Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
267 results
G0BurpSQLmaPI preview

G0BurpSQLmaPI

GitHubnu11secur1ty/g0burpsqlmapi

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

exploitationpayload-generationpenetration-testing+2
3
6 days ago
Kousei preview

Kousei

GitHubnu11secur1ty/kousei

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

exploitationpassword-crackingpayload-generation+6
36 days ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
16 days ago
athena preview

athena

GitHubathena-os/athena

Athena OS is a Arch/Nix-based distro focused on Cybersecurity. Learn, practice and enjoy with any hacking tool!

educationlabs-practicelearning-paths-courses+3
1.3k7 days ago
AutoPWN-Suite preview

AutoPWN-Suite

GitHubgamehunterkaan/autopwn-suite

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

exploitationinformation-gatheringnetwork-security+5
1.1k8 days ago
Adversarial-Detection-Engineering-Framework preview

Adversarial-Detection-Engineering-Framework

GitHubadversarial-detection-engineering/adversarial-detection-engineering-framework

A framework and taxonomy for identifying, classifying, and reasoning about detection logic bugs in SIEM, EDR, and XDR rules, with concrete examples…

curated-resourcesdefensive-toolseducation+7
639 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubcrowsec-edtech/cve-2026-87902

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

exploitationlabs-practicepayload-development+5
311 days ago
EXPLOIT-CVE-2026-87902 preview

EXPLOIT-CVE-2026-87902

GitHubjoaovicdev/exploit-cve-2026-87902

Lab vulnerável (Docker) + PoC Python para a CVE-2026-87902 — path traversal não autenticado no WordPress Core (page-template -> LFI -> RCE…

container-securityeducationexploitation+6
12 days ago
CVE-2026-87902 preview

CVE-2026-87902

GitHublutfifakee-project/cve-2026-87902

Proof-of-concept exploit for CVE-2026-87902, a WordPress Core pre-auth path traversal chaining LFI to remote code execution.

exploitationpenetration-testingremote-access-tool+3
13 days ago
WPSniper preview

WPSniper

GitHubynsmroztas/wpsniper

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

information-gatheringpenetration-testingreconnaissance+4
313 days ago
WinFlesher preview

WinFlesher

GitHubmindsflee/winflesher

Automated attack surface assessment framework for Active Directory and local infrastructures, correlating vulnerabilities with attack paths to domain…

configuration-auditinglateral-movementpenetration-testing+4
2615 days ago
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
171 month ago
CVE-2026-76569 preview

CVE-2026-76569

GitHubtoanln-cov/cve-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
OSCP-Exam-Report-Template-Markdown preview

OSCP-Exam-Report-Template-Markdown

GitHubnoraj/oscp-exam-report-template-markdown

:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report

educationpenetration-testingutilities-frameworks
4.2k1 month ago
CVE-2026-18953 preview

CVE-2026-18953

GitHubronamosa/cve-2026-18953

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

api-securityexploitationpenetration-testing+1
2 months ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
2 months ago
CVE-2025-68937 preview

CVE-2025-68937

GitHubscratchappy/cve-2025-68937

Automated PoC exploit for CVE-2025-68937 — Gitea/Forgejo Template Symlink RCE. Any authenticated user can get a shell as the git service user.

exploitationpenetration-testingprivilege-escalation+3
2 months ago
wraith preview

wraith

GitHubarcanum-sec/wraith

Browser-hooking framework for authorized red teams and educators. Hooks browsers via XSS, provides interactive post-exploitation control, blind-XSS…

command-and-controleducationexploitation+6
1542 months ago
Previous12…15Next