Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
305 results
CVE-2026-86259 preview

CVE-2026-86259

GitHubuziii2208/cve-2026-86259

OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

api-securitycloud-securitydata-exfiltration+6
25 days ago
CVE-2023-28432 preview

CVE-2023-28432

GitHubcuerz/cve-2023-28432

CVE-2023-28432 MinIO敏感信息泄露检测脚本

cloud-securitydata-exfiltrationinformation-gathering+2
103 years ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
5 days ago
kong-pwn preview

kong-pwn

GitHubrandomrobbiebf/kong-pwn

Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

api-securitycloud-securityexploitation+6
66 years ago
CVE-2021-21975 preview

CVE-2021-21975

GitHubmurataydemir/cve-2021-21975

[CVE-2021-21975] VMware vRealize Operations Manager API Server Side Request Forgery (SSRF)

cloud-securityexploitationinformation-gathering+3
45 years ago
CVE-2025-27817 preview

CVE-2025-27817

GitHubisee857/cve-2025-27817

Apache Kafka客户端未对用户输入进行严格验证和限制,未经身份验证的攻击者可通过构造恶意配置读取环境变量或磁盘任意内容,或向非预期位置发送请求,提升REST API的文件系统/环境/URL访问权限。

cloud-securityexploitationinformation-gathering+3
51 year ago
CVE-2025-22828 preview

CVE-2025-22828

GitHubstolichnayer/cve-2025-22828

Apache CloudStack vulnerability allows unauthorized access to annotations on certain resources.

cloud-securityexploitationinformation-gathering+2
41 year ago
POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability preview

POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-Vulnerability

GitHubsam00/poc-cve-2026-42826-2026-42826-microsoft-azure-devops-information-disclosure-vulnerability

Exploits CVE-2026-42826 to enumerate and extract sensitive Azure DevOps data via unauthenticated REST API requests: pipeline YAML, variable groups,…

cloud-securityexploitationinformation-gathering+4
2 months ago
domain-protect preview

domain-protect

GitHubovotech/domain-protect

Automated detection of vulnerable domain configurations and subdomain takeover risks across cloud environments, with continuous monitoring and…

cloud-securitymisconfigurationreconnaissance+1
33 years ago
CVE-2026-67620-poc preview

CVE-2026-67620-poc

GitHubabdugafforov-bobur/cve-2026-67620-poc

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

cloud-securityexploitationinformation-gathering+4
12 months ago
attackmapper preview

attackmapper

GitHubbaymaxpop23/attackmapper

attackmapper

cloud-securitynetwork-mappingpenetration-testing+4
28 months ago
CVE-2026-13768 preview

CVE-2026-13768

GitHubmichaeladamgroberman/cve-2026-13768

CVE-2026-13768: Privileged iothubowner IoT Hub credential — fleet enumeration, device RCE, home-network pivot — Gardyn (ICSA-26-183-03)

cloud-securityexploitationiot-security+5
3 months ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
5 months ago
CVE-2026-28766 preview

CVE-2026-28766

GitHubmichaeladamgroberman/cve-2026-28766

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securityauthenticationcloud-security+3
4 months ago
CVE-2026-55726 preview

CVE-2026-55726

GitHubmichaeladamgroberman/cve-2026-55726

CVE-2026-55726: Publicly Listable Azure Blob Storage Container (device logs) - Gardyn (ICSA-26-183-03)

cloud-securityinformation-gatheringiot-security+3
3 months ago
HTB-Facts-Writeup preview

HTB-Facts-Writeup

GitHubkarimelsheikh1/htb-facts-writeup

HackTheBox Facts machine writeup — CVE-2025-2304, MinIO S3 enumeration, SSH key cracking, and facter privilege escalation.

cloud-securityctfeducation+7
5 months ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubcontrast-security-oss/cve-2021-44228

Professional Service scripts to aid in the identification of affected Java applications in TeamServer

cloud-securitycode-analysisdevsecops+3
5 months ago
kali-linux-docker preview

kali-linux-docker

GitHubnu11secur1ty/kali-linux-docker

kali-linux-docker

cloud-securitycontainer-securitydevsecops+8
16 years ago
Previous1…151617Next