Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
227 results
afrog preview

afrog

GitHubzan8in/afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.

penetration-testingred-teamingvulnerability-scanners+1
4.4k4 days ago
Vulnerability-Disclosures preview

Vulnerability-Disclosures

GitHubmandiant/vulnerability-disclosures

Curated repository of vulnerability disclosures from Mandiant, including CVEs discovered through internal research, red team assessments, and wild…

exploitationpenetration-testingred-teaming+3
22224 days ago
Log4jHorizon preview

Log4jHorizon

GitHubpuzzlepeaches/log4jhorizon

Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.

exploitationpayload-developmentpenetration-testing+4
1204 years ago
Next.js-Exploit-Tool preview

Next.js-Exploit-Tool

GitHubrsatan/next.js-exploit-tool

Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。

exploitationpayload-developmentpenetration-testing+3
1199 months ago
CVE-2025-55182-scanner preview

CVE-2025-55182-scanner

GitHubfatguru/cve-2025-55182-scanner

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

exploitationpenetration-testingred-teaming+4
1119 months ago
CVE-2024-38856_Scanner preview

CVE-2024-38856_Scanner

GitHubsecurelayer7/cve-2024-38856_scanner

Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)

command-and-controlexploitationpenetration-testing+3
491 year ago
fortios-auth-bypass-check-CVE-2024-55591 preview

fortios-auth-bypass-check-CVE-2024-55591

GitHubwatchtowrlabs/fortios-auth-bypass-check-cve-2024-55591

Python script to detect FortiOS authentication bypass (CVE-2024-55591) by probing WebSocket connections to the management interface, identifying…

authenticationexploitationpenetration-testing+3
661 year ago
cve-2023-36845-scanner preview

cve-2023-36845-scanner

GitHubvulncheck-oss/cve-2023-36845-scanner

A go-exploit to scan for Juniper firewalls vulnerable to CVE-2023-36845

exploitationnetwork-securitypenetration-testing+3
621 year ago
Hadoop-Yarn-ResourceManager-RCE preview

Hadoop-Yarn-ResourceManager-RCE

GitHubal1ex/hadoop-yarn-resourcemanager-rce

Hadoop Yan ResourceManager unauthorized RCE

exploitationpenetration-testingred-teaming+3
394 years ago
gitlab_rce_cve-2022-2884 preview

gitlab_rce_cve-2022-2884

GitHubm3ssap0/gitlab_rce_cve-2022-2884

Exploits GitLab authenticated RCE vulnerability known as CVE-2022-2884.

exploitationpenetration-testingred-teaming+3
263 years ago
crlf-desyncs preview

crlf-desyncs

GitHubturtlesec-software/crlf-desyncs

Nuclei templates and exploit resources for CRLF based desync attacks

fuzzingpayload-developmentpenetration-testing+4
181 month ago
WSOB preview

WSOB

GitHubdsssssssm/wsob

Python exploit tool for CVE-2022-29464, enabling unrestricted file upload and remote code execution on vulnerable WSO2 products via directory…

exploitationpenetration-testingred-teaming+2
263 years ago
watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 preview

watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523

GitHubwatchtowrlabs/watchtowr-vs-ivanti-sentry-rce-cve-2026-10520-cve-2026-10523

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

authenticationexploitationpenetration-testing+3
143 months ago
watchTowr-vs-FortiSIEM-CVE-2025-25256 preview

watchTowr-vs-FortiSIEM-CVE-2025-25256

GitHubwatchtowrlabs/watchtowr-vs-fortisiem-cve-2025-25256

Detection artifact generator for FortiSIEM CVE-2025-25256 unauthenticated remote command execution vulnerability. Sends crafted packets to verify…

command-and-controlexploitationpenetration-testing+3
191 year ago
cPanelWHM-AuthBypass preview

cPanelWHM-AuthBypass

GitHubkagantua/cpanelwhm-authbypass

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

authenticationexploitationpenetration-testing+3
114 months ago
CVE-2024-23113 preview

CVE-2024-23113

GitHubp33d/cve-2024-23113

Python script to detect CVE-2024-23113, a format string vulnerability in FortiGate FGFM service on TCP/541, using SSL connection and crafted payload…

exploitationnetwork-securitypenetration-testing+3
111 year ago
wp2shell-scan preview

wp2shell-scan

GitHubfullhunt/wp2shell-scan

A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

exploitationpenetration-testingred-teaming+2
61 month ago
CVE-2023-22527 preview

CVE-2023-22527

GitHubrevoltsecurities/cve-2023-22527

Exploitation tool for CVE-2023-22527 targeting Confluence servers, enabling remote code execution with support for multiple targets, concurrency, and…

exploitationpenetration-testingred-teaming+3
102 years ago
Previous12…13Next