Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
13417 results
Penetration_Testing_POC preview

Penetration_Testing_POC

GitHubmr-xn/penetration_testing_poc

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor…

curated-resourceseducationexploitation+6
7.5k
5h 17m ago
dirsearch preview

dirsearch

GitHubmaurosoria/dirsearch

Web path scanner

api-securityapi-security-testingcrawler+11
14.8k5h 59m ago
CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM- preview

CVE-2019-11707-from-an-IonMonkey-type-confusion-to-SYSTEM-

GitHubg4sp4rcs/cve-2019-11707-from-an-ionmonkey-type-confusion-to-system-

Windows proof-of-concept exploit chain for CVE-2019-11707, a Firefox IonMonkey type confusion, combining browser RCE with sandbox escape to achieve…

binary-exploitationeducationexploitation+6
6h 6m ago
joro preview

joro

GitHubbishopfox/joro

A collaborative web exploitation framework.

command-and-controlexploit-frameworksfuzzing+5
469h 21m ago
dalfox preview

dalfox

GitHubhahwul/dalfox

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

devsecopsdynamic-code-analysispenetration-testing+5
5.3k9h 38m ago
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
4510h 11m ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubvulpecuna/cve-2026-87902

Python PoC for CVE-2026-87902, an unauthenticated WordPress path traversal RCE via get_page_template(), with version fingerprinting, theme checks,…

exploitationlabs-practicepenetration-testing+5
311h 9m ago
CVE-2026-23921 preview

CVE-2026-23921

GitHubqucklecrabik/cve-2026-23921

Proof-of-concept exploit for CVE-2026-23921, a time-based blind SQL injection in Zabbix API via the sortfield parameter, enabling data extraction…

database-securityexploitationpenetration-testing+3
13h 18m ago
cve-2026-87902-poc preview

cve-2026-87902-poc

GitHubressl/cve-2026-87902-poc

PoC for CVE-2026-87902 — unauthenticated path traversal in WordPress page-template resolution (local PHP inclusion, conditional RCE) with a pinned…

exploitationlabs-practicepenetration-testing+4
313h 52m ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

anti-botapi-securityapi-security-testing+21
31.4k14h 18m ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubabraxas/cve-2026-87902

Proof-of-concept and disclosure pack for CVE-2026-87902, an unauthenticated local file inclusion in WordPress Core via locate_template(), with a…

exploitationinformation-gatheringlabs-practice+4
315h 15m ago
strix preview

strix

GitHubusestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

ai-securityapi-security-testingcode-analysis+9
64.2k15h 27m ago
CVE-2011-2523 preview

CVE-2011-2523

GitHubrushikesh-a-bhujbal/cve-2011-2523

From-scratch exploit development in Python. No Metasploit. No frameworks. Raw socket-level implementation of real CVEs against authorized lab targets.

educationexploitationlabs-practice+4
16h 35m ago
IBM-Langflow-CVE-2026-48519-poc preview

IBM-Langflow-CVE-2026-48519-poc

GitHublukehebe/ibm-langflow-cve-2026-48519-poc

Proof-of-concept exploit for CVE-2026-48519, a pre-auth RCE in IBM Langflow <= 1.9.1 via the Shareable Playground /api/v1/build_public_tmp endpoint.

exploitationpenetration-testingremote-access-tool+3
16h 47m ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
3.9k17h 10m ago
1day-archive preview

1day-archive

GitHub1dayexploit/1day-archive

Technical deep-dives and root cause analyses of recently disclosed CVEs - reverse engineering patches, building proof-of-concepts, and documenting…

binary-analysiscurated-resourceseducation+5
3019h 10m ago
commix preview

commix

GitHubcommixproject/commix

Automated Αll-in-One OS command injection exploitation tool.

exploitationpenetration-testingvulnerability-scanners+2
5.9k19h 13m ago
beef preview

beef

GitHubbeefproject/beef

The Browser Exploitation Framework Project

command-and-controlexploitationexploit-frameworks+8
11.0k20h 26m ago
Previous12…100Next