Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1010 results
CVE-2021-40539 preview

CVE-2021-40539

GitHubsynacktiv/cve-2021-40539

Exploitation code for CVE-2021-40539

exploitationpenetration-testingred-teaming+2
484 years ago
CVE-2021-26084 preview

CVE-2021-26084

GitHubdinhbaouit/cve-2021-26084

Exploit for CVE-2021-26084 targeting Confluence Server OGNL injection vulnerability for unauthenticated remote code execution.

exploitationpenetration-testingred-teaming+2
535 years ago
CVE-2021-27651-PoC preview

CVE-2021-27651-PoC

GitHubsamwcyo/cve-2021-27651-poc

RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2

exploitationpenetration-testingred-teaming+2
605 years ago
rebindMultiA preview

rebindMultiA

GitHubrhynorater/rebindmultia

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

dns-analysisexploitationpenetration-testing+2
643 years ago
CVE-2020-5902 preview

CVE-2020-5902

GitHubyassineaboukir/cve-2020-5902

Proof of concept for CVE-2020-5902

exploitationpenetration-testingred-teaming+2
706 years ago
CVE-2026-21858-n8n-FullChain preview

CVE-2026-21858-n8n-FullChain

GitHubzerodayevil/cve-2026-21858-n8n-fullchain

🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection…

ai-securityexploitationpayload-development+7
8615 days ago
Moxy preview

Moxy

GitHubmatank001/moxy

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

ai-securityapi-security-testingdynamic-analysis-sandboxing+9
1258 months ago
fortios-auth-bypass-poc-CVE-2024-55591 preview

fortios-auth-bypass-poc-CVE-2024-55591

GitHubwatchtowrlabs/fortios-auth-bypass-poc-cve-2024-55591

Proof-of-concept exploit for CVE-2024-55591, demonstrating authentication bypass in FortiOS management interfaces via WebSocket race condition to…

authenticationcommand-and-controlexploitation+4
761 year ago
ReverseHttp preview

ReverseHttp

GitHubd4vinci/reversehttp

Python backdoor that uses http post/get requests to communicate

command-and-controlpayload-developmentpenetration-testing+3
4210 years ago
cve-2019-6453-poc preview

cve-2019-6453-poc

GitHubproofofcalc/cve-2019-6453-poc

Proof of calc for CVE-2019-6453

exploitationpayload-developmentpenetration-testing+3
482 years ago
CVE-2025-55182-scanner preview

CVE-2025-55182-scanner

GitHubfatguru/cve-2025-55182-scanner

A non-intrusive surface scanner for CVE-2025-55182 (React Server Components RCE). Detects exposed RSC endpoints in React 19 and Next.js applications

exploitationpenetration-testingred-teaming+4
1119 months ago
CVE-2019-2725 preview

CVE-2019-2725

GitHubjiansiting/cve-2019-2725

Exploit for CVE-2019-2725 targeting WebLogic WLS remote code execution vulnerability, enabling unauthenticated attackers to execute arbitrary…

exploitationpenetration-testingred-teaming+2
357 years ago
cc-ddos preview

cc-ddos

GitHubnayumidev/cc-ddos

Một tập lệnh Python để DDOS một trang web bằng phương pháp nhiều phương pháp HTTP Flood, một trang web bình thường chỉ cần 5s để sập hoàn toàn!

penetration-testingred-teamingweb-application-exploitation
841 year ago
Next.js-Exploit-Tool preview

Next.js-Exploit-Tool

GitHubrsatan/next.js-exploit-tool

Next.js-Exploit-Tool 图形化综合利用工具,基于 Go 开发,一款针对 CVE-2025-55182 的独立安全评估工具。

exploitationpayload-developmentpenetration-testing+3
1179 months ago
CVE-2023-34362 preview

CVE-2023-34362

GitHubsfewer-r7/cve-2023-34362

CVE-2023-34362: MOVEit Transfer Unauthenticated RCE

command-and-controlexploitationpenetration-testing+3
652 years ago
vulnhawk preview

vulnhawk

GitHubmomenbasel/vulnhawk

AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.

ai-securityapi-security-testingcloud-security+8
853 months ago
CVE-2024-38856_Scanner preview

CVE-2024-38856_Scanner

GitHubsecurelayer7/cve-2024-38856_scanner

Apache OFBiz RCE Scanner & Exploit (CVE-2024-38856)

command-and-controlexploitationpenetration-testing+3
491 year ago
CVE-2022-27925-PoC preview

CVE-2022-27925-PoC

GitHubvnhacker1337/cve-2022-27925-poc

Zimbra RCE simple poc

exploitationpenetration-testingred-teaming+2
654 years ago
Previous1…678…57Next