Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
CVE-2026-57821-PoC-Exploit preview

CVE-2026-57821-PoC-Exploit

GitHubtc4dy/cve-2026-57821-poc-exploit

🔐 CVE-2026-57821 - Apache Fineract SQL Injection Toolkit 📚 Two Python scripts for authorized security testing: verifier.py (safe detection, no…

code-analysisdatabase-securityeducation+5
3
1 month ago
selenium-node-takeover-kit preview

selenium-node-takeover-kit

GitHubjonstratton/selenium-node-takeover-kit

A collection of selenium tests that might aid it takeover of a selenium node

command-and-controldata-exfiltrationexploit-frameworks+6
28 months ago
mongobleedburp preview

mongobleedburp

GitHubj0lt-github/mongobleedburp

Burp Suite extension to detect CVE-2025-14847 (MongoBleed) via manual leak tests from a dedicated UI tab.

data-exfiltrationexploitationinformation-gathering+3
1 month ago
web-application-firewall- preview

web-application-firewall-

GitHubnithylesh/web-application-firewall-

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

educationexploitationids-ips-evasion+5
32 years ago
docker-cve-2016-2107 preview

docker-cve-2016-2107

GitHubtmiklas/docker-cve-2016-2107

Docker container implementing tests for CVE-2016-2107 - LuckyNegative20

cryptographyexploitationpenetration-testing+2
210 years ago
CVE-2022-22536_SAP_Request_Smuggling_Scanner preview

CVE-2022-22536_SAP_Request_Smuggling_Scanner

GitHubabrewer251/cve-2022-22536_sap_request_smuggling_scanner

Fast, socket-level scanner for detecting CVE-2022-22536 in SAP ICM or Web Dispatcher instances. Performs request smuggling tests with a crafted…

exploitationnetwork-securitypenetration-testing+3
9 months ago
CVE-2025-33073-checker preview

CVE-2025-33073-checker

GitHubmatejsmycka/cve-2025-33073-checker

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

authenticationexploitationinformation-gathering+3
1 year ago
MCP-Inspector-CVE-2025-49596 preview

MCP-Inspector-CVE-2025-49596

GitHubashiqrehan-21/mcp-inspector-cve-2025-49596

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

api-security-testingeducationexploitation+3
1 year ago
postgres-bruteforcer preview

postgres-bruteforcer

GitHubrandomrobbiebf/postgres-bruteforcer

This tool takes a list of default creds and tests it against a postgresql server and logs any that work and the databases it has access to.

authenticationdatabase-securityexploitation+2
3 years ago
Password-Analysis preview

Password-Analysis

GitHubam0nt31r0/password-analysis

Script in Go that analyzes a list of passwords based on in its entropy and weak passwords from a dictionary. Useful for penetration tests and…

password-attackspassword-crackingpenetration-testing+1
4 years ago
CVE-2018-1235 preview

CVE-2018-1235

GitHubabsozed/cve-2018-1235

A python script that tests for an exploitable instance of CVE-2018-1235.

exploitationpayload-developmentpenetration-testing+2
7 years ago
xmlrpc-brute preview

xmlrpc-brute

GitHubankhcorp/xmlrpc-brute

This tool tests WordPress installations for XML-RPC authentication vulnerabilities.

password-attackspenetration-testingvulnerability-analysis+1
1 year ago
CVE-2025-3248 preview

CVE-2025-3248

GitHubgraysignal/cve-2025-3248

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

exploitationpenetration-testingvulnerability-analysis+3
11 year ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
22 days ago
CVE-2025-11740 preview

CVE-2025-11740

GitHubalixploit22/cve-2025-11740

Python proof-of-concept for CVE-2025-11740; triggers the vulnerability to verify exposure and support remediation in authorized security tests.

exploitationpenetration-testingvulnerability-analysis
4 days ago
portia preview
Archived

portia

GitHubspiderlabs/portia

Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been…

exploitationinformation-gatheringlateral-movement+5
5016 years ago
atomic-operator preview
Archived

atomic-operator

GitHubswimlane/atomic-operator

A Python package is used to execute Atomic Red Team tests (Atomics) across multiple operating system environments.

cloud-securitydefensive-toolseducation+3
1562 years ago
WinPwn preview

WinPwn

GitHubs3cur3th1ssh1t/winpwn

Automation for internal Windows Penetrationtest / AD-Security

exploitationpenetration-testingpenetration-testing-frameworks+4
3.7k11 months ago
Previous123456Next