Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
dynast-bench preview

dynast-bench

GitHubj3ssie/dynast-bench

A DAST benchmark of intentionally-vulnerable apps with ground-truth answer keys for scoring scanners

api-security-testingcurated-resourceseducation+4
20 days ago
your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack preview

your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

GitHubhunt-benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

Proof-of-concept exploit for CVE-2026-68929, demonstrating unauthenticated cross-tenant takeover of FastGPT WeChat channels via public shareId,…

api-security-testingexploitationpenetration-testing+3
7 days ago
CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication preview

CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication

GitHubdylvie/cve-2026-30824-flowise-nvidia-nim-authentication

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

api-security-testingexploitationpenetration-testing+3
4 months ago
gitlab-cve-2026-19478-lab preview

gitlab-cve-2026-19478-lab

GitHubdinosn/gitlab-cve-2026-19478-lab

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

api-security-testingexploitationlabs-practice+4
1017 days ago
Gitlab-CVE-2026-19478 preview

Gitlab-CVE-2026-19478

GitHubpunitdarji/gitlab-cve-2026-19478

Dockerized exploit lab and script for CVE-2026-19478, a critical unauthenticated GitLab GraphQL code injection enabling arbitrary Ruby method calls,…

api-security-testingeducationexploitation+4
13 days ago
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

api-security-testingauthentication-authorizationcontainer-security+3
117 days ago
ActBench preview

ActBench

GitHubzjuicsr/actbench

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

ai-securityapi-security-testinglabs-practice+1
421 days ago
wp2shell-Exploit-Waf-Bypass preview

wp2shell-Exploit-Waf-Bypass

GitHubm4xsec/wp2shell-exploit-waf-bypass

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

api-security-testingexploitationpenetration-testing+4
427 days ago
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…

ai-securityapi-security-testingcloud-infrastructure-security+8
8287 days ago
Arisu preview

Arisu

GitHubrazureink/arisu

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

api-security-testingcrawlerinformation-gathering+2
1 month ago
vuln-scanner preview

vuln-scanner

GitHubzappaboy/vuln-scanner

Vulnerability Assessment Scanner with Report Generation

api-security-testingcloud-securityconfiguration-auditing+9
111 month ago
faraday_burp preview

faraday_burp

GitHubinfobyte/faraday_burp

Burp Extension for collaboration in Faraday

api-security-testingdevsecopspenetration-testing+3
136 months ago
simple-maven preview

simple-maven

GitHubmindpatch/simple-maven

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

api-security-testingeducationlabs-practice+3
1 year ago
dvcsharp-api preview

dvcsharp-api

GitHubappsecco/dvcsharp-api

Damn Vulnerable C# Application (API)

api-security-testingeducationlabs-practice+3
863 years ago
CVE-2025-45809-PoC preview

CVE-2025-45809-PoC

GitHublearner202649/cve-2025-45809-poc

Time-based blind SQL injection proof-of-concept for LiteLLM v1.65.4. Exploits the `/key/block` endpoint to extract database contents and read server…

api-security-testingdatabase-securityeducation+3
3 months ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
22 days ago
CVE-2026-55255-Lab preview

CVE-2026-55255-Lab

GitHubrootdirective-sec/cve-2026-55255-lab

Local Docker lab for reproducing CVE-2026-55255, an IDOR vulnerability in Langflow's Responses API. Validates cross-user flow execution in vulnerable…

api-security-testingeducationlabs-practice+3
2 months ago
CVE-2026-46645-Analysis-Lab preview

CVE-2026-46645-Analysis-Lab

GitHubrootdirective-sec/cve-2026-46645-analysis-lab

Docker-based lab for reproducing CVE-2026-46645, an authorization bypass in SQLAdmin's ajax_lookup endpoint. Includes vulnerable and patched targets,…

api-security-testingeducationlabs-practice+3
2 months ago
Previous123Next