Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
378 results
mqxss preview

mqxss

GitHubgrampae/mqxss

Hooked browser communication over MQTT

command-and-controlinformation-gatheringpayload-generation+4
82 years ago
CVE-2025-14847 preview

CVE-2025-14847

GitHubsakthivel10q/cve-2025-14847

🛠 Exploit the CVE-2025-14847 vulnerability in MongoDB to disclose sensitive heap memory using a Python script that analyzes responses for new leaked…

database-securityexploitationinformation-gathering+3
12 days ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc
command-and-controlexploitationinformation-gathering+8
11 month ago
CVE-2025-24893 preview

CVE-2025-24893

GitHubgotr00t0day/cve-2025-24893

Unauthenticated Remote Code Execution in XWiki via SolrSearch Macro

exploitationinformation-gatheringpenetration-testing+2
610 months ago
CVE-2025-2825-CrushFTP-AuthBypass preview

CVE-2025-2825-CrushFTP-AuthBypass

GitHubshivshantp/cve-2025-2825-crushftp-authbypass

Authentication Bypass PoC for CVE-2025-2825 – Exploiting CrushFTP 10.x

authenticationexploitationinformation-gathering+5
51 year ago
phantomrecon preview

phantomrecon

GitHubl33tdawg/phantomrecon

PhantomRecon is a CLI-based, modular, agent-driven red team automation tool designed to demonstrate autonomous offensive security workflows powered…

dns-analysisexploitationinformation-gathering+6
36 months ago
trackem preview

trackem

GitHubveteranop/trackem

Passive Device Tracker (Android)TrackEm Mobile is a real-time, passive Wi-Fi + Bluetooth LE probe-request scanner designed for OSINT, red-team ops,…

bluetooth-securityinformation-gatheringiot-security+6
49 months ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
128 days ago
watchTowr-vs-JunosEvolved-CVE-2026-21902 preview

watchTowr-vs-JunosEvolved-CVE-2026-21902

GitHubwatchtowrlabs/watchtowr-vs-junosevolved-cve-2026-21902
exploitationinformation-gatheringnetwork-security+4
45 months ago
CVE-2021-26828-Ultimate preview

CVE-2021-26828-Ultimate

GitHubridpath/cve-2021-26828-ultimate

ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR

command-and-controlexploitationinformation-gathering+6
58 months ago
CVE-2024-44000 preview

CVE-2024-44000

GitHubgeniuszly/cve-2024-44000

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies

exploitationinformation-gatheringpenetration-testing+2
51 year ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
2 months ago
GrafTraverse-CVE-2021-43798 preview

GrafTraverse-CVE-2021-43798

GitHubasbawy/graftraverse-cve-2021-43798

CVE-2021-43798 MiNi Exploitation Framework

exploitationinformation-gatheringpassword-cracking+4
2 months ago
cosmicsting-cve-2024-34102-exploit preview

cosmicsting-cve-2024-34102-exploit

GitHubrussellwork2021-lgtm/cosmicsting-cve-2024-34102-exploit

Complete CosmicSting (CVE-2024-34102) exploit suite for Magento/Adobe Commerce XXE vulnerability

exploitationinformation-gatheringpenetration-testing+3
2 months ago
CVE-2026-4631-cockpit-RCE preview

CVE-2026-4631-cockpit-RCE

GitHubexdev994/cve-2026-4631-cockpit-rce

Unauthenticated Remote Code Execution via SSH Command-Line Argument Injection Cockpit versions 327 – 359 | CVSS 9.8 Critical | CWE-78

command-and-controlexploitationinformation-gathering+6
1 month ago
WCE preview

WCE

GitHubal1ex/wce

Window Hash&Password dump

authenticationinformation-gatheringpassword-attacks+2
35 years ago
postEX preview

postEX

GitHubniker-lixy/postex
information-gatheringpenetration-testingpersistence-mechanisms+4
11 month ago
Ssh Mitm preview

Ssh Mitm

GitLabssh-mitm/ssh-mitm

Mirror moved — see GitHub and Codeberg

authenticationinformation-gatheringnetwork-security+3
1 month ago
Previous1…161718…21Next