Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
663 results
vulnhuntr preview

vulnhuntr

GitHubprotectai/vulnhuntr

Zero shot vulnerability discovery using LLMs

ai-securitycode-analysispenetration-testing+3
2.8k1 year ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubkento-sec/cve-2024-34102

Go-based exploit for CVE-2024-34102, an XXE vulnerability in Adobe Commerce leading to remote code execution. Supports single and batch URL scanning…

educationexploitationpenetration-testing+2
1 year ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubbughuntar/cve-2024-34102

Exploitation CVE-2024-34102

educationexploitationpenetration-testing+2
52 years ago
http2smugl preview

http2smugl

GitHubneex/http2smugl

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

penetration-testingvulnerability-analysisweb-application-exploitation+1
5641 year ago
cve-2023-50164-poc preview

cve-2023-50164-poc

GitHubdwisiswant0/cve-2023-50164-poc

Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")

exploitationpayload-generationpenetration-testing+2
572 years ago
ppmap preview

ppmap

GitHubkleiton0x00/ppmap

A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.

exploitationpenetration-testingvulnerability-scanners+2
5184 years ago
CVE-2026-69083_exploit preview

CVE-2026-69083_exploit

GitHub0xdak/cve-2026-69083_exploit

Python PoC for CVE-2026-69083, an unauthenticated SQL injection in SiYuan's asset-content search endpoint. Supports REGEXP breakout and raw SQL…

database-securitydata-exfiltrationexploitation+2
2 months ago
vulnknox preview

vulnknox

GitHubiqzer0/vulnknox

A Go-based wrapper for the KNOXSS API to automate XSS vulnerability testing.

penetration-testingvulnerability-scannersweb-application-exploitation+1
72 years ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubcythonic1/cve-2024-9264

A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.

educationexploitationpenetration-testing+2
31 year ago
CVE-2026-57517-CWP preview

CVE-2026-57517-CWP

GitHubgagaltotal/cve-2026-57517-cwp

Control Web Panel (CWP) vulnerability scenario related to CVE-2026-57517

command-and-controlexploitationpenetration-testing+2
3 months ago
phpggc preview

phpggc

GitHubambionics/phpggc

PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.

exploitationexploit-frameworkspayload-generation+1
3.9k1 year ago
See-SURF preview

See-SURF

GitHubin3tinct/see-surf

Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.

ai-securityreconnaissancevulnerability-scanners+2
3617 months ago
white-deface preview

white-deface

GitHubwhxitte/white-deface

This is a simple python tool to automatically deface webdav vulnerable websites.

exploitationinformation-gatheringpenetration-testing+1
1801 year ago
ssrfuzz preview

ssrfuzz

GitHubryandamour/ssrfuzz

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

fuzzingvulnerability-scannersweb-application-exploitation+1
1845 years ago
proxylogscan preview

proxylogscan

GitHubdwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

exploitationinformation-gatheringpenetration-testing+3
1664 years ago
crlfmap preview

crlfmap

GitHubryandamour/crlfmap

CRLFMap is a tool to find HTTP Splitting vulnerabilities

fuzzingids-ips-evasionpenetration-testing+3
335 years ago
HQLmap preview
Archived

HQLmap

GitHubpaulsec/hqlmap

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

database-securityinformation-gatheringpenetration-testing+2
2286 years ago
CVE-2026-26128 preview

CVE-2026-26128

GitHubjarnovandenbrink/cve-2026-26128

Exploits Kerberos reflection via Unicode normalization in Windows Active Directory to relay authentication to ADCS and MSSQL, enabling…

authenticationexploitationpenetration-testing+2
635 months ago
Previous12…37Next