Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
55 results
easy-exploits preview

easy-exploits

GitHubefchatz/easy-exploits

Curated collection of proof-of-concept exploits for 16 CVEs targeting web applications (ASUS, D-Link, Netgear, TP-Link, Xiaomi) and Wi-Fi WPA3-SAE,…

educationexploitationpenetration-testing+3
17
3 years ago
js2py-Sandbox-Escape-CVE-2024-28397-RCE preview

js2py-Sandbox-Escape-CVE-2024-28397-RCE

GitHub0xdtc/js2py-sandbox-escape-cve-2024-28397-rce

Exploit scripts for CVE-2024-28397, a js2py sandbox escape that executes arbitrary Python code to spawn a reverse shell on a target endpoint.

educationexploitationpayload-generation+3
11 months ago
wp2shell-lab preview

wp2shell-lab

GitHubananay/wp2shell-lab

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

api-security-testingcode-analysiseducation+3
1 month ago
awesome-pentest preview

awesome-pentest

GitHubenaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

cloud-securityctfcurated-resources+10
27.1k1 month ago
wordpress-hacking preview

wordpress-hacking

GitHubstealthcopter/wordpress-hacking

A collection of useful resources for hacking WordPress and it's plugins and themes

curated-resourcesdynamic-code-analysisexploitation+4
905 months ago
ai-exploits preview

ai-exploits

GitHubprotectai/ai-exploits

A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities

ai-securitycurated-resourceseducation+4
1.7k1 year ago
vulnerable-mcp-servers-lab preview

vulnerable-mcp-servers-lab

GitHubappsecco/vulnerable-mcp-servers-lab

A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.

ai-securitycode-analysiseducation+7
2778 months ago
tbhm preview

tbhm

GitHubjhaddix/tbhm

The Bug Hunters Methodology

curated-resourceseducationlearning-paths-courses+4
4.4k3 years ago
CVE-2026-54350-Budibase-NoSQL-Injection preview

CVE-2026-54350-Budibase-NoSQL-Injection

GitHubbiitts/cve-2026-54350-budibase-nosql-injection

PoC for CVE-2026-54350 — Budibase unauthenticated NoSQL operator injection (CVSS 10.0). Read/mass-write any document collection via a PUBLIC query.

database-securityexploitationpayload-development+4
1 month ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5492 years ago
Shockwave-OSS preview

Shockwave-OSS

GitHubgal-nagli/shockwave-oss

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

curated-resourceseducationfuzzing+9
7502 years ago
CVE preview

CVE

GitHubstar-sg/cve

A collection of proof-of-concept exploit scripts written by the STAR Labs team for various CVEs that they discovered or found by others.

binary-exploitationexploitationpenetration-testing+3
3201 month ago
awesome-websocket-security preview

awesome-websocket-security

GitHubpalindromelabs/awesome-websocket-security

Awesome information for WebSockets security research

curated-resourcesfuzzinglabs-practice+4
3134 years ago
CVE-2025-53770-Scanner preview

CVE-2025-53770-Scanner

GitHubzephrfish/cve-2025-53770-scanner

ToolShell scanner - CVE-2025-53770 and detection information

defensive-toolsexploitationincident-response+6
181 year ago
Onapsis_CVE-2025-31324_Scanner_Tools preview

Onapsis_CVE-2025-31324_Scanner_Tools

GitHubonapsis/onapsis_cve-2025-31324_scanner_tools

Python-based scanner for CVE-2025-31324 that identifies vulnerable SAP NetWeaver Visual Composer instances and detects indicators of compromise from…

exploitationforensicsincident-response+3
121 year ago
CVEs preview

CVEs

GitHubburaksevben/cves

Curated collection of proof-of-concept exploits for web vulnerabilities including cross-site scripting and SQL injection, with detailed technical…

curated-resourcesexploitationpapers-research+2
102 years ago
shellshocker-pocs preview

shellshocker-pocs

GitHubmubix/shellshocker-pocs

Collection of Proof of Concepts and Potential Targets for #ShellShocker

curated-resourcesexploitationpenetration-testing+3
8896 years ago
selenium-node-takeover-kit preview

selenium-node-takeover-kit

GitHubjonstratton/selenium-node-takeover-kit

A collection of selenium tests that might aid it takeover of a selenium node

command-and-controldata-exfiltrationexploit-frameworks+6
38 months ago
Previous1234Next