Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13 results
WebView2-Cookie-Stealer preview

WebView2-Cookie-Stealer

GitHubmrd0x/webview2-cookie-stealer

Injects JavaScript keylogger into WebView2 pages to capture keystrokes and exfiltrate cookies from Microsoft authentication sessions via HTTP GET…

data-exfiltrationinformation-gatheringpassword-attacks+2
2644 years ago
spamscanner preview

spamscanner

GitHubspamscanner/spamscanner

Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs,…

anti-botdynamic-analysis-sandboxingemail-security+6
3749 months ago
svg_phishing_tools preview

svg_phishing_tools

GitHubhackinglz/svg_phishing_tools

SVG Analysis and generation tools for commonly seen SVG attachment phishing

dynamic-analysis-sandboxinginformation-gatheringmalware-analysis+5
560 years ago
I-See-You preview

I-See-You

GitHubviralmaniar/i-see-you

ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location…

educationinformation-gatheringosint+5
1.2k7 years ago
CVE-2019-13496 preview

CVE-2019-13496

GitHubfurqankhan1/cve-2019-13496

Proof-of-concept exploit demonstrating OTP bypass in One Identity Cloud Access Manager 8.1.3 via MITM/SSL-strip, SAML response replay, and injected…

authenticationids-ips-evasionpenetration-testing+3
26 years ago
CVE-2021-24545 preview

CVE-2021-24545

GitHubv35hr4j/cve-2021-24545

The plugin does not sanitise the HTML allowed in the Bio of users, allowing them to use malicious JavaScript code, which will be executed when anyone…

exploitationpenetration-testingphishing+3
24 years ago
CVE-2024-34568 preview

CVE-2024-34568

GitHubsanupl/cve-2024-34568

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

exploitationphishingvulnerability-analysis+2
14 months ago
CVE-2025-69606-GSVoIP-XSS preview

CVE-2025-69606-GSVoIP-XSS

GitHubrazielx64/cve-2025-69606-gsvoip-xss

Proof-of-concept for a reflected XSS vulnerability (CVE-2025-69606) in GSVoIP Web Panel v2.0.90, demonstrating unauthenticated arbitrary JavaScript…

educationphishingsocial-engineering+3
4 months ago
CVE-2021-24563 preview

CVE-2021-24563

GitHubv35hr4j/cve-2021-24563

The plugin does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing…

exploitationpenetration-testingphishing+2
14 years ago
CVE-2025-28073 preview

CVE-2025-28073

GitHubmlniumm/cve-2025-28073

Proof-of-concept for a reflected XSS vulnerability in phpList 3.6.15 via the /lists/dl.php endpoint, enabling session hijacking and arbitrary…

exploitationphishingvulnerability-analysis+2
1 year ago
CVE-2024-57428 preview

CVE-2024-57428

GitHubahrixia/cve-2024-57428

CVE-2024-57428: PHPJabbers Cinema Booking System v2.0 suffers from stored XSS, enabling persistent JavaScript injection for phishing and malware…

exploitationpenetration-testingphishing+2
1 year ago
CVE-2020-16270 preview

CVE-2020-16270

GitHubsecurity-avs/cve-2020-16270

Proof-of-concept for CVE-2020-16270, an XSS vulnerability in OLIMPOKS under 3.3.39, demonstrating remote injection of malicious JavaScript to steal…

exploitationinformation-gatheringpenetration-testing+3
5 years ago
TokenFlare preview

TokenFlare

GitHubjumpseclabs/tokenflare

Serverless AITM Simulation Framework for Entra ID and M365

authenticationcloud-securitycommand-and-control+6
2428 months ago