Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
205 results
Honeypot_Smart_Infrastructure preview

Honeypot_Smart_Infrastructure

GitHubadarkst/honeypot_smart_infrastructure

This Repository Includes Kubernetes manifest files for configuration of Honeypot system and Falco IDS in K8s environment. There are also Demo…

cloud-securitycontainer-securityeducation+4
1
2 years ago
CVE-2023-34233_Proof_OF_Concept preview

CVE-2023-34233_Proof_OF_Concept

GitHubnayankadamm/cve-2023-34233_proof_of_concept

Proof-of-concept demonstrating CVE-2025-24793 SQL injection vulnerability in Snowflake Connector for Python, with auto-detection of patched/unpatched…

cloud-securitydatabase-securityeducation+3
11 months ago
alibaba__nacos_CVE-2021-44667_2-0-3 preview

alibaba__nacos_CVE-2021-44667_2-0-3

GitHubshoucheng3/alibaba__nacos_cve-2021-44667_2-0-3

Exploit for CVE-2021-44667 targeting Alibaba Nacos 2.0.3, enabling unauthenticated remote code execution via a crafted request to the Derby database…

cloud-securityexploitationmisconfiguration+3
1 year ago
CVE-2026-54761-poc preview

CVE-2026-54761-poc

GitHubsaku0512/cve-2026-54761-poc

Proof-of-concept demonstrating an authorization bypass in Traefik's Kubernetes Gateway provider (CVE-2026-54761) via a crossProviderNamespaces…

cloud-securitycontainer-securityeducation+3
2 months ago
CVE-2026-44578-PoC preview

CVE-2026-44578-PoC

GitHubtocong282/cve-2026-44578-poc

Proof-of-concept exploit for CVE-2026-44578, a Server-Side Request Forgery in Next.js WebSocket upgrade handler. Includes detection mode and…

cloud-securityexploitationpenetration-testing+3
3 months ago
emby_ssrf preview

emby_ssrf

GitHubbtnz-k/emby_ssrf

Metasploit auxiliary module that identifies Emby Media Server version and exploits CVE-2020-26948 SSRF vulnerability to scan internal network…

exploitationnetwork-mappingreconnaissance+3
5 years ago
aimap preview

aimap

GitHubbishopfox/aimap

Discover Exposed AI Services

ai-securityinformation-gatheringosint+6
3664 months ago
CVE-2021-26855_PoC preview

CVE-2021-26855_PoC

GitHubalt3kx/cve-2021-26855_poc

Proof-of-concept exploit for CVE-2021-26855, demonstrating SSRF in Microsoft Exchange Server to access backend services and extract user information.

exploitationinformation-gatheringpenetration-testing+3
535 years ago
rebindMultiA preview

rebindMultiA

GitHubrhynorater/rebindmultia

DNS rebinding attack tool exploiting multiple A records to bypass same-origin policy and exfiltrate data from internal network services via browser…

dns-analysisexploitationpenetration-testing+2
643 years ago
Drupal-SA-CORE-2019-003 preview

Drupal-SA-CORE-2019-003

GitHubg0rx/drupal-sa-core-2019-003

Proof-of-concept exploit for CVE-2019-6340 targeting Drupal's RESTful web services module, with curl-based RCE payload and detailed reproduction…

exploitationpenetration-testingvulnerability-analysis+2
307 years ago
CVE-2019-0708-POC preview

CVE-2019-0708-POC

GitHubclosethe/cve-2019-0708-poc

Proof-of-concept exploit for CVE-2019-0708 (BlueKeep) targeting RDP services on Windows systems. Detects vulnerability and triggers remote code…

exploitationpenetration-testingremote-access-tool+2
137 years ago
cve-2019-0708 preview

cve-2019-0708

GitHubcve-2019-0708-poc/cve-2019-0708

Exploit tool targeting CVE-2019-0708 in Remote Desktop Services, enabling remote code execution on vulnerable Windows systems for penetration testing…

exploitationpenetration-testingremote-access-tool+2
187 years ago
nmap-spring4shell preview

nmap-spring4shell

GitHubgpiechnik2/nmap-spring4shell

Nmap NSE script for detecting and exploiting Spring4Shell (CVE-2022-22965) RCE vulnerability in HTTP services with configurable payload injection and…

exploitationinformation-gatheringpenetration-testing+3
84 years ago
CVE-2019-8978 preview

CVE-2019-8978

GitHubseckatie/cve-2019-8978

Banner Web Tailor and Banner Enterprise Identity Services Vulnerability Disclosure

authenticationexploitationinformation-gathering+3
91 year ago
CVE-2025-20281-Cisco preview

CVE-2025-20281-Cisco

GitHubgrupooruss/cve-2025-20281-cisco

This script checks for the presence of the **CVE-2025-20281** vulnerability in Cisco Identity Services Engine (ISE) and ISE-PIC, which allows…

educationexploitationpenetration-testing+3
81 year ago
CVE-2026-64849.yaml preview

CVE-2026-64849.yaml

GitHubzavisco/cve-2026-64849.yaml

Detects unauthenticated MLflow webhook SSRF (CVE-2026-64849) that accesses internal or cloud metadata services and leaks response details via…

api-security-testingcloud-securityexploitation+3
14 days ago
SAPGateBreaker-Exploit preview

SAPGateBreaker-Exploit

GitHubbecodoexploit-mrcat/sapgatebreaker-exploit

SAPGateBreaker is a PoC exploit for CVE-2022-22536, a critical HTTP Request Smuggling vulnerability in SAP NetWeaver. It demonstrates how to bypass…

educationexploitationpenetration-testing+3
31 year ago
CVE-2026-52102-PoC preview

CVE-2026-52102-PoC

GitHubshowmeyourhands/cve-2026-52102-poc

Proof-of-concept exploit targeting CVE-2026-52102 in web services, accepting multiple target URLs from a file for authorized security testing and…

educationexploitationpenetration-testing+2
129 days ago
Previous12…12Next