Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
138 results
CVE-2026-80467 preview

CVE-2026-80467

GitHubsangsenimanwartefak/cve-2026-80467

Python detection tool that fingerprints ACF Extended forms on WordPress and checks for publicly exposed role fields indicating CVE-2026-80467…

educationpenetration-testingprivilege-escalation+4
15 days ago
hdwebmobile-booking-appointments preview

hdwebmobile-booking-appointments

GitHubhtrxuan/hdwebmobile-booking-appointments

Sell bookable services and appointments through WooCommerce -- closes CVE-2026-2931 by construction.

authentication-authorizationcurated-resourceseducation+2
19 days ago
Aether preview

Aether

GitHubfknmega/aether

AI-driven OSINT and security research agent that builds a live knowledge graph from public data, with bundled recon tools and offensive-security…

ai-securityctfcurated-resources+5
17921 days ago
nuclei-cve-analyzer preview

nuclei-cve-analyzer

GitHubsw33ber/nuclei-cve-analyzer

CVE intelligence pipeline that compares public CVEs against Nuclei templates to identify missing vulnerability coverage, classify types, and rank…

curated-resourceseducationthreat-intelligence+2
1 month ago
chrome-vuln-scanner preview

chrome-vuln-scanner

GitHubvirologi-info/chrome-vuln-scanner

Check for CVE-2026-79266. A use-after-free in the DevTools component allows arbitrary code execution inside the sandbox via a malicious Chrome…

defensive-toolseducationstatic-analysis+2
1 month ago
CVE-2025-4123-Exploit preview

CVE-2025-4123-Exploit

GitHubmorphykutay/cve-2025-4123-exploit

Proof-of-concept tool that sends a crafted payload to a target and detects open redirect vulnerabilities by inspecting 301/302 responses and Location…

educationexploitationvulnerability-analysis+1
11 months ago
CVE-2026-24061-Scanner preview

CVE-2026-24061-Scanner

GitHubxsanflip/cve-2026-24061-scanner

Bash-based scanner for CVE-2026-24061 that performs subnet reconnaissance, banner grabbing, and active exploitation checks against GNU Inetutils…

educationexploitationnetwork-security+4
8 months ago
SharpExchange preview

SharpExchange

GitHubceramicskate0/sharpexchange

C# Tool to interact with MS Exchange based on MS docs

data-exfiltrationeducationinformation-gathering+4
1023 years ago
react preview

react

GitHubjanhalendk/react

A OSINT project that explores how to dump data from React

educationinformation-gatheringosint+2
821 year ago
Kangaroo preview

Kangaroo

GitHubmonkeysec-sys/kangaroo

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

authentication-authorizationeducationexploitation+3
22 months ago
ysoserial preview

ysoserial

GitHubal1ex/ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization

educationexploitationpayload-generation+3
21 year ago
BLEBoy preview

BLEBoy

GitHubnccgroup/bleboy

BLEBoy is a training tool to teach users about BLE security by providing a single BLE peripheral that can be used to experiment with each BLE pairing…

bluetooth-securityeducationembedded-systems-security+3
496 years ago
shining-mask preview

shining-mask

GitHubbishopfox/shining-mask

BLE-based tool that automatically discovers and exploits Shining LED Masks by uploading a custom image without user interaction, proving security…

bluetooth-securityeducationembedded-systems-security+5
1311 months ago
CVE-2021-21983 preview

CVE-2021-21983

GitHubmurataydemir/cve-2021-21983

[CVE-2021-21983] VMware vRealize Operations (vROps) Manager API Arbitrary File Write Leads to Remote Code Execution (RCE)

educationexploitationpayload-development+2
34 years ago
ReplicatedRandom preview

ReplicatedRandom

GitHubfta2012/replicatedrandom

Java Random state replication tool that predicts future random values by recovering internal state from observed outputs, demonstrating weaknesses in…

cryptographyeducationexploitation
1209 years ago
zip_bomb preview

zip_bomb

GitHubjenderal92/zip_bomb

ZIP Bomb Creator is a tool used to create a ZIP file that is small in size but drastically expands when extracted.

educationexploitationpayload-generation+2
34 months ago
CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat- preview

CVE-2026-66750-Insufficient-Access-Controls-Allow-for-Unauthorized-File-Downloads-Let-s-Chat-

GitHubtheopaid/cve-2026-66750-insufficient-access-controls-allow-for-unauthorized-file-downloads-let-s-chat-

Security Advisory: Insufficient Access Controls Allow for Unauthorized File Downloads (Let's Chat)

authentication-authorizationeducationmisconfiguration+2
2 months ago
CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation preview

CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

GitHubninjazan420/cve-2026-1529-poc-keycloak-unauthorized-registration-via-improper-invitation-token-validation

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

authentication-authorizationeducationexploitation+4
17 months ago
Previous12…8Next