Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
290 results
G0BurpSQLmaPI preview

G0BurpSQLmaPI

GitHubnu11secur1ty/g0burpsqlmapi

CLI tool for generating SQL injection PoC requests, automating sqlmap attacks, and managing modular exploit scripts with interactive menu and…

exploitationpayload-generationpenetration-testing+2
3
7 days ago
Kousei preview

Kousei

GitHubnu11secur1ty/kousei

Python/Go framework that generates SQL injection PoC requests, automates sqlmap attacks, and manages modular exploit scripts with parameter detection…

exploitationpassword-crackingpayload-generation+6
37 days ago
CVE-2026-82226 preview

CVE-2026-82226

GitHubabraxas/cve-2026-82226

Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction…

educationexploitationlabs-practice+4
7 days ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
17 days ago
watchTowr-vs-Citrix-Netscaler-CVE-2026-88772 preview

watchTowr-vs-Citrix-Netscaler-CVE-2026-88772

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-cve-2026-88772

Detection artifact generator for Citrix NetScaler CVE-2026-88772 that builds a DTLS pre-auth buffer overflow payload to verify remote code execution.

exploitationnetwork-securitypenetration-testing+3
78 days ago
watchTowr-vs-Citrix-Netscaler-CVE-2026-88771 preview

watchTowr-vs-Citrix-Netscaler-CVE-2026-88771

GitHubwatchtowrlabs/watchtowr-vs-citrix-netscaler-cve-2026-88771

Detection artifact generator for Citrix NetScaler CVE-2026-88771, exploiting a pre-auth command injection to achieve remote code execution against…

exploitationpapers-researchpayload-generation+5
2310 days ago
CVE-2026-100903 preview

CVE-2026-100903

GitHub4ybrick/cve-2026-100903

PoC and enumeration script for CVE-2026-100903, a missing-authentication flaw in the GEO.RITM REST API that leaks object and driver data anonymously.

api-securityauthenticationexploitation+6
10 days ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubeqstlab/cve-2026-85706

PoC and Docker lab for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE via the commits API route bypass and urlencoded error…

data-exfiltrationexploitationinformation-gathering+5
2510 days ago
ffuf preview

ffuf

GitHubffuf/ffuf

Fast web fuzzer written in Go

api-securityapi-security-testingcrawler+12
16.8k12 days ago
watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127 preview

watchTowr-vs-f5-bigip-PreAuth-RCE-CVE-2026-94127

GitHubwatchtowrlabs/watchtowr-vs-f5-bigip-preauth-rce-cve-2026-94127

Python detection artifact generator and PoC for CVE-2026-94127, a pre-auth RCE in F5 BIG-IP reachable via OAuth-configured virtual servers, with…

exploitationpapers-researchpenetration-testing+4
1313 days ago
unicorn preview

unicorn

GitHubtrustedsec/unicorn

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell…

command-and-controlexploit-frameworksids-ips-evasion+8
4.0k15 days ago
CVE-2025-58434 preview

CVE-2025-58434

GitHubr3vpwnx/cve-2025-58434

Exploit chain for Flowise 3.0.5: unauthenticated account takeover via password-reset token disclosure (CVE-2025-58434) chained to CustomMCP…

authenticationexploitationpenetration-testing+3
29 days ago
CVE-2026-40864 preview

CVE-2026-40864

GitHubromain-deperne/cve-2026-40864

Proof-of-concept for CVE-2026-40864: JupyterHub XSRF bypass via cross-origin form POST exploiting Sec-Fetch-Mode: no-cors. Includes PoC HTML, root…

educationexploitationpenetration-testing+3
1 month ago
GitLab-CVE-2023-7028 preview

GitLab-CVE-2023-7028

GitHubfeartheploto/gitlab-cve-2023-7028

Mock vulnerable GitLab instance reproducing CVE-2023-7028 password reset hijack. Demonstrates array-based email parameter exploitation and account…

educationexploitationlabs-practice+2
1 month ago
CVE-2020-10770-keycloak-exploit-poc preview

CVE-2020-10770-keycloak-exploit-poc

GitHub0xlyvio/cve-2020-10770-keycloak-exploit-poc

Step-by-step guide to reproduce the Keycloak blind SSRF vulnerability (CVE-2020-10770) with Docker setup, listener configuration, and mitigation…

educationexploitationpenetration-testing+3
21 month ago
CVE-2026-38192 preview

CVE-2026-38192

GitHubming1700/cve-2026-38192

pluck-CMS-4.7.20-code-injection-vulnerability

code-analysisexploitationpenetration-testing+2
31 month ago
CVE-2026-82286-gpt-crawler-Arbitrary-File-Write preview

CVE-2026-82286-gpt-crawler-Arbitrary-File-Write

GitHubbiitts/cve-2026-82286-gpt-crawler-arbitrary-file-write

CVE-2026-82286 — gpt-crawler <=1.5.1 unauthenticated arbitrary file write via outputFileName (POST /crawl). PoC + self-contained Docker lab. CVSS…

educationexploitationlabs-practice+3
1 month ago
CVE-2026-72898 preview

CVE-2026-72898

GitHubeqstlab/cve-2026-72898

Unauthenticated blind SQL injection exploit for Metabase, exploiting a raw SQL injection in the password reset endpoint to extract data via…

exploitationpenetration-testingred-teaming+2
221 month ago
Previous12…17Next