Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
CVE-2026-1357-POC preview

CVE-2026-1357-POC

GitHubcybertechajju/cve-2026-1357-poc

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

data-exfiltrationexploitationpenetration-testing+5
9
7 months ago
CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit preview

CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit

GitHubcerberusmrxi/cve-2025-55182-advanced-react-server-components-rce-exploit

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

data-exfiltrationexploitationpayload-development+6
11 month ago
CVE-2025-67906 preview

CVE-2025-67906

GitHubfranckferman/cve-2025-67906

MISP <= 2.5.27 - Stored Cross-Site Scripting via Workflow Engine (doT.js Template Injection).

data-exfiltrationexploitationinformation-gathering+5
26 months ago
krle preview

krle

GitHubaseemyash/krle

CVE-2025-55182 & CVE-2025-66478 proof of concepts

data-exfiltrationexploitationpayload-development+3
10 months ago
MeterPwrShell preview
Archived

MeterPwrShell

GitHubgetrektboy724/meterpwrshell

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

command-and-controlexploit-frameworksids-ips-evasion+7
2275 years ago
impersonate-proxy preview

impersonate-proxy

GitHubytkoka/impersonate-proxy

A local MITM proxy that lets you control TLS fingerprints (JA3/JA4), HTTP/2 fingerprints, HTTP header order, and User-Agent — all from a single YAML…

fingerprint-spoofingimpersonation-toolspenetration-testing+3
4013 days ago
WP-Contest-Gallery-28.1.4-Exploit preview

WP-Contest-Gallery-28.1.4-Exploit

GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

exploitationpassword-crackingpayload-development+4
12 months ago
HackBar preview

HackBar

GitHubd3vilbug/hackbar

HackBar plugin for Burpsuite

penetration-testingwaf-bypassweb-application-exploitation+1
1.6k5 years ago
BounceBack preview

BounceBack

GitHubd00movenok/bounceback

↕️🤫 Stealth redirector for your red team operation security

command-and-controlids-ips-evasionpenetration-testing+3
1.1k2 months ago
CVE-2025-8723 preview

CVE-2025-8723

GitHubnxploited/cve-2025-8723

Cloudflare Image Resizing <= 1.5.6 | Unauthenticated Remote Code Execution

exploitationids-ips-evasionpayload-generation+5
71 year ago
mssqli-duet preview

mssqli-duet

GitHubkeramas/mssqli-duet

SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing

information-gatheringpenetration-testingwaf-bypass
916 years ago
Awesome-WAF preview

Awesome-WAF

GitHub0xinfection/awesome-waf

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

curated-resourceseducationwaf-bypass+1
7.6k1 month ago
ftw preview

ftw

GitHubcoreruleset/ftw

YAML-driven framework for testing Web Application Firewall (WAF) rules using OWASP Core Rule Set baselines. Automates regression detection and…

devsecopspenetration-testingvulnerability-scanners+2
1434 years ago
ftw preview
Archived

ftw

GitHubfastly/ftw

Framework for Testing WAFs (FTW!)

devsecopspenetration-testingvulnerability-scanners+2
2633 years ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5492 years ago
ModSecurity preview

ModSecurity

GitHubowasp-modsecurity/modsecurity

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. It has a robust event-based…

anti-botapi-securitydefensive-tools+7
9.8k2 days ago
CVE-2025-25369 preview

CVE-2025-25369

GitHublkasjkasj/cve-2025-25369

Documented XSS exploit for ZKBio CVSecurity v.6.4.1 with WAF bypass, enabling privilege escalation from Template Editor to administrator via crafted…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
teler-waf preview

teler-waf

GitHubteler-sh/teler-waf

teler-waf is a Go HTTP middleware that protects local web services from OWASP Top 10 threats, known vulnerabilities, malicious actors, botnets,…

api-securitydefensive-toolsids-ips-evasion+5
4081 year ago
Previous12Next