Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
22 results
CVE-2024-4879 preview

CVE-2024-4879

GitHubmr-r00t11/cve-2024-4879

CVE-2024-4879.py is a Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the…

database-securityexploitationinformation-gathering+3
4
2 years ago
CVE-2024-4879 preview

CVE-2024-4879

GitHubjdusane/cve-2024-4879

Python script designed to detect specific vulnerabilities in ServiceNow instances and dump database connection details if the vulnerability is found.…

database-securityexploitationinformation-gathering+3
2 years ago
Identificador-CVE-2018-11759 preview

Identificador-CVE-2018-11759

GitHubjulioliraup/identificador-cve-2018-11759

Bash script to detect and exploit CVE-2018-11759 in Apache Tomcat instances, with audit logging of target load balancer details, internal addresses,…

exploitationinformation-gatheringvulnerability-scanners+1
2 years ago
sqlmap-ai preview

sqlmap-ai

GitHubatiilla/sqlmap-ai

This script automates SQL injection testing using SQLMap with AI-powered decision making.

payload-generationpenetration-testingvulnerability-scanners+3
4497 months ago
scan_CVE-2020-29583 preview

scan_CVE-2020-29583

GitHubruppde/scan_cve-2020-29583

Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)

exploitationinformation-gatheringnetwork-security+3
165 years ago
watchTowr-vs-FortiWeb-CVE-2025-25257 preview

watchTowr-vs-FortiWeb-CVE-2025-25257

GitHubwatchtowrlabs/watchtowr-vs-fortiweb-cve-2025-25257

Detection artifact generator for FortiWeb CVE-2025-25257, exploiting unauthenticated SQL injection to achieve remote code execution via hex-encoded…

exploitationpayload-generationpenetration-testing+3
1001 year ago
CVE-2026-39842 preview

CVE-2026-39842

GitHubkeraattin/cve-2026-39842

Critical remote code execution vulnerability in OpenRemote's Rules Engine allows authenticated users with `write:rules` role to execute arbitrary…

exploitationpenetration-testingreconnaissance+3
15 months ago
ssl-certificate-expiry-date-checker preview

ssl-certificate-expiry-date-checker

GitHubpassword123456/ssl-certificate-expiry-date-checker

Scans SSL/TLS certificates for expiry dates, issuer details, and OCSP status. Sends notifications via webhook, Telegram, or Slack. Supports proxy per…

configuration-auditingcryptographylog-analysis+2
123 years ago
Raccoon preview

Raccoon

GitHubevyatarmeged/raccoon

A high performance offensive security tool for reconnaissance and vulnerability scanning

dns-analysisfuzzinginformation-gathering+6
4.0k1 year ago
nuubi preview

nuubi

GitHubpikpikcu/nuubi

Nuubi Tools (Information-ghatering|Scanner|Recon.)

dns-analysisinformation-gatheringosint+4
866 years ago
WhatsAppHACK-RCE preview

WhatsAppHACK-RCE

GitHubkal1gh0st/whatsapphack-rce

Exploit for CVE-2019-11932, a remote code execution vulnerability in WhatsApp via malicious GIF files. Includes proof-of-concept code and technical…

exploitationmalware-analysismobile-security+2
274 years ago
CVE-2026-34197 preview

CVE-2026-34197

GitHubkondordevsecuritycorp/cve-2026-34197

Exploit for Apache ActiveMQ RCE via Jolokia API (CVE-2026-34197) with command output capture, mass scanning, and auto-exploitation.

exploitationlabs-practicepayload-generation+4
25 months ago
CVE-2026-31278 preview

CVE-2026-31278

GitHubmda1r/cve-2026-31278

CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2

exploitationnetwork-securitypapers-research+3
3 months ago
react2shell-cve-2025-55182 preview

react2shell-cve-2025-55182

GitHubopsecramdan/react2shell-cve-2025-55182

Automated exploitation framework for CVE-2025-55182 (Next.js RCE) with subdomain enumeration, vulnerability scanning, payload generation, and…

command-and-controlexploitationpayload-generation+7
5 months ago
Blackash-CVE-2025-61884 preview

Blackash-CVE-2025-61884

GitHubjrexploit/blackash-cve-2025-61884

Provides a detailed summary and detection guidance for CVE-2025-61884, an unauthenticated data disclosure vulnerability in Oracle E-Business Suite…

exploitationinformation-gatheringvulnerability-analysis+2
11 months ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

api-security-testingcloud-securityexploitation+3
1 month ago
jetty-line-check preview

jetty-line-check

GitHubxiaoqimikko/jetty-line-check

CVE-2026-2332 and 4 more 2026 Jetty CVEs: which does your Jetty (or Spring Boot) build hit, and does the fixed version Jetty names even exist on…

configuration-auditingdefensive-toolsstatic-analysis+4
3 days ago
CopyFail-Scanner-CVE-2026-31431 preview

CopyFail-Scanner-CVE-2026-31431

GitHubraptoratack/copyfail-scanner-cve-2026-31431

Scans systems for CVE-2026-31431 (CopyFile vulnerability), enumerates system details, evaluates exposure, reports vulnerable status, and optionally…

configuration-auditinginformation-gatheringpenetration-testing+3
4 months ago
Previous12Next