Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
CVE-2023-25157 preview

CVE-2023-25157

GitHub0x2458bughunt/cve-2023-25157

Scans host lists for GeoServer endpoints vulnerable to CVE-2023-25157 SQL injection, verifies exposed paths with keyword checks, and logs confirmed…

exploitationinformation-gatheringreconnaissance+2
10
3 years ago
CVE-2026-22812-POC preview

CVE-2026-22812-POC

GitHubcaybermods/cve-2026-22812-poc

Python tool to check and exploit CVE-2026-22812 in OpenCode, supporting command execution, file read, and multi-target scanning on ports 4095-4100.

exploitationinformation-gatheringpenetration-testing+3
18 months ago
livewire-vuln-scanner preview

livewire-vuln-scanner

GitHubjenderal92/livewire-vuln-scanner

Simple scanner to detect vulnerable Livewire installations.

information-gatheringreconnaissancevulnerability-analysis+3
4 months ago
CVE-2025-24132-Scanner preview

CVE-2025-24132-Scanner

GitHubferalthedogg/cve-2025-24132-scanner

mDNS-based AirPlay device discovery tool that scans local networks and tests for CVE-2025-24132 zero-click HTTP RCE vulnerability with a simple GUI…

exploitationinformation-gatheringnetwork-mapping+3
31 year ago
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
5 months ago
magicRecon preview

magicRecon

GitHubrobotshell/magicrecon

MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this…

dns-analysisinformation-gatheringosint+7
1.1k2 years ago
SimpleCTF-THM-Walkthrough preview

SimpleCTF-THM-Walkthrough

GitHubpaulameg/simplectf-thm-walkthrough

First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web…

ctfeducationpassword-cracking+5
14 months ago
CVE-2020-13158 preview

CVE-2020-13158

GitHubinfosec4fun/cve-2020-13158

CVE-2020-13158 - Artica Proxy before 4.30.000000 Community Edition allows Directory Traversal

exploitationinformation-gatheringpenetration-testing+3
16 years ago
CVE-2020-3452-PoC preview

CVE-2020-3452-PoC

GitHubxdev05/cve-2020-3452-poc

Automates downloading and running an Nmap NSE script to scan hosts for CVE-2020-3452 vulnerability, using a list of target hosts.

exploitationpenetration-testingreconnaissance+3
26 years ago
Joomla3.7-SQLi-CVE-2017-8917 preview

Joomla3.7-SQLi-CVE-2017-8917

GitHubbrianwrf/joomla3.7-sqli-cve-2017-8917

Joomla 3.7 SQL injection (CVE-2017-8917)

exploitationinformation-gatheringreconnaissance+2
79 years ago
http-vuln-CVE-2019-16759 preview

http-vuln-CVE-2019-16759

GitHubr00tpgp/http-vuln-cve-2019-16759

Nmap NSE Script to Detect vBulletin pre-auth 5.x RCE CVE-2019-16759

exploitationinformation-gatheringpenetration-testing+3
37 years ago
CVE-2025-55182-advanced-scanner- preview

CVE-2025-55182-advanced-scanner-

GitHubzack0x01/cve-2025-55182-advanced-scanner-

Command-line scanner for detecting and exploiting CVE-2025-55182 (React Server Components RCE) in Next.js applications. Supports custom command…

educationexploitationpenetration-testing+3
2839 months ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.1k23 days ago
MyLog4Shell preview

MyLog4Shell

GitHubkal1gh0st/mylog4shell

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

dns-analysisexploitationinformation-gathering+3
14 years ago
CVE-2025-53580 preview

CVE-2025-53580

GitHubnxploited/cve-2025-53580

WordPress Simple Business Directory Pro Plugin < 15.6.9 is vulnerable to a high priority Privilege Escalation

educationexploitationinformation-gathering+6
5 months ago
rengine preview

rengine

GitHubyogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

crawlerdns-subdomain-enumerationinformation-gathering+9
8.9k10 months ago
CVE-2020-5902-Vuln-Checker preview

CVE-2020-5902-Vuln-Checker

GitHubthecyberviking/cve-2020-5902-vuln-checker

Simple Vulnerability Checker Wrote by me "@TheCyberViking" and A fellow Researcher who wanted to be left Nameless... you know who you are you…

exploitationinformation-gatheringpenetration-testing+3
6 years ago
Automation-for-Juniper-cve-2023-36845 preview

Automation-for-Juniper-cve-2023-36845

GitHubasbawy/automation-for-juniper-cve-2023-36845

Simple Automation script for juniper cve-2023-36845

exploitationreconnaissancescripting-automation+2
192 years ago
Previous12Next