Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
898 results
CertVerify preview

CertVerify

GitHubpassword123456/certverify

A scanner that files with compromised or untrusted code signing certificates written in python.

code-analysisforensicsmalware-analysis+1
65
3 years ago
HBSQLI preview

HBSQLI

GitHubsapt01/hbsqli

Automated Tool for Testing Header Based Blind SQL Injection

penetration-testingvulnerability-scannersweb-security
3293 years ago
bfac preview

bfac

GitHubmazen160/bfac

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

information-gatheringreconnaissancevulnerability-scanners+1
5624 years ago
Config-Exploiter preview

Config-Exploiter

GitHubcyb0r9/config-exploiter

Automated tool to dump config.php files from vulnerable Joomla and WordPress websites using known exploit modules (com_joomanager, revslider).

information-gatheringvulnerability-scannersweb-application-exploitation
397 years ago
metateta preview

metateta

GitHubsafebuffer/metateta

Automated network protocol scanner and exploiter leveraging Metasploit modules for rapid penetration testing across large networks, supporting SMB,…

exploit-frameworksnetwork-securitypenetration-testing-frameworks+1
848 years ago
autowpscan preview

autowpscan

GitHubpassword123456/autowpscan

Automated WordPress vulnerability scanner that processes multiple sites concurrently using wpscan, analyzes results, and sends summaries via Telegram.

information-gatheringvulnerability-scannersweb-security
13 years ago
CVE-2019-12102-Scanner preview

CVE-2019-12102-Scanner

GitHubegi08/cve-2019-12102-scanner

Automated scanner for CVE-2019-12102 unauthenticated file upload vulnerability in Kentico CMS. Checks domains, verifies with hash parameter, and…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubxuemian168/cve-2025-30208

全网首发 CVE-2025-31125 CVE-2025-30208 CVE-2025-32395 Vite Scanner

exploitationinformation-gatheringreconnaissance+3
481 year ago
ICG-AutoExploiterBoT preview

ICG-AutoExploiterBoT

GitHubio1337/icg-autoexploiterbot

Automated exploitation tool targeting CMS vulnerabilities in Joomla, WordPress, Drupal, PrestaShop, and OsCommerce with built-in brute-force and…

exploitationpenetration-testingvulnerability-scanners+1
128 years ago
CVE-2025-55182-poc-tool preview

CVE-2025-55182-poc-tool

GitHubdh4v4l8/cve-2025-55182-poc-tool

Automated exploit tool for CVE-2025-55182 in Next.js React Server Components. Enables remote command execution with built-in WAF bypass, custom…

exploitationpenetration-testingremote-access-tool+3
39 months ago
Xerror preview

Xerror

GitHubchudry/xerror

fully automated pentesting tool

exploitationexploit-frameworkspenetration-testing+3
5165 years ago
JQShell preview

JQShell

GitHubstahlz/jqshell

Automated exploit tool for CVE-2018-9206 (jQuery File Upload) with single/multi-target scanning, Tor proxy support, and output logging for…

educationexploitationpenetration-testing+2
627 years ago
AcuAutomate preview

AcuAutomate

GitHubdanialhalo/acuautomate

Unofficial Acunetix CLI tool for automated pentesting and bug hunting across large scopes.

api-security-testingpenetration-testingvulnerability-scanners+1
872 years ago
DakshSCRA preview

DakshSCRA

GitHubcoffeeandsecurity/dakshscra

Framework-aware static code analysis tool for automated source code review with platform-specific rules, taint analysis, effort estimation, and…

code-analysisdevsecopseducation+7
4513 days ago
CVE-2026-23869-Exploit preview

CVE-2026-23869-Exploit

GitHubcybertechajju/cve-2026-23869-exploit

Automated exploit tool for CVE-2026-23869, a remote DoS in React Server Components. Includes PoC, Nuclei template, and scanning scripts for detection…

exploitationpenetration-testingreconnaissance+3
84 months ago
CVE-2026-1357-POC preview

CVE-2026-1357-POC

GitHubcybertechajju/cve-2026-1357-poc

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

data-exfiltrationexploitationpenetration-testing+5
96 months ago
React2shell-ultimate-scanner preview

React2shell-ultimate-scanner

GitHubcyberprince-hub/react2shell-ultimate-scanner

CVE-2025-55182-Advanced-Scanner is an automated security tool designed to detect and validate the CVE-2025-55182 vulnerability efficiently. it helps…

educationexploitationpenetration-testing+3
8 months ago
-CVE-2024-3094-Vulnerability-Checker-Fixer-Public preview

-CVE-2024-3094-Vulnerability-Checker-Fixer-Public

GitHubtitus-soc/-cve-2024-3094-vulnerability-checker-fixer-public

A lightweight utility designed to detect and remediate systems affected by CVE-2024-3094, a critical vulnerability impacting [insert affected…

configuration-auditingdevsecopsincident-response+3
11 months ago
Previous12…50Next