Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
Complete-google-dorks preview

Complete-google-dorks

GitHubnu11secur1ty/complete-google-dorks

Curated collection of Google dork queries for advanced search engine reconnaissance, uncovering exposed databases, configuration files, admin panels,…

database-securitydns-subdomain-enumerationexploitation+7
121 year ago
CVE-2025-29306 preview

CVE-2025-29306

GitHubverylazytech/cve-2025-29306

Proof-of-concept exploit for FoxCMS v1.2.5 remote code execution via the index.html component, with FOFA dork for target discovery.

educationexploitationreconnaissance+2
21 year ago
CVE-2024-36840-Exploit preview

CVE-2024-36840-Exploit

GitHubtheexploiters/cve-2024-36840-exploit

Exploit For: CVE-2024-36840: SQL Injection Vulnerability in Boelter Blue System Management (Version 1.3)

exploitationinformation-gatheringpenetration-testing+2
21 year ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubegi08/cve-2024-10914

CVE-2024-10914_Manual testing with burpsuite

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2024-29269 preview

CVE-2024-29269

GitHubchsxthwik/cve-2024-29269

Exploit for CVE-2024-29269 enabling unauthenticated OS command injection on TLR-2005KSH routers, with integrated reconnaissance dork queries for…

educationexploitationreconnaissance+2
11 year ago
RCE_CVE-2024-7954 preview

RCE_CVE-2024-7954

GitHubthecyberguy-17/rce_cve-2024-7954

Exploit for CVE-2024-7954, an unauthenticated remote code execution in SPIP's porte_plume plugin, with a Nuclei template and Shodan dork for…

exploitationinformation-gatheringpenetration-testing+3
51 year ago
CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning preview

CVE-2024-4879-CVE-2024-5217-ServiceNow-RCE-Scanning

GitHubnotspepino/cve-2024-4879-cve-2024-5217-servicenow-rce-scanning

CVE-2024-4879 & CVE-2024-5217 ServiceNow RCE Scanning Using Nuclei & Shodan Dork to find it.

exploitationinformation-gatheringpenetration-testing+3
52 years ago
ATSCAN preview

ATSCAN

GitHubalisamtechnology/atscan

Advanced dork Search & Mass Exploit Scanner

crawlerdns-subdomain-enumerationemail-harvesting+7
1.6k2 years ago
CVE-2024-4956 preview

CVE-2024-4956

GitHubgoatsecurity/cve-2024-4956

CVE-2024-4956 : Nexus Repository Manager 3 poc exploit

exploitationinformation-gatheringpenetration-testing+3
32 years ago
CVE-2024-27198-RCE preview

CVE-2024-27198-RCE

GitHubpasswa11/cve-2024-27198-rce

Exploit for JetBrains TeamCity authentication bypass (CVE-2024-27198/27199) enabling remote code execution. Includes dork queries for asset discovery…

authentication-authorizationexploitationpenetration-testing+3
32 years ago
valhalla preview

valhalla

GitHubgotr00t0day/valhalla

Shodan-powered vulnerability scanner that discovers exposed devices and scans targets for known CVEs and vulnerabilities using dork queries and IP…

exploitationinformation-gatheringreconnaissance+1
1013 years ago
CVE-2023-29808 preview

CVE-2023-29808

GitHubzprototype/cve-2023-29808

Reflected cross-site scripting (XSS) proof-of-concept exploit for CVE-2023-29808 targeting the /index.php?map=overview&findme= endpoint in cmaps…

exploitationpenetration-testingvulnerability-analysis+2
43 years ago
CVE-2023-29809 preview

CVE-2023-29809

GitHubzprototype/cve-2023-29809

Proof-of-concept exploit for CVE-2023-29809: unauthenticated SQL injection in cmaps booking system. Demonstrates time-based blind injection and…

exploitationpenetration-testingvulnerability-analysis+1
13 years ago
CVE-2023-29983 preview

CVE-2023-29983

GitHubzprototype/cve-2023-29983

Proof-of-concept for CVE-2023-29983: stored cross-site scripting via unsanitized token parameter in cmaps auditlog, enabling admin cookie theft.

educationexploitationpenetration-testing+3
3 years ago
CVE-2021-33558 preview

CVE-2021-33558

GitHubanldori/cve-2021-33558

CVE-2021-33558 POC

exploitationinformation-gatheringreconnaissance+2
13 years ago
CVE-2017-9833 preview

CVE-2017-9833

GitHubanldori/cve-2017-9833

CVE-2017-9833 POC

exploitationinformation-gatheringreconnaissance+2
13 years ago
CVE-2022-26138 preview

CVE-2022-26138

GitHubshavchen/cve-2022-26138

Exploit for CVE-2022-26138, a SAML SSO bypass vulnerability in Atlassian products, with a FOFA dork for identifying vulnerable instances.

exploitationinformation-gatheringreconnaissance+2
4 years ago
CVE-2022-22954 preview

CVE-2022-22954

GitHuborwagodfather/cve-2022-22954

Proof-of-concept exploit for CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access via SSTI injection. Includes Shodan…

exploitationinformation-gatheringreconnaissance+2
84 years ago
Previous12Next