Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5039 results
strix preview

strix

GitHubusestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

ai-securityapi-security-testingcode-analysis+9
60.9k
5h 50m ago
CVE-2026-2472-Vertex-AI-SDK-Google-Cloud preview

CVE-2026-2472-Vertex-AI-SDK-Google-Cloud

GitHubmegafart1/cve-2026-2472-vertex-ai-sdk-google-cloud

Expose and detail an unauthenticated stored XSS vulnerability in the Google Cloud Vertex AI Python SDK affecting versions 1.98.0 to 1.130.9.

ai-securitycloud-securityeducation+3
213h 5m ago
commix preview

commix

GitHubcommixproject/commix

Automated All-in-One OS Command Injection Exploitation Tool

exploitationpenetration-testingvulnerability-scanners+2
5.8k16h 7m ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
3417h 12m ago
CVE-2026-73570 preview

CVE-2026-73570

GitHubjuanpoch/cve-2026-73570

Zimbra Collaboration Suite RCE — SMTP log poisoning → swatchdog → OS Command Injection (CVSS 8.9, CISA KEV)

educationexploitationpapers-research+3
0 days ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.7k1 day ago
CVE-2026-19598- preview

CVE-2026-19598-

GitHub0xcyp1337/cve-2026-19598-

Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning…

exploitationpenetration-testingprivilege-escalation+2
1 day ago
CVE-2026-0920 preview

CVE-2026-0920

GitHubk3ystr0k3r/cve-2026-0920

Proof-of-concept exploit for CVE-2026-0920, an unauthenticated privilege escalation in LA-Studio Element Kit WordPress plugin, allowing creation of…

exploitationpenetration-testingprivilege-escalation+2
1 day ago
feroxbuster preview

feroxbuster

GitHubepi052/feroxbuster

A fast, simple, recursive content discovery tool written in Rust.

api-securityapi-security-testingcrawler+8
8.1k1 day ago
CVE-2026-75865 preview

CVE-2026-75865

GitHubghostpels/cve-2026-75865

Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC

educationexploitationpenetration-testing+3
1 day ago
CVE-2026-32475 preview

CVE-2026-32475

GitHub4minx/cve-2026-32475

Proof-of-concept exploit for CVE-2026-32475, an unauthenticated arbitrary file upload in Elementor Pro leading to remote code execution. Includes…

exploitationpayload-developmentpenetration-testing+3
1 day ago
CVE-2023-42793-TeamCity-Unauthenticated-RCE preview

CVE-2023-42793-TeamCity-Unauthenticated-RCE

GitHubburakacar6/cve-2023-42793-teamcity-unauthenticated-rce

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

authenticationexploitationpenetration-testing+3
1 day ago
cve-2025-66398 preview

cve-2025-66398

GitHubshowy-headteacher114/cve-2025-66398

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

exploitationpayload-developmentpenetration-testing+3
11 day ago
EXPLOIT-CVE-2026-22778 preview

EXPLOIT-CVE-2026-22778

GitHubjoaovicdev/exploit-cve-2026-22778

Proof-of-concept exploit for CVE-2026-22778, an unauthenticated RCE in vLLM's video processing, demonstrating heap address disclosure and a heap…

binary-exploitationeducationexploitation+5
1 day ago
Langflow-RCE-CVE-2025-3248 preview

Langflow-RCE-CVE-2025-3248

GitHubleotheggman/langflow-rce-cve-2025-3248

Proof-of-concept exploit for CVE-2025-3248, a remote code execution vulnerability in Langflow, demonstrating exploitation of the vulnerable endpoint.

exploitationvulnerability-analysisweb-application-exploitation
1 day ago
T3MP3ST preview

T3MP3ST

GitHubelder-plinius/t3mp3st

autonomous red teaming platform; multi-agent offensive-security meta-harness

ai-securitybinary-analysiscloud-security+9
6.0k2 days ago
CVE-2025-29471 preview

CVE-2025-29471

GitHubskraft9/cve-2025-29471

Stored XSS in Nagios Log Server 2024R1.3.1

exploitationpenetration-testingprivilege-escalation+3
12 days ago
cve-2026-19900-PoC preview

cve-2026-19900-PoC

GitHubon3sk-0x1/cve-2026-19900-poc

Proof-of-concept exploit for CVE-2026-19900, an authentication bypass and remote code execution vulnerability in LB-LINK X-PRO routers, allowing…

authenticationexploitationiot-security+3
2 days ago
Previous12…100Next