Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
158 results
cve_2026_31431_audit preview

cve_2026_31431_audit

GitHubmariohy/cve_2026_31431_audit

A security auditing toolkit for CVE-2026-31431 vulnerability research

exploitationpenetration-testingpost-exploitation+3
3 months ago
CVE-2023-42793_POC preview

CVE-2023-42793_POC

GitHubjohnossawy/cve-2023-42793_poc

Automated exploit script for CVE-2023-42793 targeting TeamCity, enabling token manipulation and admin user creation for penetration testing.

exploitationpenetration-testingred-teaming+2
2 years ago
CVE-2026-23744 preview

CVE-2026-23744

GitHubctzisme/cve-2026-23744

Proof-of-concept exploit for CVE-2026-23744, demonstrating unauthenticated remote code execution in MCPJam Inspector versions up to 1.4.2 via crafted…

exploitationpenetration-testingred-teaming+2
15 months ago
CVE-2023-22527 preview

CVE-2023-22527

GitHubvozec/cve-2023-22527

Proof-of-concept exploit for CVE-2023-22527, a server-side template injection in Confluence that enables remote code execution. Includes a Python…

educationexploitationpenetration-testing+3
142 years ago
CVE-2026-41940 preview

CVE-2026-41940

GitHub0xyur1/cve-2026-41940

cPanel/WHM Authentication Bypass (Zero-Day Vulnerability)

authenticationauthentication-authorizationexploitation+6
103 months ago
zyxel-social-login-bypass-cve-2026-8508 preview

zyxel-social-login-bypass-cve-2026-8508

GitHubminanagehsalalma/zyxel-social-login-bypass-cve-2026-8508

Public writeup, PoC, and emulation materials for CVE-2026-8508 affecting Zyxel captive-portal social login.

authenticationexploitationnetwork-access-control+4
11 days ago
decode-spam-headers preview

decode-spam-headers

GitHubmgeeky/decode-spam-headers

A script that helps you understand why your E-Mail ended up in Spam

email-securityinformation-gatheringlog-analysis+2
7006 months ago
secretsdump.py preview

secretsdump.py

GitHubfin3ss3g0d/secretsdump.py

Enhanced version of secretsdump.py from Impacket. Adds multi-threading and accepts an input file with a list of target hosts for simultaneous secrets…

data-exfiltrationpassword-attackspenetration-testing+2
2593 years ago
WSL_Payload_Builder preview

WSL_Payload_Builder

GitHubm1ddl3w4r3/wsl_payload_builder

A powerful shell script for creating custom WSL (Windows Subsystem for Linux) distributions with embedded payloads.

payload-developmentpayload-generationpenetration-testing+1
729 months ago
POC-Bash-CVE-2021-3560 preview

POC-Bash-CVE-2021-3560

GitHubwithinonestem/poc-bash-cve-2021-3560

Script Bash -- CVE-2021-3560

exploitationpenetration-testingpost-exploitation+2
1 year ago
susinternals preview

susinternals

GitHubsensepost/susinternals

psexecsvc - a python implementation of PSExec's native service implementation

authenticationlateral-movementpenetration-testing+3
3145 months ago
BadSamba preview

BadSamba

GitHubstrozfriedberg/badsamba

This module is used to exploit startup script execution through Windows Group Policy settings when configured to run off of a remote SMB share.

exploitationlateral-movementnetwork-security+3
226 years ago
CVE-2024-49328-exploit preview

CVE-2024-49328-exploit

GitHubnxploited/cve-2024-49328-exploit

Python script to exploit a privilege escalation vulnerability in the WP REST API FNS WordPress plugin, allowing unauthenticated creation of…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2020-6519 preview

CVE-2020-6519

GitHubweizman/cve-2020-6519

Proof-of-concept exploit for CVE-2020-6519 - a Chromium zero-day that fully bypasses Content Security Policy (CSP) across platforms, enabling script…

exploitationpenetration-testingred-teaming+4
65 years ago
itsm-exploit preview

itsm-exploit

GitHubsynacktiv/itsm-exploit

Ivanti Neurons for ITSM (On Premise) exploits

authentication-authorizationexploitationpenetration-testing+3
810 months ago
tor-ip-changer preview

tor-ip-changer

GitHubianxtianxt/tor-ip-changer

Simple shell script to automatically request new Tor identity at configurable intervals for IP rotation.

educationids-ips-evasionprivacy+1
26 years ago
CVE-2026-1492 preview

CVE-2026-1492

GitHubnxploited/cve-2026-1492

User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

educationexploitationpenetration-testing+4
4 months ago
CVE-2026-27542-CVE-2026-27540- preview

CVE-2026-27542-CVE-2026-27540-

GitHubnxploited/cve-2026-27542-cve-2026-27540-

Unauthenticated Privilege | Unauthenticated Arbitrary File Upload

exploitationpenetration-testingprivilege-escalation+3
4 months ago
Previous12…9Next