Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
140 results
MCP-Inspector-CVE-2025-49596 preview

MCP-Inspector-CVE-2025-49596

GitHubashiqrehan-21/mcp-inspector-cve-2025-49596

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

api-security-testingeducationexploitation+3
1 year ago
Open-Worldwide-Application-Security-Project-OWASP- preview

Open-Worldwide-Application-Security-Project-OWASP-

GitHubwaburig/open-worldwide-application-security-project-owasp-

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

educationpenetration-testingvulnerability-analysis+2
8 months ago
raider preview

raider

GitHubowasp/raider

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

api-security-testingauthenticationpenetration-testing+3
1013 years ago
DVSA preview

DVSA

GitHubowasp/dvsa

a Damn Vulnerable Serverless Application

api-security-testingcloud-infrastructure-securitycloud-security+6
5473 years ago
http-desync-guardian preview

http-desync-guardian

GitHubaws/http-desync-guardian

Analyze HTTP requests to minimize risks of HTTP Desync attacks (precursor for HTTP request smuggling/splitting).

api-security-testingstatic-analysisvulnerability-analysis+1
2743 months ago
TProxer preview

TProxer

GitHubethicalhackingplayground/tproxer

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

api-security-testingpenetration-testingvulnerability-analysis+2
1844 years ago
CVE-2023-27532 preview

CVE-2023-27532

GitHubhorizon3ai/cve-2023-27532

Proof-of-concept exploit for CVE-2023-27532 in Veeam Backup and Replication that abuses an unsecured API endpoint to extract credentials from the…

api-security-testingexploitationpenetration-testing+2
743 years ago
Mass-Assigner preview

Mass-Assigner

GitHubsn1r/mass-assigner

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

api-security-testingpenetration-testingvulnerability-analysis+1
182 years ago
svja preview

svja

GitHubtheronielanddaronpodcastshow/svja

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

api-security-testingauthentication-authorizationeducation+5
138 months ago
bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork preview

bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

GitHubhunt-benito/bring-your-own-key-cve-2026-73678-unauthenticated-rce-in-mindsdb-cowork

PoC exploit for CVE-2026-73678: unauthenticated RCE in MindsDB Cowork via attacker-supplied LLM key and unsandboxed scratchpad exec to run OS…

api-security-testingexploitationmisconfiguration+4
1 month ago
zimaos-cve-2026-28286-arbitrary-file-write preview

zimaos-cve-2026-28286-arbitrary-file-write

GitHubrushi9/zimaos-cve-2026-28286-arbitrary-file-write

PoC and verification toolkit for CVE-2026-28286, an arbitrary file write vulnerability in ZimaOS, exploiting API misconfiguration to write files…

api-security-testingexploitationpenetration-testing+3
25 months ago
CVE-2026-46592 preview

CVE-2026-46592

GitHuboscerd/cve-2026-46592

Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a…

api-security-testingeducationexploitation+3
1 month ago
mcp-server preview

mcp-server

GitHuboffensive360/mcp-server

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

api-security-testingcloud-securitycode-analysis+3
1 month ago
CVE-2024-11423 preview

CVE-2024-11423

GitHubrandomrobbiebf/cve-2024-11423

Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

api-security-testingauthentication-authorizationpenetration-testing+2
31 year ago
hello-ReGrade-security preview

hello-ReGrade-security

GitHubcurtail-inc/hello-regrade-security

Find the vulnerability your tests were never written to catch. A ReGrade demo modeling CVE-2023-5968: catch a password-hash leak by comparing an app…

api-security-testingcryptographydynamic-analysis-sandboxing+6
1 month ago
CVE-2025-45809-PoC preview

CVE-2025-45809-PoC

GitHublearner202649/cve-2025-45809-poc

Time-based blind SQL injection proof-of-concept for LiteLLM v1.65.4. Exploits the `/key/block` endpoint to extract database contents and read server…

api-security-testingdatabase-securityeducation+3
3 months ago
CVE-2026-27886 preview

CVE-2026-27886

GitHubevtdanya/cve-2026-27886

Strapi CVE-2026-27886. Leaking sensitive data via relational filtering due to lack of query sanitization

api-security-testingexploitationpenetration-testing+3
3 months ago
CVE-2025-53640 preview

CVE-2025-53640

GitHubrafaelcorvino1/cve-2025-53640

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

api-security-testinginformation-gatheringosint+3
18 months ago
Previous12…8Next