Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
haptyc preview

haptyc

GitHubdefparam/haptyc

Python library for Turbo Intruder that adds payload position support and Sniper/Clusterbomb/Pitchfork attack types with tag-based test generation for…

fuzzingpayload-generationpenetration-testing+1
93
4 years ago
crlfmap preview

crlfmap

GitHubryandamour/crlfmap

CRLFMap is a tool to find HTTP Splitting vulnerabilities

fuzzingids-ips-evasionpenetration-testing+3
325 years ago
crlfmap preview

crlfmap

GitHubethicalhackingplayground/crlfmap

CRLFMap is a tool to find HTTP Splitting vulnerabilities

fuzzingvulnerability-scannersweb-security
256 years ago
CVE-2022-22274_CVE-2023-0656 preview

CVE-2022-22274_CVE-2023-0656

GitHubbishopfox/cve-2022-22274_cve-2023-0656

Proof-of-concept exploit for SonicWall SonicOS stack-based buffer overflows (CVE-2022-22274, CVE-2023-0656) that tests and triggers crashes via…

exploitationfuzzingpenetration-testing+3
192 years ago
CVE-2023-38545-libcurl-SOCKS5-heap-buffer-overflow preview

CVE-2023-38545-libcurl-SOCKS5-heap-buffer-overflow

GitHubfatmo666/cve-2023-38545-libcurl-socks5-heap-buffer-overflow

Proof-of-concept exploit for CVE-2023-38545, a heap buffer overflow in libcurl's SOCKS5 proxy handshake triggered via a malicious HTTP 301 redirect…

binary-exploitationexploitationfuzzing+2
62 years ago
CVE-2022-29593 preview

CVE-2022-29593

GitHub9lyph/cve-2022-29593

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

authenticationexploitationfuzzing+8
81 year ago
CVE-2026-23918-test preview

CVE-2026-23918-test

GitHub12lie20/cve-2026-23918-test

This repository contains a Proof of Concept (PoC) demonstrating the Double Free vulnerability (CVE-2026-23918) in Apache HTTP Server 2.4.66…

binary-exploitationexploitationfuzzing+3
44 months ago
crlfi-scanner preview

crlfi-scanner

GitHubcappricio-securities/crlfi-scanner

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

fuzzingpenetration-testingweb-application-exploitation+2
46 months ago
CVE-2020-13768 preview

CVE-2020-13768

GitHubthemalwareguardian/cve-2020-13768

Stack-based buffer overflow in MiniShare 1.4.1 reachable through a single HTTP PUT request.

binary-exploitationdebuggerseducation+7
5 months ago
CVE-2002-1120 preview

CVE-2002-1120

GitHubthemalwareguardian/cve-2002-1120

Classic stack-based buffer overflow in Savant Web Server 3.1 demonstrating early-2000s remote memory corruption through a crafted HTTP request.

binary-exploitationdebuggerseducation+8
15 months ago
CVE-2023-26976_tenda_AC6_stack_overflow preview

CVE-2023-26976_tenda_AC6_stack_overflow

GitHubfzbacon/cve-2023-26976_tenda_ac6_stack_overflow

Proof-of-concept exploit for CVE-2023-26976, a stack overflow vulnerability in Tenda AC6 routers, enabling remote code execution via crafted HTTP…

binary-exploitationembedded-systems-securityexploitation+3
12 years ago
CVE-2023-38545 preview

CVE-2023-38545

GitHubyang-shun-yu/cve-2023-38545

Proof-of-concept exploit for CVE-2023-38545, a curl heap buffer overflow. Includes SOCKS5 proxy and HTTP server to trigger the vulnerability and…

exploitationfuzzingnetwork-security+3
2 years ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
954 days ago
CVE-2025-60876 preview
Archived

CVE-2025-60876

GitHubsirredbeard/cve-2025-60876

Behavior-preserving fix for CVE-2025-60876 HTTP header injection in BusyBox wget, with proof-of-concept, percent-encoding patch, and upstream…

exploitationfuzzingpenetration-testing+3
3 months ago
Blisqy preview

Blisqy

GitHubjohntroony/blisqy

Version 0.2 - Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).

database-securityexploitationfuzzing+2
4167 years ago
cotopaxi preview

cotopaxi

GitHubsamsung/cotopaxi

Set of tools for security testing of Internet of Things devices using specific network IoT protocols

fuzzingiot-securitynetwork-security+2
3625 years ago
t-reqs preview

t-reqs

GitHubbahruzjabiyev/t-reqs

Grammar-based HTTP/1 fuzzer with mutation ability

fuzzingpapers-researchvulnerability-analysis+1
2641 year ago
CVE-2025-55315-repro preview

CVE-2025-55315-repro

GitHubsirredbeard/cve-2025-55315-repro

Tool that reproduces CVE-2025-55315 in ASP.NET Core.

exploitationfuzzingpenetration-testing+2
468 months ago
Previous123Next