Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
225 results
POC_CVE-2026-41940 preview

POC_CVE-2026-41940

GitHubimbas007/poc_cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940 targeting cPanel, enabling account enumeration, command execution, and interactive shell access on…

command-and-controlexploitationpenetration-testing+3
3 months ago
portscan-CVE-2026-41940 preview

portscan-CVE-2026-41940

GitHubamirrezamarzban/portscan-cve-2026-41940

IP CIDRs (presumably as input, maybe command line or file) and checks ports 2083 and 2087 for openness

information-gatheringnetwork-securitypenetration-testing+3
14 months ago
CVE-2021-43798-mass_scanner preview

CVE-2021-43798-mass_scanner

GitHubrodpwn/cve-2021-43798-mass_scanner

Mass scanner for Grafana CVE-2021-43798 unauthorized file read, supporting single targets, hostname lists, and IP ranges with PoC verification.

exploitationinformation-gatheringreconnaissance+2
54 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubpuckiestyle/cve-2021-41773

Python script to exploit CVE-2021-41773, a path traversal vulnerability in Apache 2.4.49, allowing file disclosure and remote code execution.

exploitationpenetration-testingreconnaissance+2
4 years ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubmauricelambert/cve-2021-42013

Detects and exploits Apache CVE-2021-42013 for remote code execution and local file disclosure via Nmap, Python, and Ruby scripts.

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubmauricelambert/cve-2021-41773

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

exploitationinformation-gatheringpenetration-testing+3
14 years ago
CVE-2026-41551 preview

CVE-2026-41551

GitHubselecthch/cve-2026-41551

Proof-of-concept exploit for CVE-2026-41551, a path traversal vulnerability in Siemens ROS# file_server, demonstrating remote file read via crafted…

exploitationinformation-gatheringpenetration-testing+3
15 days ago
CVE-2026-22812-POC preview

CVE-2026-22812-POC

GitHubcaybermods/cve-2026-22812-poc

Python tool to check and exploit CVE-2026-22812 in OpenCode, supporting command execution, file read, and multi-target scanning on ports 4095-4100.

exploitationinformation-gatheringpenetration-testing+3
17 months ago
oopso preview

oopso

GitHubb3rito/oopso

An easy-to-use client-side OSINT query builder for discovering exposed file managers across search engines.

information-gatheringosintreconnaissance+2
41 month ago
mkpath preview

mkpath

GitHubtrickest/mkpath

Make URL path combinations using a wordlist

fuzzinginformation-gatheringpenetration-testing+2
1762 years ago
ffufPostprocessing preview

ffufPostprocessing

GitHubdsecuredcom/ffufpostprocessing

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

fuzzinginformation-gatheringpenetration-testing+3
1441 year ago
EvilCrowRF_Custom_Firmware_CC1101_FlipperZero preview

EvilCrowRF_Custom_Firmware_CC1101_FlipperZero

GitHubh-rat/evilcrowrf_custom_firmware_cc1101_flipperzero

This firmware is an alternative to the EvilCrowRF default firmware. Module: CC1101 - Compatible Flipper Zero file.

embedded-systems-securityhardware-hackinghardware-iot-security+5
5972 years ago
enumhandles_BOF preview

enumhandles_BOF

GitHuboctoberfest7/enumhandles_bof

Cobalt Strike BOF for live Windows enumeration of open file handles, revealing which process has locked a target file on disk during…

information-gatheringpenetration-testingpost-exploitation+2
1271 year ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k1 year ago
CVE-2026-58048-PoC-Exploit preview

CVE-2026-58048-PoC-Exploit

GitHubtc4dy/cve-2026-58048-poc-exploit

👾 CVE-2026-58048 – cPanel Root SQL Execution Toolkit (CVSS 9.4) | Full Red/Blue Team Toolkit suite for unpatched cPanel & WHM 11.x. 2 tools: Safe…

database-securityexploitationincident-response+7
521 days ago
CVE-2026-66066 preview

CVE-2026-66066

GitHubshinthink/cve-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

exploitationpenetration-testingreconnaissance+3
126 days ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
27 days ago
Extracter preview

Extracter

GitHubk3ystr0k3r/extracter

A nice web-crawler written in Bash that will look for login pages/admin-panels for you on any given website.

crawlerinformation-gatheringosint+2
63 years ago
Previous12…13Next