Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
log4j-dork-scanner preview

log4j-dork-scanner

GitHubtimborin0/log4j-dork-scanner

A script to search, scrape and scan for Apache Log4j CVE-2021-44228 affected files using Google dorks

crawlerexploitationinformation-gathering+3
4 years ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
314 days ago
Job-Manager-Disclosure preview

Job-Manager-Disclosure

GitHubnotrustedx/job-manager-disclosure

CVE-2015-6668, relacionada con el plugin WP Job Manager para WordPress (versiones ≤ 0.7.25).

crawlereducationexploitation+3
1 year ago
joomla_exploits preview

joomla_exploits

GitHubaramosf/joomla_exploits

Curated collection of validated Joomla exploit artifacts with Docker lab environments. Includes RCE, SQLi, XSS, and privilege escalation scripts…

crawlereducationexploitation+5
11 month ago
CVE-2022-26159-Ametys-Autocompletion-XML preview

CVE-2022-26159-Ametys-Autocompletion-XML

GitHubp0dalirius/cve-2022-26159-ametys-autocompletion-xml

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

crawlerdata-exfiltrationexploitation+3
144 years ago
CVE-2024-38526 preview

CVE-2024-38526

GitHubputget/cve-2024-38526

CVE-2024-38526 - Polyfill Scanner

crawlerinformation-gatheringscripting-automation+3
1 year ago
nuclei-templates preview

nuclei-templates

GitHubprojectdiscovery/nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

code-analysiscrawlercurated-resources+6
12.9k14h 28m ago
WordPressMassExploiter preview

WordPressMassExploiter

GitHubparalelo14/wordpressmassexploiter

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

crawlerexploitationinformation-gathering+3
308 years ago
Wordpress_CVE-2019-9787 preview

Wordpress_CVE-2019-9787

GitHubmatinciel/wordpress_cve-2019-9787

Try to reproduce this issue with Docker

crawlereducationexploitation+3
6 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubhoumanpashaei/cve-2025-29927

This is a CVE-2025-29927 Scanner.

crawlerpenetration-testingreconnaissance+3
51 year ago
poc_monitor preview

poc_monitor

GitHubtnkr/poc_monitor

A short scraper looking for a POC of CVE-2024-49112

crawlerexploitationinformation-gathering+3
141 year ago
Bug-Bounty-Arsenal-v.3 preview

Bug-Bounty-Arsenal-v.3

GitHubfoxvr-sudo/bug-bounty-arsenal-v.3

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

api-security-testingcrawlerdevsecops+8
121 day ago
CVE-2023-2982-POC preview

CVE-2023-2982-POC

GitHubh4k6/cve-2023-2982-poc

WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证

authenticationcrawleremail-harvesting+3
93 years ago
directus-security preview

directus-security

GitHubperufitlife/directus-security

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

api-security-testingcrawlerdevsecops+6
2 months ago
CVE-2024-39722 preview

CVE-2024-39722

GitHubsrcx404/cve-2024-39722

Exploit tool for CVE-2024-39722, a model existence disclosure vulnerability in Ollama. Performs version checks, crawls official model library, and…

crawlerexploitationinformation-gathering+3
1 year ago
cve-2020-11023-scanner preview

cve-2020-11023-scanner

GitHubhoneyb33z/cve-2020-11023-scanner

Static analysis scanner for CVE-2020-11023 XSS vulnerabilities in JavaScript. Detects vulnerable jQuery versions and dangerous DOM manipulation…

code-analysiscrawlerstatic-analysis+3
41 year ago
CVE-2018-20555 preview

CVE-2018-20555

GitHubfs0c131y/cve-2018-20555

Exploit for CVE-2018-20555: automated discovery and takeover of Twitter accounts via leaked API keys in vulnerable Social Network Tabs WordPress…

crawlerexploitationinformation-gathering+3
717 years ago
cve-2024-56800-poc preview

cve-2024-56800-poc

GitHubcyhe50/cve-2024-56800-poc

Proof-of-concept exploit demonstrating SSRF vulnerabilities in Firecrawl web scraper (CVE-2024-56800, CVE-2025-57818) with self-hosted setup and…

crawlerexploitationpenetration-testing+3
10 months ago
Previous12Next