Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
223 results
scanner-exploit-joomla-CVE-2015-8562 preview

scanner-exploit-joomla-CVE-2015-8562

GitHubthejackerz/scanner-exploit-joomla-cve-2015-8562

Automated scanner and exploit tool targeting Joomla CMS CVE-2015-8562 for remote code execution, designed for penetration testing and vulnerability…

exploitationinformation-gatheringpenetration-testing+2
10 years ago
DejaVu-CVE-2021-22205 preview

DejaVu-CVE-2021-22205

GitHubovergrowncarrot1/dejavu-cve-2021-22205

Exploit tool for CVE-2021-22205, targeting a remote code execution vulnerability in GitLab. Enables automated exploitation and security assessment.

exploitationinformation-gatheringpenetration-testing+2
3 years ago
CVE-2021-3019 preview

CVE-2021-3019

GitHubgivemefivw/cve-2021-3019

Automated exploitation tool for CVE-2021-3019 that reads target IPs from a text file and executes the exploit against HTTP endpoints.

exploitationinformation-gatheringreconnaissance+2
5 years ago
log4j_CVE-2021-44228 preview

log4j_CVE-2021-44228

GitHubkkyehit/log4j_cve-2021-44228

Exploit tool for CVE-2021-44228 (Log4Shell) targeting vulnerable Log4j instances for remote code execution and security testing.

exploitationinformation-gatheringpenetration-testing+2
4 years ago
ultrasploiter preview

ultrasploiter

GitLabvqkro/ultrasploiter

A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs…

command-and-controlexploitationexploit-frameworks+9
5 days ago
toxssin preview

toxssin

GitHubt3l3machus/toxssin

An XSS exploitation command-line interface and payload generator.

exploitationinformation-gatheringpayload-generation+4
1.5k1 year ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
582 months ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubh454nsec/cve-2023-42793

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

authentication-authorizationexploitationpenetration-testing+3
442 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubgoatsecurity/cve-2024-24919

CVE-2024-24919 exploit

exploitationinformation-gatheringpenetration-testing+3
202 years ago
CVE-2025-5777 preview

CVE-2025-5777

GitHubbughuntar/cve-2025-5777

CVE-2025-5777 Citrix NetScaler Memory Leak Exploit (CitrixBleed 2)

exploitationinformation-gatheringmemory-forensics+3
311 year ago
PenScope preview

PenScope

GitHubspider12223/penscope

Passive recon & attack surface mapper — zero requests sent

crawlerexploitationinformation-gathering+7
375 months ago
CVE-2016-10956-mail-masta preview

CVE-2016-10956-mail-masta

GitHubp0dalirius/cve-2016-10956-mail-masta

MailMasta wordpress plugin Local File Inclusion vulnerability (CVE-2016-10956)

exploitationinformation-gatheringpenetration-testing+3
214 years ago
CVE-2026-8732-POC preview

CVE-2026-8732-POC

GitHubp3nt3st3r-star/cve-2026-8732-poc

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

exploitationinformation-gatheringpenetration-testing+4
84 months ago
CVE-2026-26980-Ghost-CMS-Api preview

CVE-2026-26980-Ghost-CMS-Api

GitHubgagaltotal/cve-2026-26980-ghost-cms-api

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

exploitationinformation-gatheringpenetration-testing+2
113 months ago
CVE-2026-93399 preview

CVE-2026-93399

GitHubmurrez/cve-2026-93399

Python PoC for CVE-2026-93399, an unauthenticated IDOR in Bookly <= 28.2 that leaks order tokens, exposes appointments, and rolls back bookings.

exploitationinformation-gatheringpenetration-testing+4
16 days ago
rwsploit preview

rwsploit

GitHubabq0/rwsploit

Automated exploitation scanner for Oracle Reports Server (rwservlet) — CVE-2012-3152 / CVE-2012-3153. Detects, fingerprints, reads files via LFI,…

exploitationinformation-gatheringpayload-generation+6
64 months ago
CVE-2026-80099 preview

CVE-2026-80099

GitHubwayang1337/cve-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

exploitationinformation-gatheringpassword-attacks+7
129 days ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
120 days ago
Previous1…10111213Next