Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
giskard-oss preview

giskard-oss

GitHubgiskard-ai/giskard-oss

🐢 Open-Source Evaluation & Testing library for LLM Agents

adversarial-attackai-securityfuzzing+3
5.8k4 days ago
unleashed-firmware preview

unleashed-firmware

GitHubdarkflippers/unleashed-firmware

Custom firmware for Flipper Zero enabling Sub-GHz radio, NFC/RFID emulation, infrared, and BadUSB attack features for hardware security testing.

embedded-systems-securityfuzzinghardware-hacking+7
22.3k11h 14m ago
cve-2021-21994_POC preview

cve-2021-21994_POC

GitHubmreza-en/cve-2021-21994_poc

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

authenticationexploitationfuzzing+3
1 month ago
dapr preview

dapr

GitHubnccgroup/dapr

Driver Attack Platform for Linux

android-securitybinary-exploitationdebuggers+5
196 years ago
ShiroScan preview

ShiroScan

GitHubianxtianxt/shiroscan

shiro 1.2.47 反序列化

exploitationfuzzingpenetration-testing+3
206 years ago
Venom-JWT preview

Venom-JWT

GitHubz-bool/venom-jwt

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

exploitationfuzzingpassword-cracking+3
2871 year ago
django-xss-example preview

django-xss-example

GitHubprikalel/django-xss-example

This repo reproduce xss attack on django 4.0.1 (see CVE-2022-22818)

educationfuzzingvulnerability-analysis+2
33 years ago
CVE-2025-5548 preview

CVE-2025-5548

GitHubmk017-hk/cve-2025-5548

Security research and technical analysis of CVE-2025-5548, a buffer overflow vulnerability affecting FreeFloat FTP Server 1.0. This repository…

binary-exploitationeducationexploitation+3
24 months ago
nextjs-cve-2026-44578 preview

nextjs-cve-2026-44578

GitHublove07oj/nextjs-cve-2026-44578

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and…

cloud-securityexploitationfuzzing+3
84 months ago
CVE-2020-25478--ASUS-RT-AC87U-TFTP-is-vulnerable-to-Denial-of-Service-DoS-attack preview

CVE-2020-25478--ASUS-RT-AC87U-TFTP-is-vulnerable-to-Denial-of-Service-DoS-attack

GitHubsantokum/cve-2020-25478--asus-rt-ac87u-tftp-is-vulnerable-to-denial-of-service-dos-attack

ASUS RT-AC87U TFTP is vulnerable to Denial of Service(DoS) attack

exploitationfuzzinghardware-iot-security+1
4 years ago
payloads preview

payloads

GitHubfoospidy/payloads

Git All the Payloads! A collection of web attack payloads.

ctfcurated-resourceseducation+6
4.0k5 years ago
ESP32-DIV preview

ESP32-DIV

GitHubcifertech/esp32-div

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

bluetooth-securityeducationembedded-systems-security+8
4.1k23 days ago
CVE-2024-38475 preview

CVE-2024-38475

GitHubsyaifulandy/cve-2024-38475

CVE-2024-38475 Scanner using FFUF + Seclists

fuzzingpenetration-testingreconnaissance+2
1 year ago
Fault-Injection-Finder preview

Fault-Injection-Finder

GitHubgeeoon/fault-injection-finder

Automatically find and execute fault injection attacks

binary-analysisembedded-systems-securityexploitation+5
1424 days ago
CVE-2022-29072 preview

CVE-2022-29072

GitHubkagancapar/cve-2022-29072

7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents…

binary-exploitationcommand-and-controlexploitation+5
6714 years ago
CVE-2024-5124 preview

CVE-2024-5124

GitHubgogo2464/cve-2024-5124

Exploit for CVE-2024-5124 targeting ChuanhuChatGPT via TLS timing side-channel attack. Uses tlsfuzzer to perform character-by-character credential…

cryptographyexploitationfuzzing+3
11 year ago
CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC preview

CVE-2024-38475_SonicBoom_Apache_URL_Traversal_PoC

GitHubabrewer251/cve-2024-38475_sonicboom_apache_url_traversal_poc

Proof-of-concept scanner for CVE-2024-38475 (SonicBoom) Apache URL traversal. Automates TLS negotiation, directory scanning, traversal verification,…

exploitationfuzzingpenetration-testing+3
1 year ago
BurpAPISecuritySuite preview

BurpAPISecuritySuite

GitHubteycir/burpapisecuritysuite

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

api-securityapi-security-testingfuzzing+4
3401 month ago
Previous123Next