Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
79 results
Java-Example preview

Java-Example

GitHubseal-sec-demo-2/java-example

Seal Security example — vulnerable Maven app (SnakeYAML CVE-2022-1471) remediated to sealed versions; GitHub Actions + Jenkins integration

code-analysisdevsecopseducation+3
1 month ago
Python-Example preview

Python-Example

GitHubseal-sec-demo-2/python-example

Seal Security example — vulnerable pip app (PyYAML CVE-2020-14343) remediated to sealed versions; GitHub Actions + Jenkins integration

code-analysisdevsecopseducation+2
1 month ago
log4shell-scanner preview

log4shell-scanner

GitHubarpitgupta369/log4shell-scanner

Lightweight scanner that detects vulnerable Log4j versions and Log4Shell (CVE-2021-44228) indicators in a filesystem tree.

defensive-toolseducationlog-analysis+3
1 month ago
React2shell-CVE-2025-55182-checker preview

React2shell-CVE-2025-55182-checker

GitHuboways/react2shell-cve-2025-55182-checker

Passive CVE-2025-55182 detection tool for vulnerable React Server Components. Scans package.json, JavaScript bundles, HTTP headers, and API endpoints…

code-analysisdevsecopssupply-chain-security+3
28 months ago
CVE-2021-3572 preview

CVE-2021-3572

GitHubfrenzymadness/cve-2021-3572

Minimal test repository for CVE-2021-3572, demonstrating a pip dependency confusion vulnerability and its fix across vulnerable and patched versions.

code-analysiseducationstatic-analysis+2
25 years ago
CVE-2007-4559-lab preview

CVE-2007-4559-lab

GitHubjithinodattu/cve-2007-4559-lab

Self-contained Docker lab demonstrating CVE-2007-4559 (TarSlip) directory traversal via Python's tarfile module. Includes vulnerable and fixed APIs,…

binary-exploitationcode-analysisctf+6
4 months ago
xz-backdoor-CVE-2024-3094-Check preview

xz-backdoor-CVE-2024-3094-Check

GitHubbella-bc/xz-backdoor-cve-2024-3094-check

Verify if your installed version of xz-utils is vulnerable to CVE-2024-3094 backdoor

curated-resourceseducationsupply-chain-security+2
22 years ago
http-server-node preview

http-server-node

GitHubdannyendortest/http-server-node

Synthetic vulnerable Node.js HTTP server used as a demo target for the EXPOSURE vulnerability scanner, tracking CVE-2021-23797 with a one-click…

educationlabs-practicesupply-chain-security+2
3 months ago
log4j-vuln-demo preview

log4j-vuln-demo

GitHubaaronm-sysdig/log4j-vuln-demo

Intentionally vulnerable Log4j 2.14.1 demo for Sysdig CNAPP scanning (CVE-2021-44228)

cloud-securitydevsecopseducation+3
3 months ago
chk_log4j preview

chk_log4j

GitHubgcmurphy/chk_log4j

Some siimple checks to see if JAR file is vulnerable to CVE-2021-44228

code-analysisstatic-analysissupply-chain-security+2
14 years ago
node-prompt-here preview

node-prompt-here

GitHubdannyendortest/node-prompt-here

Deliberately vulnerable Node.js demo target for CVE-2020-7602, used to showcase automated dependency vulnerability detection and one-click PR-based…

educationlabs-practicesupply-chain-security+2
3 months ago
ollama-consumer preview

ollama-consumer

GitHubdannyendortest/ollama-consumer

Demo consumer for ollama v0.5.0 (vulnerable range for CVE-2024-12886) — endorctl scan target

educationexploit-frameworkssupply-chain-security+1
3 months ago
CVE-2025-46295-fix-fms preview

CVE-2025-46295-fix-fms

GitHubsoliantconsulting/cve-2025-46295-fix-fms

Automated script suite to detect and remediate CVE-2025-46295 by replacing vulnerable Apache Commons JARs in FileMaker Server installations with…

configuration-auditingdevsecopsscripting-automation+3
18 months ago
aurora-demo-lockfile preview

aurora-demo-lockfile

GitHubmlbrilliance/aurora-demo-lockfile

AURORA demo target — deliberately vulnerable lockfiles (CVE-2019-10744, CVE-2018-18074, CVE-2020-26160)

curated-resourceseducationlabs-practice+2
3 months ago
CVE-2025-9267 preview

CVE-2025-9267

GitHubtiger3080/cve-2025-9267

Seagate Toolkit for Windows (Installer <2.35.0.6) is vulnerable to insecure DLL loading. The installer loads DLLs from the working directory without…

binary-exploitationexploitationprivilege-escalation+2
11 months ago
React2Shell-CVE-2025-55182-Detector preview

React2Shell-CVE-2025-55182-Detector

GitHubgarethmsheldon/react2shell-cve-2025-55182-detector

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

code-analysisscripting-automationsupply-chain-security+3
18 months ago
react2shell-audit preview

react2shell-audit

GitHubhamm0nz/react2shell-audit

A lightweight, recursive Bash script to detect Next.js and React Server DOM versions vulnerable to CVE-2025-55182 (React2Shell) in local projects.

code-analysisdevsecopseducation+3
18 months ago
ollama preview

ollama

GitHubdannyendortest/ollama

Synthetic demo target for Endor Labs EXPOSURE, tracking CVE-2024-12886 with a deliberately vulnerable dependency and a one-click PR-based fix…

devsecopseducationexploitation+3
3 months ago
Previous12345Next