Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1127 results
Shodan-CVE-2024-4577 preview

Shodan-CVE-2024-4577

GitHubd3ck4/shodan-cve-2024-4577

Proof-of-concept exploit for CVE-2024-4577 with Shodan integration for automated discovery of vulnerable targets on the internet.

exploitationinformation-gatheringosint+2
2
2 years ago
CVE-2021-45901 preview

CVE-2021-45901

GitHub9lyph/cve-2021-45901

Proof-of-concept Python script that enumerates valid ServiceNow user accounts by exploiting the password-reset response discrepancy in CVE-2021-45901.

exploitationinformation-gatheringosint+3
21 year ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubpxxdrobits/cve-2025-49132

Check a list of Pterodactyl panels for vulnerabilities from a file.

exploitationinformation-gatheringosint+3
21 year ago
CVE-2024-4367-PoC preview

CVE-2024-4367-PoC

GitHubkabiri-labs/cve-2024-4367-poc

This Proof of Concept (PoC) demonstrates the exploitation of the CVE-2024-4367 vulnerability, which involves Cross-Site Scripting (XSS) attacks.

exploitationinformation-gatheringosint+3
11 year ago
Feb2023-CVE-2021-21974-OSINT preview

Feb2023-CVE-2021-21974-OSINT

GitHubn2x4/feb2023-cve-2021-21974-osint

Analysis of the ransom demands from Shodan results

cryptographyinformation-gatheringosint+3
23 years ago
internal-security-detect preview

internal-security-detect

GitHubrxerium/internal-security-detect

The detection of internal security controls at a company

configuration-auditingdefensive-toolsinformation-gathering+5
28 months ago
CVE-2019-0708- preview

CVE-2019-0708-

GitHubttsite/cve-2019-0708-

Announces fraud

information-gatheringosintreconnaissance+2
27 years ago
CVE-2017-10797 preview

CVE-2017-10797

GitHubn4xh4ck5/cve-2017-10797

CVE-2017-10797- User Enumeration in OwnCloud Server 8.1-10.0

information-gatheringosintreconnaissance+2
18 years ago
CVE-2025-53640 preview

CVE-2025-53640

GitHubrafaelcorvino1/cve-2025-53640

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

api-security-testinginformation-gatheringosint+3
18 months ago
CVE-2026-4106 preview

CVE-2026-4106

GitHubef3tr/cve-2026-4106

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)

educationexploitationinformation-gathering+6
15 months ago
Best-Practices-Cybersecurity-Otanata-Project preview

Best-Practices-Cybersecurity-Otanata-Project

GitHubaskhatov21/best-practices-cybersecurity-otanata-project

CVE-2024-3273 — Authorized Penetration Test Report D-Link DNS-320L NAS | Client: Otonata

command-and-controleducationembedded-systems-security+8
5 months ago
CVE-2026-XXXX-atlassian-email-enumeration preview

CVE-2026-XXXX-atlassian-email-enumeration

GitHubwh4l3x/cve-2026-xxxx-atlassian-email-enumeration

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

email-harvestinginformation-gatheringosint+5
3 months ago
UserEnumJira preview

UserEnumJira

GitHubund3sc0n0c1d0/userenumjira

Serie de scripts para enumerar nombres de usuarios de JIRA a partir de vulnerabilidades conocidas (CVE-2020-14181, CVE-2019-3403, CVE-2019-8449...)

information-gatheringosintreconnaissance+2
15 years ago
Magnohost-Vulnerabilities-pentest preview

Magnohost-Vulnerabilities-pentest

GitHub0ord/magnohost-vulnerabilities-pentest

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

exploitationinformation-gatheringnetwork-security+8
14 months ago
osintnet-public preview

osintnet-public

GitHubosintnet/osintnet-public

OsintNET is a browser-based OSINT platform for domain intelligence, website risk scanning, SERP discovery, image intelligence and AI image detection.

ai-securitydigital-forensicsdns-analysis+8
13 months ago
pulse-exploit preview

pulse-exploit

GitHubandripwn/pulse-exploit

Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API.

exploitationosintpenetration-testing+3
16 years ago
NetSpecter preview

NetSpecter

GitLabs_r_e_e_r_a_j/netspecter

NetSpecter is a lightweight yet powerful asynchronous OSINT and reconnaissance engine built in Python.

dns-analysisinformation-gatheringnetwork-security+4
13 months ago
Reverse_ip_Multithreading1 preview

Reverse_ip_Multithreading1

GitHubjenderal92/reverse_ip_multithreading1

Multithreaded reverse IP lookup tool for discovering domains hosted on the same IP address.

osintreconnaissancesubdomain-enumeration
4 months ago
Previous1…545556…63Next