Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
148 results
CVE-2025-3248 preview

CVE-2025-3248

GitHubgraysignal/cve-2025-3248

Exploit scanner detecting unauthenticated code injection in Langflow's /api/v1/validate/code endpoint and executing arbitrary code for authorized…

exploitationpenetration-testingvulnerability-analysis+3
1
1 year ago
masq preview

masq

GitLabwattocyber/masq

Live recon and posture auditing for AI agent infrastructure: scans MCP configs, session logs, and APIs for secrets, poisoned catalogs, and CoT leaks.

ai-securityapi-security-testingconfiguration-auditing+6
3 days ago
CVE-2026-17106 preview

CVE-2026-17106

GitHubhackspeak/cve-2026-17106

PoC for Docker `docker cp` arbitrary file write, exploiting symlink and tar extraction flaws to overwrite host binaries or launch agents for…

container-escapecontainer-securityexploitation+3
19 days ago
cloud-middleware-dataset preview

cloud-middleware-dataset

GitHubwiz-sec-public/cloud-middleware-dataset
cloud-infrastructure-securitycloud-securitycurated-resources+2
2492 years ago
CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field preview

CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field

GitHubtheopaid/cve-2026-66421-openclaw-dashboard-stored-xss-via-lastmessage-session-field

Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

ai-securityapi-securityexploitation+3
18 days ago
CVE-2025-12189 preview

CVE-2025-12189

GitHubd0n601/cve-2025-12189

Bread & Butter: Gate content + Capture leads + Collect first-party data + Nurture with Ai agents <= 7.10.1321 - Cross-Site Request Forgery to…

exploitationpayload-generationpenetration-testing+3
9 months ago
google-osconfig-privesc preview

google-osconfig-privesc

GitHubirsl/google-osconfig-privesc

Proof of concept about the privilege escalation flaw identified in Google's Osconfig

cloud-securityexploitationpenetration-testing+4
105 years ago
nCentralDumpsterDiver preview

nCentralDumpsterDiver

GitHubflipfloptech/ncentraldumpsterdiver

This application utilized the Self Registration feature to create a rogue agent that then dumps ApplianceConfiguration settings which may or may not…

exploitationinformation-gatheringpassword-attacks+2
43 years ago
commend_sqli preview

commend_sqli

GitHubjet-pentest/commend_sqli
exploitationpayload-generationpenetration-testing+2
2 years ago
CVE-Wazuh preview

CVE-Wazuh

GitHubhorkimhab/cve-wazuh

Enrolled agent can smuggle arbitrary OpenSearch _bulk operations via DataValue.index. GHSA-ff9g-85jq-r3g3. Draft

api-securityeducationexploitation+3
2 months ago
PHP-8.1.0-dev-Backdoor preview

PHP-8.1.0-dev-Backdoor

GitHubk3ystr0k3r/php-8.1.0-dev-backdoor

PHP 8.1.0-dev User-Agentt Backdoor Remote Code Execution (RCE)

exploitationpayload-developmentsupply-chain-security+3
11 month ago
rails-forensics-CVE-2026-66066 preview

rails-forensics-CVE-2026-66066

GitHubrails/rails-forensics-cve-2026-66066

Forensic toolkit and agent skills for investigating Rails Active Storage/libvips CVE-2026-66066: detects crafted blob indicators, exposure windows,…

data-exfiltrationdigital-forensicseducation+3
2520 days ago
rails-activestorage-vips-audit preview

rails-activestorage-vips-audit

GitHubpaveg/rails-activestorage-vips-audit

Agent skill that audits a Rails codebase for CVE-2026-66066 (KindaRails2Shell) — Active Storage + libvips arbitrary file read / RCE, checking Rails…

configuration-auditingdevsecopseducation+3
22 days ago
CVE-2025-59712_CVE-2025-59713 preview

CVE-2025-59712_CVE-2025-59713

GitHubsynacktiv/cve-2025-59712_cve-2025-59713

Snipe-IT PoC exploit for CVE-2025-59712 and CVE-2025-59713

exploitationpayload-developmentpenetration-testing+3
210 months ago
CVE-2025-6758 preview

CVE-2025-6758

GitHubnxploited/cve-2025-6758

Real Spaces - WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator

exploitationpenetration-testingprivilege-escalation+3
10 months ago
CVE-2020-5148 preview

CVE-2020-5148

GitHubl0lsec/cve-2020-5148

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

authenticationexploitationinformation-gathering+6
26 days ago
exploitgym preview

exploitgym

GitHubsunblaze-ucb/exploitgym

ExploitGym is a large-scale, realistic benchmark built from real-world vulnerabilities designed to evaluate AI agents' ability to develop exploits.

ai-securitybinary-exploitationctf+9
80115 days ago
log4j2-vulnerable-spring-app preview

log4j2-vulnerable-spring-app

GitHubzzzz0317/log4j2-vulnerable-spring-app

CVE-2021-44228

educationexploitationlabs-practice+3
44 years ago
Previous12…9Next