Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
988 results
cve-2022-36804 preview

cve-2022-36804

GitHubtahtaciburak/cve-2022-36804

A simple PoC for Atlassian Bitbucket RCE [CVE-2022-36804]

exploitationpenetration-testingreconnaissance+2
7
3 years ago
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
4 months ago
cve-2022-1388-1veresk preview

cve-2022-1388-1veresk

GitHubiveresk/cve-2022-1388-1veresk

Simple shell script for the exploit

exploitationpenetration-testingreconnaissance+2
14 years ago
CVE-2020-3452-PoC preview

CVE-2020-3452-PoC

GitHubxdev05/cve-2020-3452-poc
exploitationpenetration-testingreconnaissance+3
26 years ago
CVE-2021-26855-PoC preview

CVE-2021-26855-PoC

GitHubsrvaccount/cve-2021-26855-poc

PoC exploit code for CVE-2021-26855

email-securityexploitationinformation-gathering+3
175 years ago
recon-skills preview

recon-skills

GitHubuphiago/recon-skills

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

cloud-securitycrawlerexploitation+9
1.2k23 days ago
hackbox preview

hackbox

GitHubsamhaxr/hackbox

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

information-gatheringmisconfigurationpenetration-testing+5
4183 years ago
NucleiFuzzer preview

NucleiFuzzer

GitHub0xkayala/nucleifuzzer

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

fuzzinginformation-gatheringpenetration-testing+3
1.9k4 months ago
CVE-2014-4210-SSRF-PORTSCANNER-POC preview

CVE-2014-4210-SSRF-PORTSCANNER-POC

GitHubunmanarc/cve-2014-4210-ssrf-portscanner-poc

CVE-2014-4210 SSRF PORTSCANNER PoC

educationexploitationport-scanning+3
36 years ago
CVE-2022-41040-POC preview

CVE-2022-41040-POC

GitHubkljunowsky/cve-2022-41040-poc

CVE-2022-41040 - Server Side Request Forgery (SSRF) in Microsoft Exchange Server

exploitationpenetration-testingreconnaissance+3
913 years ago
CVE-2021-26855-SSRF preview

CVE-2021-26855-SSRF

GitHubpussycat0x/cve-2021-26855-ssrf

This script helps to identify CVE-2021-26855 ssrf Poc

exploitationpenetration-testingreconnaissance+2
235 years ago
CVE-2023-27163 preview

CVE-2023-27163

GitHubrvzsec/cve-2023-27163

CVE-2023-27163 - Request Baskets SSRF

exploitationpenetration-testingreconnaissance+2
23 years ago
CVE-2026-33340 preview

CVE-2026-33340

GitHubregaan/cve-2026-33340

CVE-2026-33340: Critical SSRF in lollms-webui /api/proxy - Unauthenticated arbitrary request forgery (CVSS 9.1)

cloud-securityeducationexploitation+3
4 months ago
blind-ssrf-chains preview

blind-ssrf-chains

GitHubassetnote/blind-ssrf-chains

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

cloud-securitycurated-resourceseducation+5
9864 years ago
Garud preview

Garud

GitHubr0x4r/garud

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

penetration-testingreconnaissancesubdomain-enumeration+2
8113 months ago
nextssrf preview

nextssrf

GitHubynsmroztas/nextssrf

CVE-2026-44578 scanner and exploit tool for SSRF in Next.js WebSocket upgrade handler. Detects vulnerable versions, extracts cloud metadata, and…

cloud-securityexploitationinformation-gathering+3
773 months ago
grafana-ssrf preview

grafana-ssrf

GitHubrandomrobbiebf/grafana-ssrf

Authenticated SSRF in Grafana

cloud-securityexploitationinformation-gathering+4
832 years ago
nextjs-cve-2026-44578 preview

nextjs-cve-2026-44578

GitHublove07oj/nextjs-cve-2026-44578

Nuclei templates for detecting CVE-2026-44578 (Next.js WebSocket Upgrade SSRF) with multi-cloud metadata validation, Next.js fingerprinting, and…

cloud-securityexploitationfuzzing+3
73 months ago
Previous12…55Next