Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
CVE-2026-42897 preview

CVE-2026-42897

GitHubatiilla/cve-2026-42897

CVE-2026-42897 - Exchange Health Checker blind spot: outbound IIS URL Rewrite rules silently ignored, making EOMT mitigations invisible in diagnostic…

cloud-infrastructure-securityconfiguration-auditingeducation+3
54 months ago
Facad1ng preview

Facad1ng

GitHubspyboy-productions/facad1ng

Open-source URL masking & analysis tool for security research, phishing awareness, and defensive testing. Demonstrates adversary techniques used to…

defensive-toolseducationphishing+3
5299 months ago
POC-CVE-2025-55182 preview

POC-CVE-2025-55182

GitHubiamblacksolo2-bugbounty/poc-cve-2025-55182

Bash-based scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

educationexploitationpenetration-testing+3
10 months ago
maskphish preview

maskphish

GitHubjaykali/maskphish

Introducing "URL Making Technology" to the world for the very FIRST TIME. Give a Mask to Phishing URL like a PRO.. A MUST have tool for Phishing.

educationphishingsocial-engineering
3.2k1 year ago
browser-crash-tool preview

browser-crash-tool

GitHublyonzon2/browser-crash-tool

Automated browser crash tool exploiting CVE-2020-27950 (iOS WebKit) via Metasploit and ngrok. Generates public malicious URL for controlled…

command-and-controleducationexploitation+4
51 year ago
CVE-2025-11833-PoC preview

CVE-2025-11833-PoC

GitHubbocgoinfosec/cve-2025-11833-poc

Proof-of-concept checker for CVE-2025-11833, allowing security researchers to test vulnerable web applications with configurable credentials and loot…

educationexploitationpenetration-testing+2
10 months ago
CVE-2025-30208 preview

CVE-2025-30208

GitHub0xshaheen/cve-2025-30208

Scanner for CVE-2025-30208 in Vite Dev Server, supporting single and mass URL scanning with multiple payloads, multi-threading, and vulnerable URL…

educationexploitationpenetration-testing+3
1 year ago
URL_CHECKER preview

URL_CHECKER

GitHubmannansainicyber/url_checker

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

api-security-testingeducationmachine-learning+3
16 months ago
lxancephisher preview

lxancephisher

GitHublxance-hacker/lxancephisher

Automated phishing simulation tool with 30+ login page templates, URL masking, and multiple tunneling options (Ngrok, Cloudflared, Serveo) for…

educationphishingphishing-tools+1
291 year ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubkento-sec/cve-2024-34102

Go-based exploit for CVE-2024-34102, an XXE vulnerability in Adobe Commerce leading to remote code execution. Supports single and batch URL scanning…

educationexploitationpenetration-testing+2
1 year ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

api-securityauthentication-authorizationcryptography+4
2 months ago
CVE-2026-25604-PoC preview

CVE-2026-25604-PoC

GitHubjohn-jung/cve-2026-25604-poc

A PoC for demonstrating CVE-2026-25604

authentication-authorizationcloud-securityeducation+4
5 months ago
CVE-2017-8809_MediaWiki_RFD preview

CVE-2017-8809_MediaWiki_RFD

GitHubmotikan2010/cve-2017-8809_mediawiki_rfd

CVE-2017-8809 Docker - RFD(Reflected File Download) for MediaWiki

educationexploitationpenetration-testing+2
56 years ago
CVE-2023-49103 preview

CVE-2023-49103

GitHubcreacitysec/cve-2023-49103

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

educationexploitationpenetration-testing+2
302 years ago
CVE-2023-42222 preview

CVE-2023-42222

GitHubitssixtyn3in/cve-2023-42222

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

educationexploitationpapers-research+2
33 years ago
CVE-2023-4294 preview

CVE-2023-4294

GitHubb0marek/cve-2023-4294

Repository for CVE-2023-4294 vulnerability.

educationexploitationpenetration-testing+3
3 years ago
cve-2022-42889-text4shell-docker preview

cve-2022-42889-text4shell-docker

GitHubkarthikuj/cve-2022-42889-text4shell-docker

Dockerized proof-of-concept for CVE-2022-42889 (Text4Shell) with script, DNS, and URL lookup-based RCE payloads for security testing and education.

container-securityeducationexploitation+3
763 years ago
CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept preview

CVE-2025-33053-WebDAV-RCE-PoC-and-C2-Concept

GitHubkra1t0/cve-2025-33053-webdav-rce-poc-and-c2-concept

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

command-and-controleducationexploitation+5
31 year ago
Previous123456Next