Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
148 results
CVE-2025-55182 preview

CVE-2025-55182

GitHubjaycelation/cve-2025-55182

PoC, Hunting React2Shell about CVE-2025-55182

exploitationosintpenetration-testing+3
9 months ago
CVE-2022-28171-POC preview

CVE-2022-28171-POC

GitHubnyameeeain/cve-2022-28171-poc

Python exploit for CVE-2022-28171 targeting Hikvision Hybrid SAN devices, automating blind SQL injection and command injection to achieve remote code…

code-analysisexploitationiot-security+3
43 years ago
Pentest-Cheat-Sheet preview

Pentest-Cheat-Sheet

GitHubd0n601/pentest-cheat-sheet

There are many cheat sheets out there, but this is mine.

curated-resourceseducationexploitation+7
381 year ago
CVE-2024-1698-Exploit preview

CVE-2024-1698-Exploit

GitHubkamranhasan/cve-2024-1698-exploit

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

educationexploitationpassword-attacks+3
82 years ago
wordpress-php-object-helper preview

wordpress-php-object-helper

GitHubrandomrobbiebf/wordpress-php-object-helper

Know a plugin has a php object exploit but need to find which lib to use?

exploit-frameworkspenetration-testingreconnaissance+3
33 years ago
CVE-2022-46169-Cacti-1.2.22 preview

CVE-2022-46169-Cacti-1.2.22

GitHubalv-david/cve-2022-46169-cacti-1.2.22

Find out a modified Cacti public exploit!

exploitationpayload-generationpenetration-testing+2
1 year ago
CVE-2012-1823-exploit-for-https-user-password-web preview

CVE-2012-1823-exploit-for-https-user-password-web

GitHubdmitri131313/cve-2012-1823-exploit-for-https-user-password-web

CVE-2012-1823 exploit for https user password website.

exploitationinformation-gatheringpenetration-testing+2
11 year ago
CVE-2024-10914 preview

CVE-2024-10914

GitHubegi08/cve-2024-10914

CVE-2024-10914_Manual testing with burpsuite

command-and-controlexploitationpenetration-testing+3
1 year ago
CVE-2017-14263 preview

CVE-2017-14263

GitHubzzz66686/cve-2017-14263

Proof-of-concept exploit for CVE-2017-14263 in Honeywell NVR devices. Demonstrates session hijacking and privilege escalation from guest to admin via…

authenticationexploitationiot-security+3
59 years ago
0day-POC-for-CVE-2024-27173 preview

0day-POC-for-CVE-2024-27173

GitHubieakd/0day-poc-for-cve-2024-27173

Proof-of-concept exploit for CVE-2024-27173 targeting Toshiba e-Studio devices with remote command execution. Includes Shodan and FOFA dorks for…

exploitationinformation-gatheringreconnaissance+2
2 years ago
CVE-2017-8641_chakra_Js_GlobalObject preview

CVE-2017-8641_chakra_Js_GlobalObject

GitHubhomjxi0e/cve-2017-8641_chakra_js_globalobject

There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP.…

binary-exploitationexploitationmemory-forensics+3
19 years ago
CVE-2020-15999 preview

CVE-2020-15999

GitHuboxfemale/cve-2020-15999

CVE-2020-15999

binary-analysisexploitationfuzzing+3
35 years ago
x-stream__xstream_CVE-2021-21345_1-4-15 preview

x-stream__xstream_CVE-2021-21345_1-4-15

GitHubshoucheng3/x-stream__xstream_cve-2021-21345_1-4-15

Java XML serialization library with a focus on CVE-2021-21345 exploit analysis and deserialization vulnerability testing for web applications.

code-analysisdynamic-code-analysisexploitation+3
1 year ago
strix preview

strix

GitHubusestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

ai-securityapi-security-testingcode-analysis+9
65.4k1 day ago
SSRFire preview

SSRFire

GitHubksharinarayanan/ssrfire

An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

information-gatheringvulnerability-scannersweb-application-exploitation+1
9694 years ago
reflector preview

reflector

GitHubelkokc/reflector

Burp plugin able to find reflected XSS on page in real-time while browsing on site

penetration-testingvulnerability-scannersweb-application-exploitation+1
1.2k5 years ago
shocker preview

shocker

GitHubnccgroup/shocker

A tool to find and exploit servers vulnerable to Shellshock

exploitationpenetration-testingvulnerability-scanners+1
3273 years ago
See-SURF preview

See-SURF

GitHubin3tinct/see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

ai-securityreconnaissancevulnerability-scanners+2
3617 months ago
Previous12…9Next