Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1762 results
static-analysis preview

static-analysis

GitHubanalysis-tools-dev/static-analysis

Curated directory of static analysis (SAST) tools and linters for programming languages, configs, build tools, and CI, focused on improving code…

code-analysiscurated-resourcesdevsecops+5
14.8k
18h 30m ago
logrus-dos-poc preview

logrus-dos-poc

GitHubmjuanxd/logrus-dos-poc

CVE-2025-65637: Logrus Denial of Service Vulnerability

code-analysiseducationexploitation+2
29 months ago
React2Shell-CVE-2025-55182-Detector preview

React2Shell-CVE-2025-55182-Detector

GitHubgarethmsheldon/react2shell-cve-2025-55182-detector

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

code-analysisscripting-automationsupply-chain-security+3
18 months ago
CVE-2026-29786 preview

CVE-2026-29786

GitHubjvr2022/cve-2026-29786

Proof-of-concept demonstrating a hardlink path traversal in the tar npm package, allowing overwrite of files outside the extraction directory via…

code-analysisexploitationsupply-chain-security+2
16 months ago
CVE-2023-26563-26564-26565 preview

CVE-2023-26563-26564-26565

GitHubrupturainfosec/cve-2023-26563-26564-26565

Proof-of-concept exploits for three vulnerabilities in Syncfusion file managers: directory traversal leading to arbitrary file read/write/delete, and…

code-analysisdatabase-securityexploitation+3
1 year ago
wwwgrep preview
Archived

wwwgrep

GitHubowasp/wwwgrep

OWASP Foundation Web Respository

code-analysisinformation-gatheringpenetration-testing+3
365 years ago
Awesome-LLMs-for-Vulnerability-Detection preview

Awesome-LLMs-for-Vulnerability-Detection

GitHubhuhusmang/awesome-llms-for-vulnerability-detection

The community's most comprehensive, continuously-updated index of research on Large Language Models for software vulnerability detection — papers…

ai-securitycode-analysiscurated-resources+4
1.4k2 days ago
sudowp-crowdsignal-forms preview

sudowp-crowdsignal-forms

GitHubsudo-wp/sudowp-crowdsignal-forms

A security-hardened fork of Crowdsignal Forms. Patches CVE-2025-69015 (Broken Access Control), modernizes for PHP 8.2+, and enforces strict…

api-securityauthentication-authorizationcode-analysis+3
5 months ago
CVE-2025-56815 preview

CVE-2025-56815

GitHubxiaoxiaoranxxx/cve-2025-56815

Datart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transferTo() to…

code-analysisexploitationmisconfiguration+3
511 months ago
MakerChecker preview

MakerChecker

GitHubmakerchecker/makerchecker

Open-source security gateway & static scanner for AI agents. Enforce role-based access control (RBAC), human-in-the-loop approvals, segregation of…

ai-securityauthentication-authorizationcloud-security+7
522 months ago
sudowp-clickfunnels-zurich preview

sudowp-clickfunnels-zurich

GitHubsudo-wp/sudowp-clickfunnels-zurich

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

api-securityauthentication-authorizationcode-analysis+3
15 months ago
heartwood preview

heartwood

GitHubradicle-dev/heartwood

Peer-to-peer code collaboration and publishing stack with a secure, decentralized protocol, CLI tool, and network daemon for sovereign code forges.

authentication-authorizationcode-analysisnetwork-security+2
2651 month ago
CVE-2024-47051 preview

CVE-2024-47051

GitHubmallo-m/cve-2024-47051

Mautic < 5.2.3 Authenticated RCE

code-analysisexploitationpayload-development+3
51 year ago
cve-2026-47777 preview

cve-2026-47777

GitHubbekwiner/cve-2026-47777

Detailed technical analysis of CVE-2026-47777, a high-severity authorization bypass in Mastodon's Featured Collections federation pipeline, including…

authentication-authorizationcode-analysispenetration-testing+3
11 month ago
sudowp-postgallery preview

sudowp-postgallery

GitHubsudo-wp/sudowp-postgallery

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

authentication-authorizationcode-analysisconfiguration-auditing+3
15 months ago
CVE-2026-66917 preview

CVE-2026-66917

GitHubtoanln-cov/cve-2026-66917

IDOR + Stored XSS via Broken Object-Level Authorization in JoomGallery

authentication-authorizationcode-analysisexploitation+3
16 days ago
nuclei-templates preview

nuclei-templates

GitHubprojectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

code-analysiscrawlercurated-resources+6
12.9k8h 13m ago
CVE-2025-55182-POC-NEXTJS preview

CVE-2025-55182-POC-NEXTJS

GitHubaliclub0x00/cve-2025-55182-poc-nextjs

Working proof of concept for NextJS RCE to establish a reverse shell. [React2Shell]

code-analysisdynamic-analysis-sandboxingexploitation+5
279 months ago
Previous12…98Next