Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5850 results
context-aware-offensive-intelligence preview

context-aware-offensive-intelligence

GitHubindoushka/context-aware-offensive-intelligence

Research framework redefining post-exploitation through decision intelligence.

privilege-escalationvulnerability-analysisconfiguration-auditing+4
6 months ago
BloodBash preview

BloodBash

GitHubsquidsec/bloodbash

Offline AD/Entra attack-path analyzer for SharpHound/AzureHound JSON. Surfaces prioritized privilege escalation, credential, and misconfiguration…

privilege-escalationvulnerability-analysislateral-movement+6
4061 day ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

vulnerability-scannersexploitationweb-application-exploitation+3
1 day ago
CVE-2026-53959 preview

CVE-2026-53959

GitHubanirbala98/cve-2026-53959

4gaBoards < 3.3.9 - User Information Disclosure

vulnerability-analysisexploitationweb-application-exploitation+5
11 day ago
CVE-2026-19478 preview

CVE-2026-19478

GitHubrenzi25031469/cve-2026-19478

Detects CVE-2026-19478 in GitLab CE/EE with a non-destructive Nuclei template that triggers the GraphQL fallback-field method invocation via touch…

web-vulnerability-scannersvulnerability-analysisweb-application-exploitation+4
1 day ago
memdumper preview

memdumper

GitHubcenobyte-vincit/memdumper

Abuses macOS debugger entitlements and DYLD_INSERT_LIBRARIES to dump or search a running process's memory while shifting EDR attribution to a signed…

memory-forensicsids-ips-evasioninformation-gathering+4
12 days ago
CVE-2026-19478-PoC preview

CVE-2026-19478-PoC

GitHubdavkharrr/cve-2026-19478-poc

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

vulnerability-analysisexploitationweb-application-exploitation+3
12 days ago
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability preview

CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability

GitHubgraysignal/cve-2024-23897-jenkins-arbitrary-read-file-vulnerability

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

vulnerability-analysisexploitationweb-application-exploitation+4
32 years ago
CVE-2024-24919-Check-Point-Remote-Access-VPN preview

CVE-2024-24919-Check-Point-Remote-Access-VPN

GitHubgraysignal/cve-2024-24919-check-point-remote-access-vpn

Scan for and exploit CVE-2024-24919 in Check Point Security Gateways, an unauthenticated arbitrary file read that can expose credentials and lead to…

vulnerability-scannersexploitationinformation-gathering+2
12 years ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

web-vulnerability-scannersexploitationweb-application-exploitation+4
22 days ago
scambuster preview

scambuster

GitHublaugiov/scambuster

Defensive engagement & threat intelligence research laboratory. Converts inbound scam emails into actionable IOCs through controlled, policy-driven…

defensive-toolsioc-managementinformation-gathering+5
132 days ago
CVE-2026-71203-PoC preview

CVE-2026-71203-PoC

GitHubnel-droid/cve-2026-71203-poc

PoC: changedetection.io unauthenticated OpenAPI schema disclosure (CVE-2026-71203, Medium 5.3)

vulnerability-analysisexploitationapi-security-testing+4
3 days ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubaleewyy/cve-2025-49132

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

vulnerability-analysisexploitationweb-application-exploitation+3
2 months ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubkaiisyms/cve-2025-24071

Microsoft Windows File Explorer Spoofing Vulnerability / NTLM Hash Leak

vulnerability-analysisexploitationinformation-gathering+1
1 year ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubnxploited/cve-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

privilege-escalationweb-vulnerability-scannersexploitation+3
3 days ago
CVE-2026-9830 preview

CVE-2026-9830

GitHubopaxial/cve-2026-9830

Python PoC validating unauthenticated BookingPress Pro REST API exposure and checking for exposed booking/customer data with configurable request…

vulnerability-analysisexploitationweb-application-exploitation+3
1424 days ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsvulnerability-scannersweb-vulnerability-scanners+4
4 days ago
CVE-2017-7921-EXP preview

CVE-2017-7921-EXP

GitHubblacksheepstudio/cve-2017-7921-exp

Python exploit for CVE-2017-7921 in Hikvision IP cameras, performing unauthenticated user enumeration, snapshot capture, and configuration file…

iot-securityvulnerability-analysisexploitation+3
3 years ago
Previous12…325Next