Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
205 results
CVE-2020-2733 preview

CVE-2020-2733

GitHubanmolksachan/cve-2020-2733

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

encryption-decryption-toolsexploitationinformation-gathering+5
1
2 years ago
CVE-2024-46635 preview

CVE-2024-46635

GitHubh1thub/cve-2024-46635

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

api-securityinformation-gatheringmisconfiguration+3
12 years ago
cloudpanel-2.4.2-CVE-2024-44765-recovery preview

cloudpanel-2.4.2-CVE-2024-44765-recovery

GitHubjosephgodwinkimani/cloudpanel-2.4.2-cve-2024-44765-recovery

How to "recover" a CloudPanel server affected by the CVE-2024-44765 vulnerability

cloud-securityincident-responsemisconfiguration+3
11 year ago
dns-zone-audit preview

dns-zone-audit

GitHubsleepthegod/dns-zone-audit

This Bash script checks domains for DNS zone transfer misconfigurations (CVE-1999-0532). It queries name servers and attempts AXFR requests; if…

dns-analysisinformation-gatheringmisconfiguration+3
16 months ago
behat-config-leaks preview

behat-config-leaks

GitHubcappricio-securities/behat-config-leaks

BeHat Configuration file leaking

information-gatheringmisconfigurationsecret-detection+3
12 years ago
appspec-yaml-leaks preview

appspec-yaml-leaks

GitHubcappricio-securities/appspec-yaml-leaks

Appspec YML and YAML leaks

api-securitycloud-securityinformation-gathering+4
12 years ago
phpinfo-files-leaks preview

phpinfo-files-leaks

GitHubcappricio-securities/phpinfo-files-leaks

This tool is used to find php info page

information-gatheringmisconfigurationpenetration-testing+4
12 years ago
CVE-2025-34171 preview

CVE-2025-34171

GitHubeyodav/cve-2025-34171

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

exploitationinformation-gatheringmisconfiguration+3
9 months ago
CVE-2025-14172-Nuclei-Template preview

CVE-2025-14172-Nuclei-Template

GitHubrootharpy/cve-2025-14172-nuclei-template

The WP Page Permalink Extension plugin (<= 1.5.4) allows authenticated users with insufficient privileges to trigger the AJAX action…

exploitationinformation-gatheringmisconfiguration+3
8 months ago
CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026 preview

CYBERDUDEBIVASH-MONGODB-DETECTOR-v2026

GitHub14mb1v45h/cyberdudebivash-mongodb-detector-v2026

Detect exposed MongoDB instances and CVE-2025-14847 "MongoBleed" risks — Zero-Trust Python scanner

database-securityexploitationinformation-gathering+3
9 months ago
CVE-2025-12721 preview

CVE-2025-12721

GitHubd0n601/cve-2025-12721

g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure

exploitationinformation-gatheringmisconfiguration+3
10 months ago
CVE-2025-67160 preview

CVE-2025-67160

GitHubremenis/cve-2025-67160

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

exploitationinformation-gatheringiot-security+3
8 months ago
Trinity-Audio-CVE-Report preview

Trinity-Audio-CVE-Report

GitHubmooseloveti/trinity-audio-cve-report

Disclosure for CVE-2025-9196

exploitationinformation-gatheringmisconfiguration+3
9 months ago
CVE-H3C-Report preview

CVE-H3C-Report

GitHubkuangxiaotu/cve-h3c-report

PoC exploit for CVE-2023-5142 targeting H3C GR series routers with an unauthenticated directory traversal vulnerability to extract sensitive…

exploitationinformation-gatheringmisconfiguration+2
3 years ago
context-aware-offensive-intelligence preview

context-aware-offensive-intelligence

GitHubindoushka/context-aware-offensive-intelligence

Research framework redefining post-exploitation through decision intelligence.

configuration-auditinginformation-gatheringmisconfiguration+4
8 months ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubamnnrth/cve-2025-14847

This script is used to identify MongoDB services that are network-exposed and allow unauthenticated protocol handshakes.

database-securityinformation-gatheringmisconfiguration+3
8 months ago
printix-CVE-2022-30006 preview

printix-CVE-2022-30006

GitHubcomparedarray/printix-cve-2022-30006

[Reserved for CVE-2022-30006]

exploitationinformation-gatheringmisconfiguration+3
4 years ago
CVE-2023-45184 preview

CVE-2023-45184

GitHubafine-com/cve-2023-45184

IBM i Access Client Solution < 1.1.9.4 - Local server broken access control.

authenticationexploitationinformation-gathering+3
2 years ago
Previous1…8910…12Next