Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
Hundred OSINT preview

Hundred OSINT

GitLabt-beckett/h-osint

Local-first, keyboard-driven OSINT workbench for the terminal with 28 modules covering username, domain, IP, email, breach, and geolocation lookups…

dns-analysiseducationemail-harvesting+7
9 days ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

exploitationphishingreconnaissance+2
12 days ago
POC-CVE-2026-54121-Certighost preview

POC-CVE-2026-54121-Certighost

GitHubsam00/poc-cve-2026-54121-certighost

Exploit toolkit for AD CS CVE-2026-54121: low-privileged domain users impersonate a Domain Controller, forge certificates, and compromise the domain…

exploitationimpersonation-toolspenetration-testing+5
1 month ago
CVE-2025-51586-PrestaShop-PoC preview

CVE-2025-51586-PrestaShop-PoC

GitHub7h30th3r0n3/cve-2025-51586-prestashop-poc

PrestaShop AdminLogin Email Enumeration PoC - CVE-2025-51586. This repository provides an ethical Proof-of-Concept (PoC) for the PrestaShop…

exploitationinformation-gatheringpenetration-testing+3
110 months ago
ninja-forms-brute preview

ninja-forms-brute

GitHubrandomrobbiebf/ninja-forms-brute

Exploit for Ninja Forms plugin vulnerability allowing unauthenticated download of submission CSVs to disclose email addresses.

information-gatheringvulnerability-analysisweb-application-exploitation
4 years ago
OutlookLeakTest preview

OutlookLeakTest

GitHubnccgroup/outlookleaktest

The Outlook HTML Leak Test Project

data-exfiltrationemail-securityinformation-gathering+5
1298 years ago
smtp_userenum preview

smtp_userenum

GitHubh3x0v3rl0rd/smtp_userenum

Python script for enumerating SMTP users by leveraging VRFY and EXPN commands to identify valid email accounts on a target mail server.

email-harvestingemail-securityinformation-gathering+4
1 year ago
exchange-scanner preview

exchange-scanner

GitHubbishopfox/exchange-scanner

Identify public-facing Microsoft Exchange servers and determine their software versions

email-securityinformation-gatheringreconnaissance+3
23 months ago
CVE-2024-2876 preview

CVE-2024-2876

GitHubkernel364/cve-2024-2876

Proof-of-concept exploit for a critical SQL injection vulnerability in WordPress Email Subscribers plugin. Includes exploitation details, HTTP…

exploitationreconnaissancevulnerability-analysis+1
21 year ago
CVE-2019-9053-exploit preview

CVE-2019-9053-exploit

GitHubjeanback1/cve-2019-9053-exploit

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

exploitationinformation-gatheringpassword-cracking+3
3 months ago
CVE-2016-10033 preview

CVE-2016-10033

GitHubblue-chocolates/cve-2016-10033

Exploit for CVE-2016-10033, a remote code execution vulnerability in PHPMailer, enabling unauthenticated attackers to execute arbitrary code via…

exploitationinformation-gatheringpenetration-testing+2
1 month ago
CVE-2026-XXXX-atlassian-email-enumeration preview

CVE-2026-XXXX-atlassian-email-enumeration

GitHubwh4l3x/cve-2026-xxxx-atlassian-email-enumeration

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

email-harvestinginformation-gatheringosint+5
12 months ago
Blackash-CVE-2025-20393 preview

Blackash-CVE-2025-20393

GitHubredpack-kr/blackash-cve-2025-20393

CVE-2025-20393

exploitationinformation-gatheringpenetration-testing+3
9 months ago
sentryexploit preview

sentryexploit

GitHubleakix/sentryexploit

CVE-2023-38035 Recon oriented exploit, extract company name contact information

exploitationinformation-gatheringreconnaissance+2
73 years ago
CVE-2026-54390 preview

CVE-2026-54390

GitHubshinthink/cve-2026-54390

CVE-2026-54390 — JTL Shop Smarty SSTI RCE | Pre-Auth Template Injection via fetch('string:' . ) | 5.2.0-5.7.1

exploitationpenetration-testingreconnaissance+2
2 months ago
CVE-2025-8422 preview

CVE-2025-8422

GitHubrandomrobbiebf/cve-2025-8422

Propovoice <= 1.7.6.7 - Unauthenticated Arbitrary File Read

exploitationinformation-gatheringpenetration-testing+2
11 months ago
CVE-2024-0235-PoC preview

CVE-2024-0235-PoC

GitHubnxploited/cve-2024-0235-poc

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2023-5561-POC-Updated preview

CVE-2023-5561-POC-Updated

GitHubrootxsushant/cve-2023-5561-poc-updated

Updated POC for Unauth Post Author Email Disclosures WordPress CVE-2023-5561

exploitationinformation-gatheringpenetration-testing+2
31 year ago
Previous1234Next