Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
141 results
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

api-securityapi-security-testingdynamic-code-analysis+14
5.6k
5 days ago
perwendel__spark_CVE-2016-9177_2-5-1 preview

perwendel__spark_CVE-2016-9177_2-5-1

GitHubshoucheng3/perwendel__spark_cve-2016-9177_2-5-1

Exploit for CVE-2016-9177 targeting Spark Java web framework, demonstrating directory traversal vulnerability in version 2.5.1 for security testing…

api-security-testingexploitationpenetration-testing+3
1 year ago
DeliberatelyVulnerableWebApp preview
Archived

DeliberatelyVulnerableWebApp

GitHubtimothyjxhn/deliberatelyvulnerablewebapp

A Deliberately Vulnerable Web Application built on Struts 2 (CVE-2017-5638) and Log4J (CVE-2021-44228) for testing and demonstration of OWASP Top 10…

educationexploitationlabs-practice+3
1 year ago
Spring4Shell preview

Spring4Shell

GitHubloneyers/spring4shell

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

api-security-testingexploitationpenetration-testing+3
44 years ago
CVE-2022-23808 preview

CVE-2022-23808

GitHubdipakpanchal05/cve-2022-23808

Proof-of-concept exploit for CVE-2022-23808, a stored XSS vulnerability in phpMyAdmin 5.1.1 setup script, with payload and reproduction steps for…

exploitationpenetration-testingred-teaming+3
1151 year ago
Multi-VLAN-Enterprise-Network-Vulnerability-Assessment preview

Multi-VLAN-Enterprise-Network-Vulnerability-Assessment

GitHubklairmanraj/multi-vlan-enterprise-network-vulnerability-assessment

Multi-VLAN enterprise network vulnerability assessment using Nessus, OWASP ZAP, and Wireshark. Confirms Stored XSS on WebGoat and EternalBlue…

exploitationnetwork-mappingnetwork-security+6
5 months ago
CVE-2020-23839 preview

CVE-2020-23839

GitHubboku7/cve-2020-23839

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

exploitationpayload-developmentpenetration-testing+3
125 years ago
CVE-2026-21876 preview

CVE-2026-21876

GitHubmefhika120/cve-2026-21876

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
CVE-2024-11972-POC preview

CVE-2024-11972-POC

GitHubronf98/cve-2024-11972-poc

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

api-security-testingcode-analysisexploitation+3
11 year ago
log4shell-coraza preview

log4shell-coraza

GitHubtieupham267/log4shell-coraza

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.

defensive-toolseducationexploitation+8
5 months ago
vbscan preview
Archived

vbscan

GitHubowasp/vbscan

OWASP VBScan is a Black Box vBulletin Vulnerability Scanner

exploitationinformation-gatheringpenetration-testing+3
3257 years ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
1351 day ago
CVE-2021-4191-EXPLOIT preview

CVE-2021-4191-EXPLOIT

GitHubk3ystr0k3r/cve-2021-4191-exploit

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

api-security-testingexploitationinformation-gathering+3
93 years ago
wp2shell-Exploit-Waf-Bypass preview

wp2shell-Exploit-Waf-Bypass

GitHubm4xsec/wp2shell-exploit-waf-bypass

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

api-security-testingexploitationpenetration-testing+4
51 month ago
ClaimJumper preview

ClaimJumper

GitHubfevra-dev/claimjumper

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

authenticationcryptographyexploitation+6
18 months ago
area51 preview

area51

GitHubthoropass-public/area51

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

api-security-testingcloud-securityemail-security+4
54 days ago
your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack preview

your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

GitHubhunt-benito/your-bot-my-inbox-cve-2026-68929-fastgpt-unauthenticated-wechat-channel-hijack

Proof-of-concept exploit for CVE-2026-68929, demonstrating unauthenticated cross-tenant takeover of FastGPT WeChat channels via public shareId,…

api-security-testingexploitationpenetration-testing+3
29 days ago
CVE-2026-65013-BOLA-IDOR preview

CVE-2026-65013-BOLA-IDOR

GitHubisaca0315/cve-2026-65013-bola-idor

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

api-security-testingauthentication-authorizationeducation+7
13 days ago
Previous12…8Next