Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
314 results
Project-CVE-2025-54068 preview

Project-CVE-2025-54068

GitHube4zyy/project-cve-2025-54068

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

information-gatheringreconnaissancevulnerability-analysis+2
3
3 days ago
htb-labs-nexus preview

htb-labs-nexus

GitHubdiegorivas1/htb-labs-nexus

Hack The Box Nexus machine write-up covering reconnaissance, Gitea credential discovery, Krayin CRM exploitation via CVE-2026-38526, initial access,…

ctfeducationexploitation+7
3 days ago
RCE-CVE-2026-10520-CVE-2026-10523 preview

RCE-CVE-2026-10520-CVE-2026-10523

GitHubimbas007/rce-cve-2026-10520-cve-2026-10523

Detection artifact generator for Ivanti Sentry authentication bypass and RCE vulnerabilities (CVE-2026-10520, CVE-2026-10523). Scans single or…

exploitationpenetration-testingreconnaissance+3
6 days ago
CVE-2024-28000-Exploit-Lab preview

CVE-2024-28000-Exploit-Lab

GitHubshawnng078-ops/cve-2024-28000-exploit-lab

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

educationexploitationlabs-practice+5
8 days ago
unrealircd-backdoor-pentest-report preview

unrealircd-backdoor-pentest-report

GitHubelazab2005/unrealircd-backdoor-pentest-report

Controlled PenTest lab report for UnrealIRCd 3.2.8.1 backdoor (CVE-2010-2075) on Metasploitable3 with remediation steps.

educationexploitationlabs-practice+5
9 days ago
CVE-2026-67620-poc preview

CVE-2026-67620-poc

GitHubabdugafforov-bobur/cve-2026-67620-poc

CVE-2026-67620 - Flowise SSRF via incomplete cloud-metadata deny-list (Oracle OCI 192.0.0.192 + Alibaba 100.100.100.200 bypass the DEFAULT_DENY_LIST)

cloud-securityexploitationinformation-gathering+4
124 days ago
CVE-2026-60004-POC preview

CVE-2026-60004-POC

GitHubimbas007/cve-2026-60004-poc

CVE-2026-60004 Pre-Auth RCE Exploit — Gitea <= 1.27.0 diffpatch git hook injection (CVSS 9.8)

exploitationpayload-developmentpenetration-testing+4
1627 days ago
CVE-2021-41773-PoC preview

CVE-2021-41773-PoC

GitHubzephrfish/cve-2021-41773-poc

Proof-of-concept scanner that checks hosts for CVE-2021-41773 Apache path traversal vulnerability, reporting vulnerable or not vulnerable status.

exploitationpenetration-testingreconnaissance+2
171 month ago
offensive-security-adversary-emulation preview

offensive-security-adversary-emulation

GitHubkhalilu020/offensive-security-adversary-emulation

Simulated a real-world attack (CVE-2011-2523) against a vulnerable host, then cross-checked detection coverage against an existing…

educationexploitationlabs-practice+5
1 month ago
regreSSHion-Checker preview

regreSSHion-Checker

GitHubm0n3ef/regresshion-checker

A lightweight, fast tool to scan and detect the "regreSSHion" OpenSSH remote code execution vulnerability (CVE-2024-6387).

exploitationinformation-gatheringnetwork-security+3
31 month ago
Google-api-key-scanner preview

Google-api-key-scanner

GitHubcoffinxp/google-api-key-scanner

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

api-security-testingcloud-securitymisconfiguration+3
561 month ago
Room-Walkthrough-Billing preview

Room-Walkthrough-Billing

GitHubadityabhatt3010/room-walkthrough-billing

A detailed walkthrough of Billing room exploiting CVE-2023-30258 and escalating via fail2ban misconfig

ctfeducationexploitation+6
141 month ago
Damn-Vulnerable-Drone preview

Damn-Vulnerable-Drone

GitHubnicholasaleks/damn-vulnerable-drone

Damn Vulnerable Drone is an intentionally vulnerable drone hacking simulator based on the popular ArduPilot/MAVLink architecture, providing a…

educationexploitationhardware-iot-security+7
7941 month ago
VMware-CVE-2022-22954 preview

VMware-CVE-2022-22954

GitHubnieldk/vmware-cve-2022-22954

Proof-of-concept exploit for CVE-2022-22954, a Freemarker server-side template injection in VMware Workspace ONE Access, with a one-line GET request…

exploitationinformation-gatheringreconnaissance+2
1 month ago
JustTryHarder preview

JustTryHarder

GitHubsinfulz/justtryharder

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

educationexploitationpassword-cracking+7
8351 month ago
recon-test-livewire preview

recon-test-livewire

GitHubluisdalmolin/recon-test-livewire

Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning

educationlabs-practicepenetration-testing+3
1 month ago
smbghost preview

smbghost

GitHubp4ncontomat3/smbghost

scanner for CVE-2020-0796

exploitationnetwork-securitypenetration-testing+2
2 months ago
React2Shell-PoC-CVE-2025-55182 preview

React2Shell-PoC-CVE-2025-55182

GitHublitndat/react2shell-poc-cve-2025-55182

PoC scanner and exploit for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Detects vulnerable servers and executes remote…

educationexploitationlabs-practice+4
2 months ago
Previous12…18Next