Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
263 results
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
12
24 days ago
PQC-Scanner preview

PQC-Scanner

GitHubcyberjez/pqc-scanner

The PQC Network Scanner is a quantum‑focused network assessment tool that scans TLS/SSL certificates across enterprise environments to identify…

cloud-securitycryptographynetwork-security+2
199 months ago
flask_heroku_redirector preview

flask_heroku_redirector

GitHubkillswitch-gui/flask_heroku_redirector

flask heroku C2 redirector template

cloud-securitycommand-and-controlpenetration-testing+3
119 years ago
test_cve-2023-46747 preview

test_cve-2023-46747

GitHubnvansluis/test_cve-2023-46747

Python script to test F5 BIG-IP for CVE-2023-46747 and add an administrator account if vulnerable.

cloud-securityconfiguration-auditingexploitation+3
72 years ago
CVE-2026-2472-Vertex-AI-SDK-Google-Cloud preview

CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

GitHubmegafart1/cve-2026-2472-vertex-ai-sdk-google-cloud

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

ai-securitycloud-securityeducation+3
23 days ago
react2shell-toolkit preview

react2shell-toolkit

GitHubolezhaku/react2shell-toolkit

Toolkit for CVE-2025-55182, also known as React2Shell.

cloud-securitydatabase-securityexploitation+8
43 months ago
My-Exploits preview

My-Exploits

GitHubm4xsec/my-exploits

Metasploit modules, Python PoCs and throwaway Docker labs for four platform CVEs: Keycloak (CVE-2026-18963), Apache NiFi (CVE-2026-39816), HashiCorp…

cloud-securitycontainer-securityeducation+7
125 days ago
CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath preview

CVE-2026-21008-Kubernetes-Service-Account-Token-Mounted-in-HostPath

GitHubgeorge0papasotiriou/cve-2026-21008-kubernetes-service-account-token-mounted-in-hostpath

Proof-of-concept exploit for Kubernetes service-account token disclosure via hostPath mounts; includes vulnerable pod YAML and Python token-theft…

cloud-infrastructure-securitycloud-securitycontainer-security+4
1 month ago
CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata preview

CVE-2026-3333-DNS-Rebinding-to-Steal-Cloud-Metadata

GitHubgeorge0papasotiriou/cve-2026-3333-dns-rebinding-to-steal-cloud-metadata

Python exploit for CVE-2026-3333 demonstrating DNS rebinding to access cloud metadata and steal IAM credentials through an SSRF-vulnerable web app.

cloud-securitydata-exfiltrationexploitation+4
1 month ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
1 month ago
CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation preview

CVE-2026-21019-Kubernetes-CronJob-Suspended-Execution-via-Time-Manipulation

GitHubgeorge0papasotiriou/cve-2026-21019-kubernetes-cronjob-suspended-execution-via-time-manipulation

Reproduces CVE-2026-21019 by manipulating node clock to force early Kubernetes CronJob execution; includes vulnerable YAML manifest and Python…

adversarial-attackcloud-infrastructure-securitycloud-security+3
1 month ago
CVE-2021-41805 preview

CVE-2021-41805

GitHubblackm4c/cve-2021-41805

HashiCorp Consul exploit with python. (CVE-2021-41805)

cloud-securityexploitationpenetration-testing+3
13 years ago
palo-alto-cve-2026-0265-checker preview

palo-alto-cve-2026-0265-checker

GitHubtstephens1080/palo-alto-cve-2026-0265-checker

Python script to sweep a fleet of Palo Alto firewalls and Panoramas via SSH, check PAN-OS version against CVE-2026-0265 (Authentication Bypass via…

authenticationcloud-securityconfiguration-auditing+3
4 months ago
s3-bucket-take-0v3r preview

s3-bucket-take-0v3r

GitHubjenderal92/s3-bucket-take-0v3r

AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool

cloud-securityconfiguration-auditinginformation-gathering+4
13 months ago
CVE-2023-34233_Proof_OF_Concept preview

CVE-2023-34233_Proof_OF_Concept

GitHubnayankadamm/cve-2023-34233_proof_of_concept

Proof-of-concept demonstrating CVE-2025-24793 SQL injection vulnerability in Snowflake Connector for Python, with auto-detection of patched/unpatched…

cloud-securitydatabase-securityeducation+3
1 year ago
CVE-2023-3128 preview

CVE-2023-3128

GitHubspyata123/cve-2023-3128

Python script to detect CVE-2023-3128 authentication bypass in Grafana via Azure AD email claim validation. Checks Azure AD SSO configuration and…

authentication-authorizationcloud-securityexploitation+3
1 year ago
atomic-operator preview
Archived

atomic-operator

GitHubswimlane/atomic-operator

A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.

cloud-securitydefensive-toolseducation+3
1562 years ago
jumpserver preview

jumpserver

GitHubjumpserver/jumpserver

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH,…

authentication-authorizationcloud-securityconfiguration-auditing+5
31.6k1 day ago
Previous123…15Next