Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
216 results
ninja-form-exploit preview

ninja-form-exploit

GitHubmadexploits/ninja-form-exploit

CVE-2026-0740

exploitationfuzzinginformation-gathering+3
3
1 month ago
CVE-2020-1938-Tool preview

CVE-2020-1938-Tool

GitHubjust1cep4rtn3r/cve-2020-1938-tool

批量检测幽灵猫漏洞

exploitationinformation-gatheringpenetration-testing+2
36 years ago
CVE-2019-0708 preview

CVE-2019-0708

GitHubskommando/cve-2019-0708

CVE-2019-0708 BlueKeep漏洞批量扫描工具和POC,暂时只有蓝屏。

exploitationinformation-gatheringpenetration-testing+2
26 years ago
CVE-2020-1350 preview

CVE-2020-1350

GitHubgraph-inc/cve-2020-1350

PowerShell-based scanner and mitigator for CVE-2020-1350 (SIGRed) targeting Windows DNS Server vulnerabilities with automated detection and…

exploitationinformation-gatheringpenetration-testing+3
26 years ago
CVE-2025-31324-File-Upload preview

CVE-2025-31324-File-Upload

GitHubnullcult/cve-2025-31324-file-upload

A totally unauthenticated file-upload endpoint in Visual Composer lets anyone drop arbitrary files (e.g., a JSP web-shell) onto the server.

exploitationpenetration-testingred-teaming+2
21 year ago
gocropalypse preview

gocropalypse

GitHubnotaswe/gocropalypse

CVE-2023-21036 detection in Go

data-recoverydigital-forensicsforensics+2
13 years ago
Automated-scanner-CVE-2026-41940 preview

Automated-scanner-CVE-2026-41940

GitHubsardine-web/automated-scanner-cve-2026-41940

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

authentication-authorizationcommand-and-controlexploitation+8
13 months ago
CVE-2025-30208-ViteVulnScanner preview

CVE-2025-30208-ViteVulnScanner

GitHubkeklick1337/cve-2025-30208-vitevulnscanner

CVE-2025-30208 ViteVulnScanner

exploitationinformation-gatheringpenetration-testing+3
11 year ago
Ashwesker-CVE-2025-52691 preview

Ashwesker-CVE-2025-52691

GitHubmohammadzarnian1357/ashwesker-cve-2025-52691

CVE-2025-52691

exploitationpenetration-testingred-teaming+3
8 months ago
CVE-2023-34960 preview

CVE-2023-34960

GitHubyongye-security/cve-2023-34960

Chamilo CVE-2023-34960 Batch scan/exploit

command-and-controlexploitationvulnerability-scanners+1
3 years ago
vuln-CVE-2022-41082 preview

vuln-CVE-2022-41082

GitHubnotareaperbutdr34p3r/vuln-cve-2022-41082

https & http

exploitationnetwork-securitypenetration-testing+3
3 years ago
py-log4shellscanner preview

py-log4shellscanner

GitHubscheibling/py-log4shellscanner

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

dns-analysisexploitationfuzzing+3
4 years ago
cPanelSniper preview

cPanelSniper

GitHubzwanski2019/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
3 months ago
cPanelSniper preview

cPanelSniper

GitHubynsmroztas/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4944 months ago
smart-tree preview

smart-tree

GitHub8b-is/smart-tree

Smart Tree: not just a tree, a philosophy. A context-aware, AI-crafted replacement for 20+ tools with MEM8 quantum compression, semantic search,…

curated-resourceseducationgeneral-purpose-utilities+3
2661 month ago
IntruderPayloads preview

IntruderPayloads

GitHub1n3/intruderpayloads

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

curated-resourceseducationfuzzing+3
4.0k4 years ago
BurpSuite-collections preview

BurpSuite-collections

GitHubmr-xn/burpsuite-collections

有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using…

curated-resourceseducationpenetration-testing+2
4.0k15 days ago
cariddi preview

cariddi

GitHubedoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

crawlerinformation-gatheringosint+4
3.8k1 month ago
Previous1…101112Next