Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
530 results
WSOB preview

WSOB

GitHubdsssssssm/wsob

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

exploitationpenetration-testingred-teaming+2
26
3 years ago
CVE-2021-41773 preview

CVE-2021-41773

GitHubmauricelambert/cve-2021-41773

Multi-language exploit and detection scripts for CVE-2021-41773, enabling remote code execution and local file disclosure on vulnerable Apache…

exploitationinformation-gatheringpenetration-testing+3
14 years ago
Ghost-CMS-Code-Injection-Audit-CVE-2026-26980 preview

Ghost-CMS-Code-Injection-Audit-CVE-2026-26980

GitHubkulik-labs-development/ghost-cms-code-injection-audit-cve-2026-26980

Outdated Ghost CMS websites that have fallen become compromised from CVE-2026-26980 can suffer from spam code injection to pages. Use this to mass…

code-analysisdefensive-toolsincident-response+3
1 month ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubr0otk3r/cve-2024-4577

Scanner and exploit tool for CVE-2024-4577, a PHP CGI argument injection vulnerability enabling remote code execution on Windows systems. Includes…

command-and-controleducationexploitation+3
1 year ago
CVE-2023-21887 preview

CVE-2023-21887

GitHubzwxxb/cve-2023-21887

Scans a list of URLs for CVE-2023-46805 and exploits CVE-2023-21887 to achieve remote code execution on Ivanti products.

exploitationpenetration-testingreconnaissance+2
22 years ago
CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX preview

CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX

GitHubbimboxh4/cve-2025-66039_cve-2025-61675_cve-2025-61678_reepbx

This vulnerability allows both authenticated and unauthenticated remote attackers to execute remote code on vulnerable FreePBX instances. These…

authenticationeducationexploitation+3
19 months ago
dawnscanner preview

dawnscanner

GitHubthesp0nge/dawnscanner

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

code-analysisstatic-analysisvulnerability-scanners+1
7492 years ago
pulledpork preview

pulledpork

GitHubshirkdog/pulledpork

Pulled Pork for Snort and Suricata rule management (from Google code)

configuration-auditingintrusion-detectionnetwork-security+2
4405 years ago
Bughound preview

Bughound

GitHubmhaskar/bughound

Static code analysis tool based on Elasticsearch

code-analysisdevsecopsstatic-code-analysis+2
1305 years ago
melee preview

melee

GitHubadityaks/melee

Python-based tool to detect ransomware infections and malicious code in MySQL instances. Performs reconnaissance, user enumeration, and deep scans…

database-securityincident-responsemalware-analysis+2
233 years ago
CVE-2024-3094-check preview

CVE-2024-3094-check

GitHubwgetnz/cve-2024-3094-check

Shell script to detect CVE-2024-3094 (xz-utils backdoor) on Linux and macOS systems, with automated check and fix instructions.

exploitationgeneral-purpose-utilitiesscripting-automation+2
52 years ago
sec-af preview

sec-af

GitHubagent-field/sec-af

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

ai-securitycode-analysisdevsecops+7
1991 month ago
react2shell preview
Archived

react2shell

GitHubmantvmass/react2shell

A CLI tool that exploits vulnerabilities in React Server Components and Server Actions (CVE-2025-55182, CVE-2025-66478) to achieve remote code…

educationexploitationpenetration-testing+3
29 months ago
CVE-2023-36845 preview

CVE-2023-36845

GitHube11i0t4lders0n/cve-2023-36845

Shell-based scanner for CVE-2023-36845, an unauthenticated remote code execution vulnerability in Juniper J-Web, enabling environment variable…

exploitationpenetration-testingremote-access-tool+2
12 years ago
CVE-2026-42945 preview

CVE-2026-42945

GitHubchenqin231/cve-2026-42945

Local risk assessment script for CVE-2026-42945 (nginx-rift). Checks version, vulnerable rewrite+set config, ASLR status, and compile hardening to…

binary-analysisconfiguration-auditingexploitation+3
14 months ago
CVE-2025-55182 preview

CVE-2025-55182

GitHub0xsj/cve-2025-55182

Proof-of-concept scanner for CVE-2025-55182, an unauthenticated RCE in React Server Components. Supports batch scanning, JSON/CSV export, and…

command-and-controlexploitationpenetration-testing+3
18 months ago
react2shell-scanner preview

react2shell-scanner

GitHubshield-cyber/react2shell-scanner

Scanner to detect the presence of CVE-2025-55182 & CVE-2025-66478 on targeted web services.

exploitationinformation-gatheringpenetration-testing+3
19 months ago
node9-proxy preview

node9-proxy

GitHubnode9-ai/node9-proxy

Access control for AI agents. Set what Claude Code, Codex, Gemini, Cursor and any MCP server are allowed to do, review risky actions before they run,…

ai-securitycloud-securitycommand-and-control+7
2173 days ago
Previous12…30Next