ago
CVE-2026-52616 preview

CVE-2026-52616

GitHubs1ko/cve-2026-52616

Advisory and benign PoC for OS command injection in an nmap MCP server, with duplicate CVE tracking, detection guidance, and mitigation.

api-securityexploitationnetwork-security+1
1 month ago
CVE-2026-19650-CVE-2026-19478 preview

CVE-2026-19650-CVE-2026-19478

GitHubhorkimhab/cve-2026-19650-cve-2026-19478

Proof-of-concept exploit resources for CVE-2026-19650 and CVE-2026-19478 targeting a GitLab GraphQL vulnerability, intended for authorized research,…

api-securityeducationexploitation+4
1 month ago
CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass preview

CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass

GitHubbiitts/cve-2026-49230-apisix-jwe-decrypt-auth-bypass

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

api-securityauthenticationcryptography+5
2 months ago
cloudflared preview

cloudflared

GitHubcloudflare/cloudflared

Client for Cloudflare Tunnel enabling secure outbound-only connections to origins via Zero Trust architecture. Supports HTTP, WebSocket, SSH, and RDP…

api-securitycloud-infrastructure-securitycloud-security+3
15.9k3 days ago
fabric8io__kubernetes-client_CVE-2021-4178_5-0-2 preview

fabric8io__kubernetes-client_CVE-2021-4178_5-0-2

GitHubshoucheng3/fabric8io__kubernetes-client_cve-2021-4178_5-0-2

Java client providing fluent DSL access to Kubernetes and OpenShift REST APIs for managing cloud-native infrastructure, pods, services, and…

api-securityauthentication-authorizationcloud-infrastructure-security+3
1 year ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
21.0k1 month ago
CVE-2026-23552 preview

CVE-2026-23552

GitHuboscerd/cve-2026-23552

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

api-securityauthentication-authorizationeducation+3
7 months ago
llm-agent-testbed preview

llm-agent-testbed

GitHubpie-script/llm-agent-testbed

An empirical security testbed evaluating prompt injection, confused-deputy vulnerabilities, and tool-calling defenses in LLM agents.

ai-securityapi-securityeducation+4
1614 days ago
CVE-Wazuh preview

CVE-Wazuh

GitHubhorkimhab/cve-wazuh

Enrolled agent can smuggle arbitrary OpenSearch _bulk operations via DataValue.index. GHSA-ff9g-85jq-r3g3. Draft

api-securityeducationexploitation+3
3 months ago
Previous12Next