Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
80 results
WCFDSer-ngng preview

WCFDSer-ngng

GitHubnccgroup/wcfdser-ngng

A Burp Extender plugin, that will make binary soap objects readable and modifiable.

api-security-testingpenetration-testingvulnerability-analysis+3
30
4 years ago
AMFDSer-ngng preview

AMFDSer-ngng

GitHubnccgroup/amfdser-ngng

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
2711 years ago
reDOM preview

reDOM

GitHubweirdmachine64/redom

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

api-security-testingdynamic-analysis-sandboxinginformation-gathering+5
153 months ago
api-scanner-docker preview

api-scanner-docker

GitHubcspf-founder/api-scanner-docker

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

api-securityapi-security-testingconfiguration-auditing+5
96 months ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

api-security-testingcloud-securityexploitation+3
15 days ago
CVE-2026-54356 preview

CVE-2026-54356

GitHubkovachvl/cve-2026-54356

Proof-of-concept exploit and advisory for CVE-2026-54356, a Budibase missing-authorization flaw that lets low-privilege users mint S3 pre-signed…

api-security-testingcloud-securityexploitation+3
20 days ago
CVE-2026-70481 preview

CVE-2026-70481

GitHubfoxer131/cve-2026-70481

Proof-of-concept exploit for an authorization flaw in Open WebUI that lets low-privileged users edit and delete other members' channel messages via…

api-security-testingauthentication-authorizationexploitation+4
29 days ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubrenzi25031469/cve-2026-19478

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

api-security-testinginformation-gatheringpenetration-testing+4
115 days ago
reconix preview

reconix

GitHubaquibpro/reconix

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

api-security-testingcrawlerexploitation+8
24 months ago
CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication preview

CVE-2026-30824-Flowise-NVIDIA-NIM-Authentication

GitHubdylvie/cve-2026-30824-flowise-nvidia-nim-authentication

A proof-of-concept exploit for **CVE-2026-30824**, a critical authentication bypass vulnerability in Flowise that exposes NVIDIA NIM API endpoints…

api-security-testingexploitationpenetration-testing+3
4 months ago
CVE-2021-4191_Exploits preview

CVE-2021-4191_Exploits

GitHubadelittle/cve-2021-4191_exploits

Exploit script for CVE-2021-4191 that enumerates GitLab users via the GraphQL API, useful for security assessments and validating exposure.

api-security-testingexploitationinformation-gathering+3
3 years ago
cve-2023-45612_exploit preview

cve-2023-45612_exploit

GitHubclemfavre/cve-2023-45612_exploit

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

api-security-testingcode-analysiseducation+3
10 months ago
MCP-Inspector-CVE-2025-49596 preview

MCP-Inspector-CVE-2025-49596

GitHubashiqrehan-21/mcp-inspector-cve-2025-49596

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

api-security-testingeducationexploitation+3
1 year ago
s4e-cve-scanner preview

s4e-cve-scanner

GitHubs4e-io-old-labs/s4e-cve-scanner

API-based scanner that retrieves and lists the latest Common Vulnerabilities and Exposures (CVEs) for automated security assessment and vulnerability…

api-security-testinginformation-gatheringvulnerability-scanners
5 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubaureum01/cve-2023-23752

A bash automation that exploits the vulnerable endpoints for the Joomla! API 4.0 - 4.2.7

api-security-testingeducationexploitation+3
2 years ago
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

api-securityapi-security-testingcrawler+12
38.3k1 day ago
android-reverse-engineering-skill preview

android-reverse-engineering-skill

GitHubsimoneavogadro/android-reverse-engineering-skill

Decompiles Android APK/XAPK/JAR/AAR files and extracts HTTP APIs, authentication patterns, and call flows using jadx, with R8-resistant Kotlin name…

android-securityapi-security-testingbinary-analysis+8
7.7k2 months ago
metlo preview

metlo

GitHubmetlo-labs/metlo

Metlo is an open-source API security platform.

api-securityapi-security-testingdefensive-tools+4
1.8k1 year ago
Previous12345Next