Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
bash-apocalypse preview

bash-apocalypse

GitHubmtaha-sec/bash-apocalypse

Recreating Shellshock (CVE-2014-6271) - the bash vulnerability that endangered millions of servers. Automated exploitation toolkit + Burp Suite…

command-and-controleducationexploitation+8
1 month ago
Mongodb-Redis-scan preview

Mongodb-Redis-scan

GitHubianxtianxt/mongodb-redis-scan

mongodb-redis匿名扫描脚本,支持mongodb和redis的匿名扫描

database-securityinformation-gatheringmisconfiguration+3
46 years ago
CVE-2026-32646 preview

CVE-2026-32646

GitHubmichaeladamgroberman/cve-2026-32646

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securityauthenticationcloud-security+6
2 months ago
azuredevops-enum preview

azuredevops-enum

GitHubreverseclabs/azuredevops-enum
api-securitycloud-securityconfiguration-auditing+7
25 months ago
joomla_CVE-2023-23752 preview

joomla_CVE-2023-23752

GitHubvulnmachines/joomla_cve-2023-23752

Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

api-securityexploitationinformation-gathering+3
33 years ago
CVE-2026-13768 preview

CVE-2026-13768

GitHubj4ck3lsyn-gen2/cve-2026-13768

Azure IoT Hub where exposure of an owner-level Shared Access Key enables unauthenticated remote code execution (RCE) against connected IoT devices.…

cloud-securitycommand-and-controleducation+9
11 month ago
starlette-host-header-lab preview

starlette-host-header-lab

GitHubxtremebeing/starlette-host-header-lab

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

authenticationeducationlabs-practice+3
12 months ago
zeroheight-account-verification-bypass-CVE-2025-65925 preview

zeroheight-account-verification-bypass-CVE-2025-65925

GitHubsneden/zeroheight-account-verification-bypass-cve-2025-65925

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

authentication-authorizationexploitationmisconfiguration+3
27 months ago
CVE-2026-31156 preview

CVE-2026-31156

GitHubunicorn-hyh/cve-2026-31156

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

code-analysisexploitationinformation-gathering+3
3 months ago
cloudpanel-2.4.2-CVE-2024-44765-recovery preview

cloudpanel-2.4.2-CVE-2024-44765-recovery

GitHubjosephgodwinkimani/cloudpanel-2.4.2-cve-2024-44765-recovery

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

cloud-securityincident-responsemisconfiguration+3
11 year ago
CVE-2025-59843-CVE-2025-59932 preview

CVE-2025-59843-CVE-2025-59932

GitHubat0mxploit/cve-2025-59843-cve-2025-59932

CVE on FlagForge on versions 2.0.0 to 2.3.0. Upgrade to version 2.3.1 to fix the issue.

api-securityinformation-gatheringmisconfiguration+3
110 months ago
CVE-2024-46635 preview

CVE-2024-46635

GitHubh1thub/cve-2024-46635
api-securityinformation-gatheringmisconfiguration+3
11 year ago
CVE-2025-54554 preview

CVE-2025-54554

GitHubaman-parmar/cve-2025-54554

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

api-securityinformation-gatheringmisconfiguration+2
1 year ago
CVE-2023-45184 preview

CVE-2023-45184

GitHubafine-com/cve-2023-45184

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.

authenticationexploitationinformation-gathering+3
2 years ago
redis-checker preview

redis-checker

GitHubrandomrobbiebf/redis-checker

Checks for exposed Redis servers

database-securityinformation-gatheringmisconfiguration+3
3 years ago
CVE-2025-29705 preview

CVE-2025-29705

GitHubyxzrw/cve-2025-29705

CVE-2025-29705

database-securityinformation-gatheringmisconfiguration+2
1 year ago
sentrymcp preview

sentrymcp

GitHubzaydmulani09/sentrymcp

A static + runtime security scanner for MCP (Model Context Protocol) servers

ai-securityapi-securitymisconfiguration+3
2 days ago
CVE-2020-27368 preview
Archived

CVE-2020-27368

GitHubswzhouu/cve-2020-27368

TOTOLINK-A702R-V1.0.0-B20161227.1023 Directory Indexing Vulnerability

embedded-systems-securityinformation-gatheringiot-security+3
13 years ago
Previous1…456…13Next