Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
advisories preview

advisories

GitHubjustinsteven/advisories

Personal repository of security advisory disclosures covering vulnerabilities in web, cloud, infrastructure, and open-source software.

cloud-securitycurated-resourceseducation+3
271
3 years ago
react2shell-scanner preview

react2shell-scanner

GitHubnxgn-kd01/react2shell-scanner

Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Fast, accurate scanner with zero false positives.

code-analysisdevsecopsexploitation+3
38 months ago
sudowp-hooks-visualizer preview

sudowp-hooks-visualizer

GitHubsudo-wp/sudowp-hooks-visualizer

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

code-analysisdebuggerseducation+4
26 months ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
451 day ago
ship-safe preview

ship-safe

GitHubasamassekou10/ship-safe

The independent security agent for AI-written software. Finds issues, investigates whether they are real, and shows you the evidence. Deterministic…

ai-securityapi-security-testingcloud-infrastructure-security+8
84713h 36m ago
git_rce preview

git_rce

GitHubamalmurali47/git_rce

Exploit PoC for CVE-2024-32002

educationexploitationpayload-development+3
5332 years ago
vulnerable-mcp-servers-lab preview

vulnerable-mcp-servers-lab

GitHubappsecco/vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

ai-securitycode-analysiseducation+7
2779 months ago
mcp-xray preview

mcp-xray

GitHubtraceforce/mcp-xray

Unified security scanner for MCP servers with config, pentest, and repo-scan modes. Generates SARIF reports for CI/CD integration, detects secrets,…

api-security-testingcode-analysisconfiguration-auditing+8
861 month ago
ifuncd-up preview

ifuncd-up

GitHubrobertdfrench/ifuncd-up

GNU IFUNC is the real culprit behind CVE-2024-3094

binary-analysisdynamic-code-analysiseducation+5
604 months ago
FIASSE preview

FIASSE

GitHubowasp/fiasse

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

code-analysiscurated-resourcesdevsecops+7
141 month ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
1811 days ago
GuardScan preview

GuardScan

GitHubntanwir10/guardscan

100% Free & Open Source • Privacy-First Security Scanning and AI Code Review CLI

ai-securityapi-securitycloud-security+8
153 months ago
malicious-devfile-registry preview

malicious-devfile-registry

GitHubdoyensec/malicious-devfile-registry

CVE-2024-0402 exploit for GitLab Workspaces using a malicious Devfile Registry with path-traversal archive to overwrite authorized_keys and gain SSH…

exploitationpenetration-testingred-teaming+3
151 year ago
CVE-2021-26700 preview

CVE-2021-26700

GitHubjackadamson/cve-2021-26700

Proof-of-concept for CVE-2021-26700: remote code execution in the VSCode npm-script extension via malicious workspace settings.json, with detailed…

code-analysiseducationexploitation+3
205 years ago
CVE-2023-51385_test preview

CVE-2023-51385_test

GitHubltmthink/cve-2023-51385_test

一个验证对CVE-2023-51385

educationexploitationsupply-chain-security+2
72 years ago
CVE-2014-4936 preview

CVE-2014-4936

GitHub0x3a/cve-2014-4936

Repository for CVE-2014-4936 POC code.

exploitationpenetration-testingsupply-chain-security+2
711 years ago
CVE-2026-40345 preview

CVE-2026-40345

GitHubjvr2022/cve-2026-40345

Reproduces a stack-exhaustion denial-of-service in deepmerge-ts before 8.0.0, documents exploitation, and includes a scanner for vulnerable…

exploitationsupply-chain-securityvulnerability-analysis+3
61 month ago
react2shell-scanner-rce-react-next-CVE-2025-55182-CVE-2025-66478 preview

react2shell-scanner-rce-react-next-CVE-2025-55182-CVE-2025-66478

GitHubsecurity-phoenix-demo/react2shell-scanner-rce-react-next-cve-2025-55182-cve-2025-66478

Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol…

code-analysiseducationexploitation+6
67 months ago
Previous123Next