Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
139 results
djangohunter preview

djangohunter

GitHubjimywork/djangohunter

Tool designed to help identify incorrectly configured Django applications that are exposing sensitive information.

information-gatheringmisconfigurationvulnerability-scanners+1
250
7 years ago
DNSint preview

DNSint

GitHubwho0xac/dnsint

DNSint - A comprehensive DNS reconnaissance and OSINT toolkit for domain intelligence gathering and security analysis.

dns-analysisdns-fuzzingemail-security+7
199 months ago
CVE-2022-1077 preview

CVE-2022-1077

GitHubbrosck/cve-2022-1077

TEM FLEX-1080/FLEX-1085 1.6.0 log log.cgi Information Disclosure

exploitationinformation-gatheringiot-security+3
41 year ago
CVE-2023-34965 preview

CVE-2023-34965

GitHubagenty0/cve-2023-34965

SSPanel UIM is a multi-purpose agency service sales management system specially designed for Shadowsocks / V2Ray / Trojan protocols. SSPanel-Uim…

information-gatheringmisconfigurationpenetration-testing+2
33 years ago
CVE-2022-37703 preview

CVE-2022-37703

GitHubmaherazzouzi/cve-2022-37703

Amanda Information Disclosure bug.

exploitationinformation-gatheringmisconfiguration+3
44 years ago
Prommetrix preview

Prommetrix

GitHubepsylon/prommetrix

Prommetrix can obtain relevant information from the instances of 'Node Exporter' executed by 'Prometheus'.

cloud-securityinformation-gatheringmisconfiguration+4
52 years ago
CVE-2021-33558. preview

CVE-2021-33558.

GitHubmdanzaruddin/cve-2021-33558.

Exploit code for CVE-2021-33558 targeting Boa/0.94.13 misconfigurations that expose sensitive information via backup, preview, log, and config files.

exploitationinformation-gatheringmisconfiguration+2
35 years ago
CVE-2020-24029 preview

CVE-2020-24029

GitHubredteambrasil/cve-2020-24029

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

authenticationexploitationinformation-gathering+4
1 month ago
git-scan preview

git-scan

GitHubjenderal92/git-scan

This tool is designed to scan and identify whether a website has an exposed ".git" directory, which may contain sensitive information such as source…

information-gatheringmisconfigurationpenetration-testing+1
13 months ago
CVE-2026-31156 preview

CVE-2026-31156

GitHubunicorn-hyh/cve-2026-31156

There is a path injection vulnerability in OpenPLC-v3, which arises from the program not performing any validity checks on the file path parameters…

code-analysisexploitationinformation-gathering+3
4 months ago
CVE-2024-46635 preview

CVE-2024-46635

GitHubh1thub/cve-2024-46635

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

api-securityinformation-gatheringmisconfiguration+3
11 year ago
CVE-2023-47529 preview

CVE-2023-47529

GitHubrandomrobbiebf/cve-2023-47529

Cloud Templates & Patterns collection <= 1.2.2 - Sensitive Information Exposure via Log File

exploitationinformation-gatheringlog-analysis+3
12 years ago
CVE-2025-34171 preview

CVE-2025-34171

GitHubeyodav/cve-2025-34171

CasaOS expose multiple unauthenticated API endpoints that allow remote disclosure of sensitive configuration files and system debug information

exploitationinformation-gatheringmisconfiguration+3
8 months ago
CVE-2025-12721 preview

CVE-2025-12721

GitHubd0n601/cve-2025-12721

g-FFL Cockpit <= 1.7.1 - Missing Authorization to Unauthenticated Information Exposure

exploitationinformation-gatheringmisconfiguration+3
10 months ago
CVE-2025-67160 preview

CVE-2025-67160

GitHubremenis/cve-2025-67160

Vatilon-based IP cameras expose internal web directories without authentication, leading to information disclosure.

exploitationinformation-gatheringiot-security+3
8 months ago
CVE-2022-1442 preview

CVE-2022-1442

GitHubrandomrobbiebf/cve-2022-1442

WordPress Plugin Metform <= 2.1.3 - Improper Access Control Allowing Unauthenticated Sensitive Information Disclosure

exploitationinformation-gatheringmisconfiguration+3
3 years ago
CVE-2025-54554 preview

CVE-2025-54554

GitHubaman-parmar/cve-2025-54554

CVE-2025-54554 – Unauthenticated Access in tiaudit REST API leading to Sensitive Information Disclosure

api-securityinformation-gatheringmisconfiguration+2
1 year ago
CVE-2019-19653 preview

CVE-2019-19653

GitHubjra89/cve-2019-19653

Chevereto information disclosure <= 3.13.5 Core

exploitationinformation-gatheringmisconfiguration+2
6 years ago
Previous12…8Next