Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
355 results
Adalanche preview

Adalanche

GitHublkarlslund/adalanche

Attack Graph Visualizer and Explorer (Active Directory) ...Who's *really* Domain Admin?

penetration-testingreconnaissancered-teaming+1
2.2k2 days ago
CVE-2026-89055 preview

CVE-2026-89055

GitHubmurrez/cve-2026-89055

Python check/exploit PoC for CVE-2026-89055, an unauthenticated authorization bypass in Customer Reviews for WooCommerce that lets attackers link…

exploitationpenetration-testingreconnaissance+4
5 days ago
CVE-2026-57827 preview

CVE-2026-57827

GitHubcandisexterior171/cve-2026-57827

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

exploitationpenetration-testingreconnaissance+2
6 days ago
tcpdump preview

tcpdump

GitHubthe-tcpdump-group/tcpdump

the TCPdump network dissector

dns-analysisforensicslog-analysis+5
3.2k8 days ago
CVE-2026-88854 preview

CVE-2026-88854

GitHubmurrez/cve-2026-88854

Python 3 PoC scanner and exploit for CVE-2026-88854, an unauthenticated SQL injection in OrdaSoft Joomla Gallery, with mass check and EXTRACTVALUE…

exploitationpenetration-testingreconnaissance+4
39 days ago
CVE-2026-84434 preview

CVE-2026-84434

GitHubmurrez/cve-2026-84434

Python PoC scanner and exploit for CVE-2026-84434, an unauthenticated arbitrary file upload in Gravity Forms <=3.1.0.4 via hidden File Upload fields.…

exploitationpenetration-testingreconnaissance+5
10 days ago
devin-cve48384-1789318364-1162143-parent preview

devin-cve48384-1789318364-1162143-parent

GitHubfishjojo1/devin-cve48384-1789318364-1162143-parent

Authorized reachability probe for CVE-2025-48384, used to verify whether a target is exposed to the vulnerability in a controlled testing context.

exploitationpenetration-testingreconnaissance+2
16 days ago
nuclei-CVE-2025-24813 preview

nuclei-CVE-2025-24813

GitHubsebastianmautner/nuclei-cve-2025-24813

University Project of developing a template for safely testing for the CVE 2025-24813 on a server. It is intentionally made to not leave any lasting…

exploitationpenetration-testingreconnaissance+4
17 days ago
openfire-ssrf-cve-2019-18394 preview

openfire-ssrf-cve-2019-18394

GitHubl0lsec/openfire-ssrf-cve-2019-18394

PoC for CVE-2019-18394: unauthenticated full-read SSRF in Openfire <= 4.4.2 FaviconServlet

exploitationpenetration-testingreconnaissance+4
20 days ago
CVE-2026-34160 preview

CVE-2026-34160

GitHubromain-deperne/cve-2026-34160

Unauthenticated SSRF in the Chamilo LMS PENS plugin — CVE-2026-34160 / CVSS 8.6

exploitationpenetration-testingreconnaissance+3
22 days ago
CVE-2026-33715 preview

CVE-2026-33715

GitHubromain-deperne/cve-2026-33715

Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

exploitationphishingreconnaissance+2
22 days ago
RPC-Triage preview

RPC-Triage

GitHubtalha-nazeef-ahmed/rpc-triage

A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model.

binary-analysisreconnaissancered-teaming+3
141 month ago
teamcity-CVE-2026-63077-pcap preview

teamcity-CVE-2026-63077-pcap

GitHubboredhackerblog/teamcity-cve-2026-63077-pcap

teamcity teamcity-CVE-2026-63077 exploitation pcap

exploitationintrusion-detectionnetwork-security+2
1 month ago
CVE-2026-60004-poc-gitea preview

CVE-2026-60004-poc-gitea

GitHubgagaltotal/cve-2026-60004-poc-gitea

CVE-2026-60004 — Gitea Pre-Auth RCE via diffpatch hook injection

exploitationpenetration-testingreconnaissance+3
21 month ago
ghe-push-option-rce-scanner preview

ghe-push-option-rce-scanner

GitHubridhinva/ghe-push-option-rce-scanner

Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

penetration-testingreconnaissancered-teaming+4
1 month ago
wp2shell-rce preview

wp2shell-rce

GitHubjohnlodan/wp2shell-rce

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

penetration-testingreconnaissancevulnerability-analysis+4
31 month ago
CVE-2026-66066 preview

CVE-2026-66066

GitHubshinthink/cve-2026-66066

CVE-2026-66066 — KindaRails2Shell: Rails Active Storage/libvips Arbitrary File Read → RCE. MATLAB/HDF5 dual-identity file → SECRET_KEY_BASE theft →…

exploitationpenetration-testingreconnaissance+3
11 month ago
CVE-2021-22986_Check preview
Archived

CVE-2021-22986_Check

GitHubzephrfish/cve-2021-22986_check

CVE-2021-22986 Checker Script in Python3

exploitationpenetration-testingreconnaissance+2
32 months ago
Previous12…20Next