Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
246 results
bugbounty-arsenal-resources preview

bugbounty-arsenal-resources

GitHubfoxvr-sudo/bugbounty-arsenal-resources

Checklists and templates for bug bounty programs. MIT licensed.

curated-resourceseducationfuzzing+6
4 months ago
ReconHound preview

ReconHound

GitLabs_r_e_e_r_a_j/reconhound

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

fuzzinginformation-gatheringpenetration-testing+3
15 months ago
CVE-2025-59843-CVE-2025-59932 preview

CVE-2025-59843-CVE-2025-59932

GitHubat0mxploit/cve-2025-59843-cve-2025-59932

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

api-securityinformation-gatheringmisconfiguration+3
11 year ago
CVE-2021-45232 preview

CVE-2021-45232

GitHubyggcwhat/cve-2021-45232

Batch vulnerability scanner that integrates FOFA to discover and test Apache APISIX Dashboard instances for CVE-2021-45232 unauthorized access.

api-securityexploitationinformation-gathering+2
14 years ago
CVE-2024-46635 preview

CVE-2024-46635

GitHubh1thub/cve-2024-46635

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

api-securityinformation-gatheringmisconfiguration+3
11 year ago
CVE-2022-1598 preview

CVE-2022-1598

GitHubv35hr4j/cve-2022-1598

WPQA < 5.5 - Unauthenticated Private Message Disclosure

api-securityexploitationinformation-gathering+3
14 years ago
CVE-2025-44823 preview

CVE-2025-44823

GitHubskraft9/cve-2025-44823

Authenticated API Key Exposure in Nagios Log Server 2024R1.3.1

api-securityauthenticationexploitation+3
10 months ago
CVE-2025-51869 preview

CVE-2025-51869

GitHubsecsys-fdu/cve-2025-51869

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Liner's chat component, allowing attackers to tamper with other users'…

api-securityinformation-gatheringpenetration-testing+3
11 year ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Appspec YML and YAML leaks

api-securitycloud-securityinformation-gathering+4
12 years ago
Olyx preview

Olyx

GitLabshacode/olyx

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…

android-securityapi-securitydns-analysis+7
8 months ago
CVE-2025-29557 preview

CVE-2025-29557

GitHub0xsu3ks/cve-2025-29557

Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…

api-securityeducationexploitation+3
1 year ago
CVE-2025-54554 preview

CVE-2025-54554

GitHubaman-parmar/cve-2025-54554

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

api-securityinformation-gatheringmisconfiguration+2
1 year ago
CVE-2022-45354 preview

CVE-2022-45354

GitHubrandomrobbiebf/cve-2022-45354

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

api-securityexploitationinformation-gathering+3
3 years ago
aaLogger preview

aaLogger

GitHubusscltd/aalogger

CVE-2017-9627 CVE-2017-9629 CVE-2017-9631

binary-analysisexploitationfuzzing+3
5 years ago
insect preview

insect

GitHubnu11secur1ty/insect

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

fuzzinginformation-gatheringpenetration-testing+3
3 years ago
CVE-2019-19012 preview

CVE-2019-19012

GitHubtarantula-team/cve-2019-19012

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read

binary-analysisexploitationfuzzing+3
6 years ago
CVE-2018-16890 preview

CVE-2018-16890

GitHubmichelleamesquita/cve-2018-16890

CVE-2018-16890

exploitationfuzzinginformation-gathering+2
4 years ago
endsfuzzer preview

endsfuzzer

GitHubameenalkerdy/endsfuzzer

Fuzz a list of domains for specific endpoints

fuzzinginformation-gatheringweb-security
3 years ago
Previous1…121314Next