Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
CVE-2025-14172-Nuclei-Template preview

CVE-2025-14172-Nuclei-Template

GitHubrootharpy/cve-2025-14172-nuclei-template

The WP Page Permalink Extension plugin (<= 1.5.4) allows authenticated users with insufficient privileges to trigger the AJAX action…

exploitationinformation-gatheringmisconfiguration+3
8 months ago
CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 preview

CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026

GitHub14mb1v45h/cyberdudebivash-mongodb-detector-v2026

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

database-securityexploitationinformation-gathering+3
8 months ago
Trinity-Audio-CVE-Report preview

Trinity-Audio-CVE-Report

GitHubmooseloveti/trinity-audio-cve-report

Disclosure for CVE-2025-9196

exploitationinformation-gatheringmisconfiguration+3
8 months ago
CVE-H3C-Report preview

CVE-H3C-Report

GitHubkuangxiaotu/cve-h3c-report

PoC exploit for CVE-2023-5142 targeting H3C GR series routers with an unauthenticated directory traversal vulnerability to extract sensitive…

exploitationinformation-gatheringmisconfiguration+2
3 years ago
CVE-2023-36643 preview

CVE-2023-36643

GitHubcaffeinated-labs/cve-2023-36643

Proof-of-concept for CVE-2023-36643: an incorrect access control vulnerability in ITB-GmbH TradePro v9.5 that allows remote attackers to enumerate…

information-gatheringmisconfigurationpenetration-testing+2
2 years ago
CVE-2023-45184 preview

CVE-2023-45184

GitHubafine-com/cve-2023-45184

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.

authenticationexploitationinformation-gathering+3
2 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
7 months ago
cgi-printenv preview

cgi-printenv

GitHubcappricio-securities/cgi-printenv

CGI Print ENV leaking

information-gatheringmisconfigurationpenetration-testing+3
2 years ago
CVE-2023-39144 preview

CVE-2023-39144

GitHubcduram/cve-2023-39144

CVE-2023-39144 disclosure: cleartext password exposure in Element55 Maketime appliance admin pages, enabling privilege escalation via…

exploitationinformation-gatheringmisconfiguration+3
3 years ago
CVE-2023-33477 preview

CVE-2023-33477

GitHubskr11lex/cve-2023-33477

Exploit for CVE-2023-33477, an unauthorized configuration file download vulnerability in Harmonic NSG 9000-6G modulator, allowing remote attackers to…

exploitationinformation-gatheringmisconfiguration+2
3 years ago
CVE-2021-42913 preview

CVE-2021-42913

GitHubkernel-cyber/cve-2021-42913

Samsung Printer SCX-6X55X Improper Access Control

exploitationinformation-gatheringmisconfiguration+2
4 years ago
redis-checker preview

redis-checker

GitHubrandomrobbiebf/redis-checker

Checks for exposed Redis servers

database-securityinformation-gatheringmisconfiguration+3
3 years ago
CVE-2023-49979 preview

CVE-2023-49979

GitHubgeraldoalcantara/cve-2023-49979

Best Student Management System v1.0 - Incorrect Access Control - Directory Listing

information-gatheringmisconfigurationpenetration-testing+2
2 years ago
CVE-2021-27187 preview

CVE-2021-27187

GitHubjet-pentest/cve-2021-27187

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

data-exfiltrationexploitationinformation-gathering+3
5 years ago
CVE-2020-25747 preview

CVE-2020-25747

GitHubjet-pentest/cve-2020-25747

Proof-of-concept exploit for CVE-2020-25747 demonstrating unauthenticated remote access to RTSP and ONVIF services on Rubetek RV-3406/3409/3411…

exploitationinformation-gatheringiot-security+2
5 years ago
CVE-2025-29705 preview

CVE-2025-29705

GitHubyxzrw/cve-2025-29705

CVE-2025-29705

database-securityinformation-gatheringmisconfiguration+2
1 year ago
CVE-2020-29666 preview

CVE-2020-29666

GitHubjet-pentest/cve-2020-29666

Proof-of-concept for CVE-2020-29666: directory listing vulnerability in Lan ATMService M3 ATM Monitoring System 6.1.0 that exposes log files…

information-gatheringmisconfigurationreconnaissance+2
5 years ago
CVE-2023-49981 preview

CVE-2023-49981

GitHubgeraldoalcantara/cve-2023-49981

School Fees Management System v1.0 - Incorrect Access Control - Directory Listing

information-gatheringmisconfigurationpenetration-testing+2
2 years ago
Previous1…678Next