Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
215 results
OllamaHound preview

OllamaHound

GitHub7h30th3r0n3/ollamahound

Mass reconnaissance, version fingerprinting, CVE tester and live exploitation framework for Ollama open instances.

command-and-controlexploitationinformation-gathering+6
62
7 months ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubal1ex/cve-2022-1388

CVE-2022-1388 F5 BIG-IP iControl REST RCE

command-and-controlexploitationpenetration-testing+3
374 years ago
rschunter preview

rschunter

GitHubsumanrox/rschunter

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

command-and-controlexploitationpenetration-testing+3
379 months ago
FortiSandbox-RCE-Exploit-CVE-2026-39808 preview

FortiSandbox-RCE-Exploit-CVE-2026-39808

GitHubynsmroztas/fortisandbox-rce-exploit-cve-2026-39808

Unauthenticated RCE scanner for FortiSandbox CVE-2026-39808 with canary-based verification, command execution, and pipeline integration for mass…

command-and-controlexploitationpenetration-testing+3
265 months ago
php-cgi-Injector preview

php-cgi-Injector

GitHubnight-have-dreams/php-cgi-injector

一個測試CVE-2024-4577和CVE-2024-8926的安全滲透工具

command-and-controlexploitationpayload-generation+4
521 year ago
CVE-2025-34085-Multi-target preview

CVE-2025-34085-Multi-target

GitHubill-deed/cve-2025-34085-multi-target

Multi-target unauthenticated RCE scanner for CVE-2025-34085 affecting WordPress Simple File List plugin. Uploads, renames, and triggers PHP webshells…

command-and-controlexploitationpayload-generation+5
341 year ago
CVE-2026-65643-PoC-Toolkit preview

CVE-2026-65643-PoC-Toolkit

GitHubtc4dy/cve-2026-65643-poc-toolkit

Red/Blue team toolkit for CVE-2026-65643, a cPanel domain parking RCE. Includes exploit with reverse shell, webshell, persistence, and mass scanning,…

command-and-controlexploitationpayload-development+7
1223 days ago
CVE-2026-44825-Apache-Solr-Scanner preview

CVE-2026-44825-Apache-Solr-Scanner

GitHubgagaltotal/cve-2026-44825-apache-solr-scanner

Apache Solr instances that may be affected by CVE-2026-44825, related to Velocity Template Remote Code Execution (RCE) conditions.

command-and-controlexploitationpenetration-testing+3
122 months ago
Struts-Apache-ExploitPack preview

Struts-Apache-ExploitPack

GitHubret2jazzy/struts-apache-exploitpack

These are just some script which you can use to detect and exploit the Apache Struts Vulnerability (CVE-2017-5638)

command-and-controlexploitationpenetration-testing+3
169 years ago
R2C-CVE-2025-55182-66478 preview

R2C-CVE-2025-55182-66478

GitHubcybertechajju/r2c-cve-2025-55182-66478

🔥 React2Shell Toolkit - CVE-2025-55182 & CVE-2025-66478

command-and-controleducationexploitation+8
249 months ago
watchTowr-vs-FortiSIEM-CVE-2025-25256 preview

watchTowr-vs-FortiSIEM-CVE-2025-25256

GitHubwatchtowrlabs/watchtowr-vs-fortisiem-cve-2025-25256

Detection artifact generator for FortiSIEM CVE-2025-25256 unauthenticated remote command execution vulnerability. Sends crafted packets to verify…

command-and-controlexploitationpenetration-testing+3
191 year ago
Next.js-RCE-Scanner-BurpSuite-Extension- preview

Next.js-RCE-Scanner-BurpSuite-Extension-

GitHubcr4at0r/next.js-rce-scanner-burpsuite-extension-

使用burp自动检测CVE-2025-55182 Next.js RCE 漏洞

command-and-controlexploitationpayload-generation+3
289 months ago
CVE-2022-22954 preview

CVE-2022-22954

GitHubjax7sec/cve-2022-22954

提供批量扫描URL以及执行命令功能。Workspace ONE Access 模板注入漏洞,可执行任意代码

command-and-controlexploitationpenetration-testing+2
124 years ago
hideNsneak preview

hideNsneak

GitHubrmikehodges/hidensneak

a CLI for ephemeral penetration testing

cloud-securitycommand-and-controlpayload-generation+5
186 years ago
strutsy preview

strutsy

GitHubtahmed11/strutsy

Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability

command-and-controlexploitationinformation-gathering+3
108 years ago
ConfluentPwn preview

ConfluentPwn

GitHubredhuntlabs/confluentpwn

Atlassian confluence unauthenticated ONGL injection remote code execution scanner (CVE-2022-26134).

command-and-controlexploitationpenetration-testing+3
121 year ago
SkillsGuard preview

SkillsGuard

GitHubteycir/skillsguard

Static security scanner for AI agent skill packages. Detects malicious SKILL.md files and bundled scripts before they run.

ai-securitycode-analysiscommand-and-control+8
153 months ago
CVE-2026-82329-JFrog-Artifactory-Auth-Bypass preview

CVE-2026-82329-JFrog-Artifactory-Auth-Bypass

GitHubynsmroztas/cve-2026-82329-jfrog-artifactory-auth-bypass

Exploit for CVE-2026-82329, an unauthenticated auth bypass in self-hosted JFrog Artifactory, allowing admin token takeover via blank join key.

authentication-authorizationexploitationpenetration-testing+2
625 days ago
Previous1…456…12Next