Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2662 results
phantom-grid preview

phantom-grid

GitHubevkir/phantom-grid

Free Burp Collaborator alternative- OOB interaction capture (HTTP/HTTPS/DNS) with SQLite & exfil reassembly

data-exfiltrationdns-analysisinformation-gathering+7
1
1 month ago
blackbox-pentesting-infsecos preview

blackbox-pentesting-infsecos

GitHubsaqibnet/blackbox-pentesting-infsecos

Full black-box penetration test against SecOS:1 (VulnHub) — CSRF exploitation, privilege escalation via CVE-2015-1328 (OverlayFS), post-exploitation

ctfeducationexploitation+9
5 months ago
CVE-2026-21589 preview

CVE-2026-21589

GitHub0xblackash/cve-2026-21589

Technical analysis and detection guidance for CVE-2026-21589, a pre-auth path traversal arbitrary file access flaw in Atlassian Data Center products.

educationexploitationincident-response+7
2 days ago
ultrasploiter preview

ultrasploiter

GitLabvqkro/ultrasploiter

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

command-and-controlexploitationexploit-frameworks+9
4 days ago
repeat-strike preview

repeat-strike

GitHubhackvertor/repeat-strike

Burp Suite extension that uses AI-generated regex strike rules to detect IDOR and access-control flaws, then scans proxy history to find similar…

ai-securityapi-security-testinginformation-gathering+6
411 year ago
Kimai-CVE-2026-52824-POC preview

Kimai-CVE-2026-52824-POC

GitHubcyeezy08/kimai-cve-2026-52824-poc

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

authenticationexploitationinformation-gathering+7
19 days ago
qyvora-anansi preview

qyvora-anansi

GitHubqyvora/qyvora-anansi

Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

exploitationinformation-gatheringnetwork-mapping+8
45 days ago
nextjs-scanner preview

nextjs-scanner

GitHubferpalma21/nextjs-scanner

This script scans a list of URLs to detect if they are using **Next.js** and determines whether they are vulnerable to **CVE-2025-29927**. It…

exploitationfingerprint-spoofinginformation-gathering+6
212 days ago
APIHarvester preview

APIHarvester

GitHubpiratesshield/apiharvester

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

api-securityapi-security-testingcrawler+9
322 months ago
CVE-2026-104051-pictshare-info-disclosure preview

CVE-2026-104051-pictshare-info-disclosure

GitHubwvllxe/cve-2026-104051-pictshare-info-disclosure

Sensitive info disclosure via info API in PictShare < 3.7.1 (CWE-522). PoC + advisory writeup.

data-exfiltrationeducationexploitation+5
28 days ago
CVE-2026-103978 preview

CVE-2026-103978

GitHubkiwknr/cve-2026-103978

Proof-of-concept and writeup for CVE-2026-103978, an unauthenticated path traversal in OPNMGR's snyk_scan_progress.php allowing arbitrary .json file…

exploitationinformation-gatheringpenetration-testing+3
17 days ago
CVE-2026-103445 preview

CVE-2026-103445

GitHubbombobombone/cve-2026-103445

Report summary and local proof-of-concept for CVE-2026-103445, a stored XSS in MediaWiki PageForms #autoedit via javascript: redirect URLs.

exploitationinformation-gatheringvulnerability-analysis+2
9 days ago
CVE-2026-102425 preview

CVE-2026-102425

GitHubmurrez/cve-2026-102425

Python PoC for CVE-2026-102425: unauthenticated RCE in Joomla Balbooa Forms (com_baforms) via field shortcode injection in post-submission PHP…

exploitationpayload-developmentpenetration-testing+5
10 days ago
CVE-2026-101894 preview

CVE-2026-101894

GitHubmurrez/cve-2026-101894

Python PoC for CVE-2026-101894: symlink-chain path traversal in @xhmikosr/decompress. Includes local Node lab, lockfile version scan, and mass…

exploitationinformation-gatheringpenetration-testing+6
11 days ago
CVE-2026-101110 preview

CVE-2026-101110

GitHubmurrez/cve-2026-101110

Python 3 PoC and mass exploit for CVE-2026-101110, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Book Library <=6.4.6 via…

exploitationinformation-gatheringpenetration-testing+6
11 days ago
CVE-2026-101108 preview

CVE-2026-101108

GitHubmurrez/cve-2026-101108

Python 3 PoC and mass scanner for CVE-2026-101108, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Vehicle Manager <=6.5.7…

exploitationinformation-gatheringpenetration-testing+5
11 days ago
CVE-2026-100903 preview

CVE-2026-100903

GitHub4ybrick/cve-2026-100903

PoC and enumeration script for CVE-2026-100903, a missing-authentication flaw in the GEO.RITM REST API that leaks object and driver data anonymously.

api-securityauthenticationexploitation+6
12 days ago
CVE-2026-100752 preview

CVE-2026-100752

GitHubmurrez/cve-2026-100752

Python 3 PoC and mass exploit for CVE-2026-100752, an unauthenticated SQL injection in OrdaSoft Joomla Real Estate Manager <=6.7.8 via the…

exploitationinformation-gatheringpenetration-testing+6
11 days ago
Previous12…100Next