Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
65 results
DIY_WhisperPair preview

DIY_WhisperPair

GitHubspectrixdev/diy_whisperpair

Hijacking Bluetooth Accessories Using Google Fast Pair: WhisperPair CVE-2025-36911 Reference Implementation & Vulnerability Verification Toolkit

bluetooth-securityeducationexploitation+5
105
3 months ago
Magneto-PolyShell preview

Magneto-PolyShell

GitHubjenderal92/magneto-polyshell

Magento 2 Unauthenticated RCE Exploit – Uploads a PHP webshell via GraphQL product lookup + guest cart custom options. Multi‑threaded, auto‑detects…

exploitationpayload-generationpenetration-testing+3
3 months ago
capture-the-flag preview

capture-the-flag

GitHubctf-o-matic/capture-the-flag

Helper scripts to remaster Linux Live CD images for the purpose of creating ready to use security wargames with pre-installed vulnerabilities to…

ctfeducationexploitation+3
527 years ago
rikune preview

rikune

GitHublast-emo-boy/rikune

MCP server for reverse engineering Windows executables and binary formats. Combines static triage, Ghidra-assisted function recovery, plugin-driven…

binary-analysisdynamic-analysis-sandboxingeducation+8
2388 days ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
13 months ago
cynative preview

cynative

GitHubcynative/cynative

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

ai-securitycloud-securitycontainer-security+7
19515h 4m ago
CVE-2024-7954 preview

CVE-2024-7954

GitHubr0otk3r/cve-2024-7954

Unauthenticated remote command execution exploit for SPIP CMS 4.2.8 (CVE-2024-7954) with proxy support and live output retrieval.

educationexploitationpenetration-testing+3
1 year ago
XM_ONVIF_auth_bypass preview

XM_ONVIF_auth_bypass

GitHubkostasereksonas/xm_onvif_auth_bypass

Proof-of-concept code (Bash and Python) for CVE-2025-65856 where ONVIF implementation in in Xiongmai XM530 IP cameras allows for unauthenticated …

exploitationhardware-iot-securityiot-security+3
26 months ago
CVE-2025-66956 preview

CVE-2025-66956

GitHubthewoodenbench/cve-2025-66956

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute…

exploitationinformation-gatheringreconnaissance+2
7 months ago
CVE-2025-66955 preview

CVE-2025-66955

GitHubthewoodenbench/cve-2025-66955

Local File Inclusion in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote authenticated users to access files on the…

exploitationinformation-gatheringpenetration-testing+2
8 months ago
CVE-2020-24088 preview

CVE-2020-24088

GitHubrjt-gupta/cve-2020-24088

Windows Privilege Escalation: Foxconn Live Update Utility v2.1.6.26

binary-exploitationexploitationprivilege-escalation+1
2 years ago
CVE-2025-51400 preview

CVE-2025-51400

GitHubthewhiteevil/cve-2025-51400

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Personal Canned Messages # Date: 09/06/2025

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-51398 preview

CVE-2025-51398

GitHubthewhiteevil/cve-2025-51398

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Facebook Integration Page Name Field

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-51397 preview

CVE-2025-51397

GitHubthewhiteevil/cve-2025-51397

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Operator Surname

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2025-51396 preview

CVE-2025-51396

GitHubthewhiteevil/cve-2025-51396

LiveHelperChat <=4.61 - Stored Cross Site Scripting (XSS) via Telegram Bot Username

exploitationinformation-gatheringpenetration-testing+3
11 year ago
wireshark-forensics-plugin preview

wireshark-forensics-plugin

GitHubrjbhide/wireshark-forensics-plugin

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

digital-forensicsforensicsnetwork-forensics+3
1024 years ago
CVE-2026-47858 preview

CVE-2026-47858

GitHubrealstatus/cve-2026-47858

Proof-of-concept exploit for unauthenticated JMX RCE in Spring Tools live information mode, using MLet remote class loading to execute arbitrary…

exploitationpayload-generationpenetration-testing+1
14 days ago
nextjs-rce-incident-response preview

nextjs-rce-incident-response

GitHubrewantchaudhari/nextjs-rce-incident-response

Real-world incident response for CVE-2025-55182 (React2Shell) — script injection, server remediation, and post-incident report

educationforensicsincident-response+2
4 months ago
Previous1234Next