Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
31 results
CVE-2026-21876 preview

CVE-2026-21876

GitHubmefhika120/cve-2026-21876

Minimal PoC and Docker container demonstrating a WAF bypass in OWASP ModSecurity CRS via multipart charset handling, leading to XSS payload delivery.

exploitationpenetration-testingvulnerability-analysis+2
8 months ago
waf-community-bypasses preview

waf-community-bypasses

GitHubwaf-bypass-maker/waf-community-bypasses

Curated CSV collection of community-sourced Web Application Firewall bypass payloads for testing and validating WAF protections.

curated-resourcespayload-developmentpenetration-testing+3
5522 years ago
nowafpls preview

nowafpls

GitHubassetnote/nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

ids-ips-evasionpenetration-testingred-teaming+3
1.5k1 year ago
react2shell-scanner preview

react2shell-scanner

GitHuborwagodfather/react2shell-scanner

RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)

exploitationpenetration-testingwaf-bypass+3
189 months ago
watchTowr-vs-Fortiweb-AuthBypass preview

watchTowr-vs-Fortiweb-AuthBypass

GitHubwatchtowrlabs/watchtowr-vs-fortiweb-authbypass

Python-based detector for FortiWeb authentication bypass (CVE-2025-xxxxx). Sends exploit payload to create a test user as proof of exploitation.

exploitationpenetration-testingvulnerability-analysis+2
7610 months ago
CVE-2022-31813 preview

CVE-2022-31813

GitHubyiliufeng168/cve-2022-31813

Demonstrates CVE-2022-31813 Apache HTTP Server bypass using X-Real-IP header manipulation to evade access controls, with a Docker-based test…

exploitationpenetration-testingvulnerability-analysis+2
6 months ago
Predator preview

Predator

GitHubs0md3v/predator

Anti-Automation System

anti-botcrawlerids-ips-evasion+3
1275 years ago
Bypass-CVE-2025-58360 preview

Bypass-CVE-2025-58360

GitHubquyenheu/bypass-cve-2025-58360

A new way to exploit CVE-2025-58360 bypass WAF

exploitationpenetration-testingvulnerability-analysis+2
18 months ago
web-application-firewall- preview

web-application-firewall-

GitHubnithylesh/web-application-firewall-

This project demonstrates a Web Application Firewall (WAF) simulation using Flask and a vulnerability checker for CVE-2017-5638. The WAF middleware…

educationexploitationids-ips-evasion+5
32 years ago
fortinet-fortiweb-cve-2025-64446-58034 preview

fortinet-fortiweb-cve-2025-64446-58034

GitHublequoca/fortinet-fortiweb-cve-2025-64446-58034

Security research on Fortinet FortiWeb vulnerabilities (CVE-2025-64446, CVE-2025-58034)

authentication-authorizationcommand-and-controlexploitation+3
9 months ago
Drupal-Exploit-Lab preview

Drupal-Exploit-Lab

GitHubtea-celikik/drupal-exploit-lab

Demonstration on exploitation on Drupal 7.57 (CVE-2018-7600) with and without WAF(Web Application Firewall)

educationexploit-frameworkslabs-practice+3
7 months ago
CVE-2026-26718 preview

CVE-2026-26718

GitHubibrahim-sartawi/cve-2026-26718

A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application that allows an attacker to perform unauthorized…

exploitationids-ips-evasionpenetration-testing+3
12 months ago
CVE-2025-55182-bypass preview

CVE-2025-55182-bypass

GitHubmomika233/cve-2025-55182-bypass

CVE-2025-55182-bypass-waf

exploitationpenetration-testingvulnerability-analysis+2
318 months ago
CVE-2025-55182-research preview

CVE-2025-55182-research

GitHubfarhan9488/cve-2025-55182-research

🛡️ Explore CVE-2025-55182, a critical RCE vulnerability in React's Flight Protocol, demonstrating exploitation techniques and mitigation strategies.

exploitationpenetration-testingvulnerability-analysis+3
5h 30m ago
bunkerweb preview

bunkerweb

GitHubbunkerity/bunkerweb

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

anti-botcloud-securitycontainer-security+6
11.0k4 days ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5576 months ago
cve-2025-64446-fortiweb-exploit preview

cve-2025-64446-fortiweb-exploit

GitHuban5i/cve-2025-64446-fortiweb-exploit

Security research tool for detecting and testing CVE-2025-64446 (FortiWeb Path Traversal RCE vulnerability)

educationexploitationpayload-development+5
110 months ago
CVE-2024-34102 preview

CVE-2024-34102

GitHub11whoami99/cve-2024-34102

Proof-of-concept for CVE-2024-34102 exploiting unauthenticated Magento XXE and WAF bypass by sending a crafted request to the…

exploitationpenetration-testingvulnerability-analysis+2
32 years ago
Previous12Next