Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
216 results
CVE-2020-17453 preview

CVE-2020-17453

GitHubkarthi-the-hacker/cve-2020-17453

CLI scanner for CVE-2020-17453 that tests single or multiple URLs for the vulnerability, designed for bug bounty hunters and penetration testers.

information-gatheringpenetration-testingvulnerability-scanners+2
5
3 years ago
CVE-2021-21972 preview

CVE-2021-21972

GitHubhurrrraaaa/cve-2021-21972

Isolated lab research writeup for VMware vCenter Server CVE-2021-21972, covering unauthenticated arbitrary file upload to RCE, Nmap-based detection,…

educationexploitationlabs-practice+4
27 days ago
cve-2019-7192-check preview

cve-2019-7192-check

GitHubcycraft-corp/cve-2019-7192-check

Checker for QNAP pre-auth root RCE (CVE-2019-7192 ~ CVE-2019-7195)

exploitationpenetration-testingreconnaissance+2
135 years ago
npm-tar-path-traversal-scanner preview

npm-tar-path-traversal-scanner

GitHubridhinva/npm-tar-path-traversal-scanner

Scanner: CVE-2026-31802 npm tar path traversal — Python checker for arbitrary file write via npm pack

code-analysiseducationstatic-analysis+2
22 days ago
Email-Vulnerability-Checker preview

Email-Vulnerability-Checker

GitHubblack-scorp10/email-vulnerability-checker

Automated SPF and DMARC configuration checker that identifies email spoofing vulnerabilities across single or bulk domains using DNS lookups.

dns-analysisemail-securityinformation-gathering+1
972 years ago
CVE-2024-6387-Vulnerability-Checker preview

CVE-2024-6387-Vulnerability-Checker

GitHubfilipi86/cve-2024-6387-vulnerability-checker

This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports.…

exploitationnetwork-securityvulnerability-scanners
1022 years ago
CVE-2024-6387-Vulnerability-Checker preview

CVE-2024-6387-Vulnerability-Checker

GitHubidentity-threat-labs/cve-2024-6387-vulnerability-checker

This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports.…

exploitationinformation-gatheringnetwork-security+3
22 years ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubthemehackers/cve-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

exploitationinformation-gatheringpayload-generation+3
101 year ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubth-secforge/cve-2025-30208

CVE‑2025‑30208 is a medium-severity arbitrary file read vulnerability in the Vite development server (a popular frontend build tool)

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2020-35489 preview

CVE-2020-35489

GitHubcappricio-securities/cve-2020-35489

WordPress Contact Form 7 - Unrestricted File Upload

exploitationinformation-gatheringpenetration-testing+3
22 years ago
CVE-2020-3452 preview

CVE-2020-3452

GitHubcappricio-securities/cve-2020-3452

Cisco Adaptive Security Appliance (ASA)/Firepower Threat Defense (FTD) - Local File Inclusion

exploitationinformation-gatheringreconnaissance+3
12 years ago
CVE-2024-0352 preview

CVE-2024-0352

GitHubcappricio-securities/cve-2024-0352

Likeshop < 2.5.7.20210311 - Arbitrary File Upload

exploitationinformation-gatheringpenetration-testing+3
2 years ago
CVE-2019-5418 preview

CVE-2019-5418

GitHubrandom-robbie/cve-2019-5418

Go-based scanner for CVE-2019-5418 (Ruby on Rails file disclosure) that reads a list of websites and tests for the vulnerability using a burl-derived…

exploitationpenetration-testingvulnerability-scanners+2
56 years ago
smartermail-cve-scanner preview

smartermail-cve-scanner

GitHubnxgn-kd01/smartermail-cve-scanner

CVE-2025-52691 Scanner - Detects vulnerable SmarterMail installations (CVSS 10.0 RCE)

exploitationinformation-gatheringpenetration-testing+3
17 months ago
MSAPer preview

MSAPer

GitHubim-hanzou/msaper

Automatic Mass Tool for check and exploiting vulnerability in CVE-2023-3076 - MStore API < 3.9.9 - Unauthenticated Privilege Escalation (Mass Add…

exploitationprivilege-escalationvulnerability-scanners+1
162 years ago
JBWPer preview

JBWPer

GitHubim-hanzou/jbwper

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4061 - JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload

exploitationpayload-generationshellcode+2
52 years ago
WooRefer preview

WooRefer

GitHubim-hanzou/woorefer

Automatic Mass Tool for check and exploiting vulnerability in CVE-2022-4047 - Return Refund and Exchange For WooCommerce < 4.0.9 - Unauthenticated…

exploitationvulnerability-scannersweb-application-exploitation
12 years ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubpxxdrobits/cve-2025-49132

Check a list of Pterodactyl panels for vulnerabilities from a file.

exploitationinformation-gatheringosint+3
211 months ago
Previous1…345…12Next