Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
226 results
cve-2026-33067 preview

cve-2026-33067

GitHublopseg/cve-2026-33067

Nuclei template for detecting CVE-2026-33017, an unauthenticated remote code execution vulnerability in Langflow ≤ 1.8.2. Performs non-destructive…

exploitationpenetration-testingreconnaissance+3
3 months ago
Ghost-CMS-Code-Injection-Audit-CVE-2026-26980 preview

Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

GitHubkulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

code-analysisdefensive-toolsincident-response+3
3 months ago
shai-scan preview

shai-scan

GitHubdigi4care/shai-scan

Zero-dependency CLI scanner for npm/PyPI supply chain compromises. Detects compromised packages in lockfiles and system-level IOCs from attacks like…

code-analysisdevsecopsincident-response+6
3 months ago
CVE-2019-19781 preview

CVE-2019-19781

GitHubandripwn/cve-2019-19781

Citrix ADC scanner (CVE-2019-19781) using hosts retrieved from Shodan API.

exploitationinformation-gatheringpenetration-testing+3
26 years ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubpxxdrobits/cve-2025-49132

Check a list of Pterodactyl panels for vulnerabilities from a file.

exploitationinformation-gatheringosint+3
211 months ago
CVE-2023-6000 preview

CVE-2023-6000

GitHubrxerium/cve-2023-6000

The Popup Builder WordPress plugin before 4.2.3 does not prevent simple visitors from updating existing popups, and injecting raw JavaScript in them,…

educationpenetration-testingvulnerability-scanners+2
210 months ago
ProxySqlMap preview

ProxySqlMap

GitHubianxtianxt/proxysqlmap

From Proxy to SqlMapApi

penetration-testingvulnerability-scannersweb-application-exploitation+2
16 years ago
CVE-2024-6387-Vulnerability-Checker preview

CVE-2024-6387-Vulnerability-Checker

GitHubidentity-threat-labs/cve-2024-6387-vulnerability-checker

This Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports.…

exploitationinformation-gatheringnetwork-security+3
21 year ago
Optimum preview

Optimum

GitHubr3fr4kt/optimum

Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain…

educationexploitationinformation-gathering+7
5 months ago
S3-from-csp preview

S3-from-csp

GitHubrandomrobbiebf/s3-from-csp

Extracts all S3 Buckets from CSP report headers and then tests for file upload vulns

cloud-infrastructure-securitycloud-securityinformation-gathering+2
13 years ago
CVE-2023-29489.py preview

CVE-2023-29489.py

GitHubipk1/cve-2023-29489.py

a pyhton script to test all results from shodan for cPanel CVE-2023-29489, credits to @assetnote, I just automate

exploitationinformation-gatheringreconnaissance+2
23 years ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubrbctee/cve-2025-53770

Scanner for the SharePoint CVE-2025-53770 RCE zero day vulnerability (fork from hazcod/CVE-2025-53770)

exploitationinformation-gatheringpenetration-testing+3
16 months ago
CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner preview

CYBERDUDEBIVASH-FortiSIEM-CVE-2025-64155-Scanner

GitHubcyberdudebivash/cyberdudebivash-fortisiem-cve-2025-64155-scanner

Authorized high-impact tool from CYBERDUDEBIVASH ECOSYSTEM to detect CVE-2025-64155 (FortiSIEM phMonitor Command Injection). Scans for open ports and…

command-and-controlexploitationpenetration-testing+3
17 months ago
CVE-2024-3094-Checker preview

CVE-2024-3094-Checker

GitHubiheb2b/cve-2024-3094-checker

The CVE-2024-3094 Checker is a Bash tool for identifying if Linux systems are at risk from the CVE-2024-3094 flaw in XZ/LZMA utilities. It checks XZ…

configuration-auditinggeneral-purpose-utilitiesscripting-automation+2
12 years ago
xz-utils-vuln-checker preview

xz-utils-vuln-checker

GitHubharekrishnarai/xz-utils-vuln-checker

Checker for CVE-2024-3094 where malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of…

curated-resourceseducationsupply-chain-security+2
12 years ago
Prober preview

Prober

GitLabisnic/prober

Automated, reproducible network security testing framework using Ansible and BATS to verify DNS, host availability, open ports, and TLS configuration…

configuration-auditingdns-analysisnetwork-security+3
15 years ago
dns_amplification_scanner preview

dns_amplification_scanner

GitHubpcastagnaro/dns_amplification_scanner

This script checks if each domain from a given domain list is vulnerable to CVE-2006-0987

dns-analysisinformation-gatheringnetwork-security+3
11 year ago
cve-2025-22294 preview

cve-2025-22294

GitHubmirmeweu/cve-2025-22294

the task from C*****k

exploitationpenetration-testingvulnerability-analysis+3
10 months ago
Previous1…345…13Next