Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2030 results
ezXSS preview

ezXSS

GitHubssl/ezxss

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

information-gatheringpayload-generationpenetration-testing+2
2.3k2 months ago
CVE-2018-0296 preview

CVE-2018-0296

GitHubyassineaboukir/cve-2018-0296

Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.

exploitationinformation-gatheringnetwork-security+3
2052 years ago
CVE-2021-26855_PoC preview

CVE-2021-26855_PoC

GitHubalt3kx/cve-2021-26855_poc

Proof-of-concept exploit for CVE-2021-26855, demonstrating SSRF in Microsoft Exchange Server to access backend services and extract user information.

exploitationinformation-gatheringpenetration-testing+3
535 years ago
exploit-CVE-2023-23752 preview

exploit-CVE-2023-23752

GitHubacceis/exploit-cve-2023-23752

Joomla! < 4.2.8 - Unauthenticated information disclosure

exploitationinformation-gatheringpenetration-testing+3
942 years ago
CVE-2020-4463 preview

CVE-2020-4463

GitHubibonok/cve-2020-4463

IBM Maximo Asset Management is vulnerable to Information Disclosure via XXE Vulnerability (CVE-2020-4463)

exploitationinformation-gatheringpenetration-testing+3
512 years ago
CVE-2022-24990 preview

CVE-2022-24990

GitHublishang520/cve-2022-24990

Proof-of-concept exploit for CVE-2022-24990 combining information disclosure and remote code execution in a single chain, targeting web applications.

exploitationinformation-gatheringpenetration-testing+2
384 years ago
Microsoft-Edge-Information-Disclosure preview

Microsoft-Edge-Information-Disclosure

GitHubabsholi7ly/microsoft-edge-information-disclosure

CVE-2024-30056 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

data-exfiltrationexploitationinformation-gathering+3
172 years ago
CVE-2006-3392 preview

CVE-2006-3392

GitHubivanglinkin/cve-2006-3392

This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help…

exploitationinformation-gatheringpenetration-testing+3
143 years ago
FHEM-6.0-Local-File-Inclusion-LFI-Vulnerability preview

FHEM-6.0-Local-File-Inclusion-LFI-Vulnerability

GitHubemreovunc/fhem-6.0-local-file-inclusion-lfi-vulnerability

Local File Inclusion (LFI) in FHEM 6.0 allows an attacker to include a file, it can lead to sensitive information disclosure.

exploitationinformation-gatheringpenetration-testing+2
125 years ago
CVE-2025-11749 preview

CVE-2025-11749

GitHubnxploited/cve-2025-11749

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

exploitationinformation-gatheringpenetration-testing+4
810 months ago
CVE-2021-41277 preview

CVE-2021-41277

GitHubzer0yu/cve-2021-41277

Go-based exploit tool for CVE-2021-41277, a Metabase sensitive information disclosure vulnerability enabling local file inclusion and environment…

exploitationinformation-gatheringpenetration-testing+3
94 years ago
CVE-2022-26134 preview

CVE-2022-26134

GitHubofflinehoster/cve-2022-26134

Information and scripts for the confluence CVE-2022-26134

exploitationinformation-gatheringthreat-intelligence+2
84 years ago
cve-2021-38314 preview

cve-2021-38314

GitHubphrantom/cve-2021-38314

Python exploit for CVE-2021-38314 targeting unauthenticated information disclosure in the Gutenberg Template Library & Redux Framework WordPress…

exploitationinformation-gatheringpenetration-testing+2
64 years ago
sentryexploit preview

sentryexploit

GitHubleakix/sentryexploit

CVE-2023-38035 Recon oriented exploit, extract company name contact information

exploitationinformation-gatheringreconnaissance+2
73 years ago
Eaton-Intelligent-Power-Manager-Local-File-Inclusion preview

Eaton-Intelligent-Power-Manager-Local-File-Inclusion

GitHubemreovunc/eaton-intelligent-power-manager-local-file-inclusion

CVE-2018-12031 | LFI in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file, it can lead to sensitive information disclosure,…

exploitationinformation-gatheringpenetration-testing+2
48 years ago
ExploitVeer preview

ExploitVeer

GitHubcyberleelawat/exploitveer

An advanced, powerful, and easy-to-use tool designed to detect and exploit CVE-2025-5777 (CitrixBleed 2). This script not only identifies the…

exploitationinformation-gatheringpenetration-testing+3
31 year ago
nCentralDumpsterDiver preview

nCentralDumpsterDiver

GitHubflipfloptech/ncentraldumpsterdiver

This application utilized the Self Registration feature to create a rogue agent that then dumps ApplianceConfiguration settings which may or may not…

exploitationinformation-gatheringpassword-attacks+2
43 years ago
LocalNet_Attacker preview

LocalNet_Attacker

GitHubdhesitheking/localnet_attacker

This is a project about attacking and gathering information of the windows machines which is connected in the same network by using java programs

information-gatheringpenetration-testingremote-access-tool+1
32 years ago
Previous12…100Next