Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
Linux-Kernel-Vulnerabilities-CVE-2026-23111 preview

Linux-Kernel-Vulnerabilities-CVE-2026-23111

GitHubvrtlbob/linux-kernel-vulnerabilities-cve-2026-23111

High Severity LPE vulnerability in Linux Kernel, with a CVS score of 7.8. An inverted check from user enables a process inside the container to break…

container-escapeeducationexploitation+3
1
2 months ago
CVE-2026-48907 preview

CVE-2026-48907

GitHub87achrafg-stack/cve-2026-48907

Exploits CVE-2025-9209 in WordPress by querying /wp-json/wp/v2/users, harvesting user keys, tokens, and cookies, bypassing Defender/Imunify360, and…

exploitationids-ips-evasioninformation-gathering+3
2 months ago
YellowKey-WinRE-Remediation preview

YellowKey-WinRE-Remediation

GitHubeverest90909/yellowkey-winre-remediation

PowerShell-based Intune remediation package that detects and removes the vulnerable autofstx.exe BootExecute entry from offline WinRE images, then…

configuration-auditingdefensive-toolsincident-response+2
13 months ago
nginx-cve-2026-42945-check preview

nginx-cve-2026-42945-check

GitHubbyezero/nginx-cve-2026-42945-check

Local read-only scanner for CVE-2026-42945 (NGINX Rift) that checks NGINX, OpenResty, and Tengine instances for vulnerable rewrite configurations…

configuration-auditingscripting-automationstatic-analysis+3
3 months ago
Dead.Letter-CVE-2026-45185 preview

Dead.Letter-CVE-2026-45185

GitHubliamromanis101/dead.letter-cve-2026-45185

Shell-based vulnerability scanner for CVE-2026-45185 (Dead.Letter) in Exim MTA. Detects use-after-free in GnuTLS builds, checks version, TLS library,…

configuration-auditingdevsecopsemail-security+5
23 months ago
audit-axios preview

audit-axios

GitHubsurri/audit-axios

Scan local repos for vulnerable axios versions (CVE-2026-40175) and patch interactively

code-analysisconfiguration-auditingdevsecops+3
4 months ago
MCPwnfluence preview

MCPwnfluence

GitHubplutosecurity/mcpwnfluence

Information about CVE-2026-27825 & CVE-2026-27826 discovered by Pluto Security and a bash script for identifying vulnerable mcp-atlassian instances…

configuration-auditingdevsecopseducation+3
76 months ago
CVE-2026-1405 preview

CVE-2026-1405

GitHubnxploited/cve-2026-1405

Slider Future <= 1.0.5 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
46 months ago
CVE-2025-46295-fix-fms preview

CVE-2025-46295-fix-fms

GitHubsoliantconsulting/cve-2025-46295-fix-fms

Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with…

configuration-auditingdevsecopsscripting-automation+3
18 months ago
React2Shell-CVE-2025-55182-Detector preview

React2Shell-CVE-2025-55182-Detector

GitHubgarethmsheldon/react2shell-cve-2025-55182-detector

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

code-analysisscripting-automationsupply-chain-security+3
18 months ago
CVE-1999-0524 preview

CVE-1999-0524

GitHubb1tsec/cve-1999-0524

A Bash script to check if systems are vulnerable to ICMP Timestamp Request Remote Date Disclosure (CVE-1999-0524).

information-gatheringnetwork-securitypenetration-testing+3
18 months ago
react-vuln-scanner preview

react-vuln-scanner

GitHubumairahmadh/react-vuln-scanner

A bash script to scan your server for React applications vulnerable to **CVE-2025-55182** — a critical remote code execution vulnerability (CVSS…

code-analysisdevsecopsexploitation+3
19 months ago
CVE-2021-44228 preview

CVE-2021-44228

GitHubaxisops/cve-2021-44228

log4j mitigation work

configuration-auditingdevsecopsmisconfiguration+3
1 year ago
CVE-2025-29927-Testing preview

CVE-2025-29927-Testing

GitHubtheresafewconors/cve-2025-29927-testing

PowerShell script to test if a web app is vulnerable to CVE-2025-29927

exploitationinformation-gatheringpenetration-testing+3
21 year ago
loxs-optimized preview

loxs-optimized

GitHubmomika233/loxs-optimized

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

payload-generationpenetration-testingscripting-automation+3
451 year ago
CVE-2024-9593-Exploit preview

CVE-2024-9593-Exploit

GitHubnxploited/cve-2024-9593-exploit

PoC exploit for CVE-2024-9593 exploiting unauthenticated remote code execution in WordPress Time Clock plugin. Python script invokes vulnerable…

educationexploitationpenetration-testing+3
11 year ago
CVE-2024-7456scripts preview

CVE-2024-7456scripts

GitHub77philly/cve-2024-7456scripts

Bash and Node.js scripts to automate SQL injection exploitation against vulnerable web applications, targeting CVE-2024-7456.

exploitationpenetration-testingscripting-automation+2
1 year ago
cve-2024-41110-checker preview

cve-2024-41110-checker

GitHubvvpoglazov/cve-2024-41110-checker

Parallel SSH-based scanner that detects CVE-2024-41110 in Docker installations, identifies vulnerable versions and AuthZ plugins, and generates a…

cloud-infrastructure-securityconfiguration-auditingcontainer-security+2
62 years ago
Previous123Next