Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
17 results
CVE-2023-23752 preview

CVE-2023-23752

GitHub0xwhoami35/cve-2023-23752

Authentication bypass exploit for Joomla CVE-2023-23752 that leaks administrator credentials and MySQL configuration from vulnerable versions…

authenticationexploitationinformation-gathering+3
3
1 year ago
fapro preview

fapro

GitHubfofapro/fapro

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…

defensive-toolsfingerprint-spoofinginformation-gathering+3
1.6k1 year ago
exploits preview

exploits

GitHub0xdea/exploits

Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel,…

binary-exploitationdatabase-securityexploitation+3
6759 months ago
enumdb preview

enumdb

GitHubm8sec/enumdb

Relational database brute force and post exploitation tool for MySQL and MSSQL

database-securityinformation-gatheringpassword-attacks+2
2212 years ago
chameleon preview

chameleon

GitHubqeeqbox/chameleon

19 Customizable honeypots for monitoring network traffic, bots activities and username\password credentials (DNS, HTTP Proxy, HTTP, HTTPS, SSH, POP3,…

defensive-toolsinformation-gatheringnetwork-security+1
8433 years ago
brutus preview

brutus

GitHubpraetorian-inc/brutus

Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative…

authenticationexploitationinformation-gathering+7
3274 days ago
EnvVisualizer preview

EnvVisualizer

GitHubw4r10ck423/envvisualizer

Parse and visualize /proc/self/environ on compromised Linux boxes — categorizes env vars by tech stack (AWS, Django, Rails, NodeJS, MySQL, K8s,…

cloud-securityconfiguration-auditingctf+7
14 months ago
CVE-2021-41651 preview

CVE-2021-41651

GitHubmobiusbinary/cve-2021-41651

Proof-of-concept exploit for CVE-2021-41651, demonstrating unauthenticated time-based blind SQL injection in hotel-mgmt-system via the cid parameter,…

exploitationinformation-gatheringpenetration-testing+2
5 years ago
informer preview

informer

GitHubpaulpierre/informer

A Telegram Mass Surveillance Bot in Python

crawlerdata-exfiltrationimpersonation-tools+3
1.7k11 months ago
hekate preview

hekate

GitHubsourceincite/hekate

Exploit for VMWare Workspace ONE Access chaining five CVEs for unauthenticated remote code execution via JDBC injection and privilege escalation.

authentication-authorizationexploitationinformation-gathering+5
484 years ago
MysqlHoneypot preview

MysqlHoneypot

GitHubal1ex/mysqlhoneypot

MysqlHoneypot

defensive-toolsinformation-gatheringintrusion-detection+2
244 years ago
DBScanner preview

DBScanner

GitHubianxtianxt/dbscanner

未授权访问+弱口令批量检测

database-securityinformation-gatheringmisconfiguration+3
56 years ago
CVE-2026-37149 preview

CVE-2026-37149

GitHubpateldhyeyit/cve-2026-37149

CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in…

database-securityeducationinformation-gathering+3
23 months ago
CVE-2024-8949-POC preview

CVE-2024-8949-POC

GitHubgh-ost00/cve-2024-8949-poc

SourceCodester Online Eyewear Shop Remote File Inclusion Vulnerability

information-gatheringpenetration-testingvulnerability-analysis+2
22 years ago
CVE-2024-32640 preview

CVE-2024-32640

GitHubpizza-power/cve-2024-32640

Python POC for CVE-2024-32640 Mura CMS SQLi

exploitationinformation-gatheringpenetration-testing+2
11 year ago
CVE-2026-7071-access-Control preview

CVE-2026-7071-access-Control

GitHubxmyronn/cve-2026-7071-access-control

Proof of concept demonstrating unauthenticated access to user resumes via directory listing in CodeAstro Online Job Portal, with reproduction steps…

exploitationinformation-gatheringpenetration-testing+2
6 months ago
CVE-2024-55099-Online-Nurse-Hiring-System-v1.0-SQL-Injection-Vulnerability- preview
Archived

CVE-2024-55099-Online-Nurse-Hiring-System-v1.0-SQL-Injection-Vulnerability-

GitHubugurkarakoc1/cve-2024-55099-online-nurse-hiring-system-v1.0-sql-injection-vulnerability-

Proof-of-concept exploit for CVE-2024-55099, demonstrating SQL injection in the Online Nurse Hiring System v1.0 via unsanitized username parameter,…

exploitationinformation-gatheringpenetration-testing+2
11 year ago