Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
48 results
cve-checker-2026 preview

cve-checker-2026

GitHubsebinxavi/cve-checker-2026

Multi-OS vulnerability checker for CVE-2026-31431 (Linux kernel) and CVE-2026-41940 (cPanel)

configuration-auditingforensicsincident-response+3
1
4 months ago
poc-cpanel-cve-2026-41940 preview

poc-cpanel-cve-2026-41940

GitHubxsanflip/poc-cpanel-cve-2026-41940

Multi-threaded security auditing tool that detects CVE-2026-41940, an authentication bypass in cPanel/WHM, using CRLF injection and dynamic port…

authenticationexploitationinformation-gathering+3
654 months ago
Mass-CVE-2026-23550-Exploit preview

Mass-CVE-2026-23550-Exploit

GitHubdzmind2312/mass-cve-2026-23550-exploit

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

exploitationinformation-gatheringpenetration-testing+3
27 months ago
CVE-2025-61882 preview

CVE-2025-61882

GitHubsachinart/cve-2025-61882

Multi-threaded scanner for CVE-2025-61882 in Oracle E-Business Suite, exploiting HTTP request smuggling to achieve unauthenticated remote code…

exploitationpenetration-testingreconnaissance+3
1111 months ago
giskard-oss preview

giskard-oss

GitHubgiskard-ai/giskard-oss

🐢 Open-Source Evaluation & Testing library for LLM Agents

adversarial-attackai-securityfuzzing+3
5.8k1h 12m ago
vamp-forticheck preview

vamp-forticheck

GitHubvampsecure-labs/vamp-forticheck

VampSecure Labs: FortiOS CVE scanner (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

information-gatheringmisconfigurationnetwork-security+5
8 days ago
INtrack preview

INtrack

GitHubk3ystr0k3r/intrack

A flexible internet crawler used for scanning technologies, instances and vulnerabilities worldwide across the internet.

crawlerexploitationinformation-gathering+7
601 month ago
xpath preview

xpath

GitHubblue0x1/xpath

xpath is a fast, multi-technique XPath injection scanner written in Nim. It focuses on practical detection, response comparison, visible extraction,…

information-gatheringpenetration-testingvulnerability-scanners+3
32 months ago
CVE-2026-4106 preview

CVE-2026-4106

GitHubef3tr/cve-2026-4106

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)

educationexploitationinformation-gathering+6
15 months ago
DeepGuard preview

DeepGuard

GitHubunknownhl/deepguard

Code for ACL 2026 (main) paper "DeepGuard: Secure Code Generation via Multi-Layer Semantic Aggregation"

ai-securitycode-analysiseducation+5
25 months ago
fuckshitup preview

fuckshitup

GitHubsmaash/fuckshitup

php-cli vulnerability scanner

information-gatheringpassword-attackspenetration-testing+2
7911 years ago
rschunter preview

rschunter

GitHubsumanrox/rschunter

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

command-and-controlexploitationpenetration-testing+3
379 months ago
ninja-form-exploit preview

ninja-form-exploit

GitHubmadexploits/ninja-form-exploit

CVE-2026-0740

exploitationfuzzinginformation-gathering+3
32 months ago
heartbleed-masstest preview

heartbleed-masstest

GitHubmusalbas/heartbleed-masstest

Multi-threaded tool for scanning many hosts for CVE-2014-0160.

information-gatheringnetwork-securitypenetration-testing+3
57111 years ago
Get-log4j-Windows.ps1 preview

Get-log4j-Windows.ps1

GitHubkeysau/get-log4j-windows.ps1

Identifying all log4j components across all windows servers, entire domain, can be multi domain. CVE-2021-44228

configuration-auditingincident-responseinformation-gathering+3
74 years ago
CVE-2025-55182-Terminal preview

CVE-2025-55182-Terminal

GitHubmrsol0/cve-2025-55182-terminal

This is a POC for testing your projects that are vulnerable to CVE-2025-55182 with a terminal and ability to scan a list

exploitationpayload-generationpenetration-testing+3
9 months ago
CVE-2022-22954 preview

CVE-2022-22954

GitHubmlx15/cve-2022-22954

CVE-2022-22954 VMware Workspace ONE Access free marker SSTI

command-and-controlexploitationpayload-generation+3
44 years ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
12.0k1 month ago
Previous123Next