Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
55 results
BurpSuite_Pro_v1.7.37 preview

BurpSuite_Pro_v1.7.37

GitHubjas502n/burpsuite_pro_v1.7.37

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

api-security-testinginformation-gatheringpenetration-testing+4
56
7 years ago
CVE-2024-4879 preview

CVE-2024-4879

GitHub0xwhoami35/cve-2024-4879

Exploit script for ServiceNow CVE-2024-4879 that enables unauthenticated remote code execution, with mass target scanning and database dumping…

database-securityexploitationinformation-gathering+3
1 year ago
nginxrift-CVE-2026-42945 preview

nginxrift-CVE-2026-42945

GitHubnanwinata/nginxrift-cve-2026-42945

Proof-of-concept exploit for CVE-2026-42945 (NGINX Rift) with multi-mode RCE, blind verification, reverse shell, and batch scanning capabilities for…

educationexploitationpayload-development+3
23 months ago
ghauri preview

ghauri

GitHubr0oth3x49/ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

database-securitypenetration-testingvulnerability-scanners+2
4.1k11 months ago
CVE-2025-55182_liyon preview

CVE-2025-55182_liyon

GitHubhujiaozhuzhu/cve-2025-55182_liyon

Python-based exploit for CVE-2025-55182 (React Server Components RCE) with interactive shell, reverse shell, batch scanning, and Docker-based…

command-and-controleducationexploitation+7
5 months ago
DVWA-ZAP-PENTEST preview

DVWA-ZAP-PENTEST

GitHubmehedi-hasan-sami98/dvwa-zap-pentest

Web application security assessment of DVWA using OWASP ZAP — vulnerability scanning, RCE (CVE-2012-1823) analysis, and remediation report.

educationlabs-practicepenetration-testing+3
1 month ago
CVE-2026-40022 preview

CVE-2026-40022

GitHuboscerd/cve-2026-40022

Reproducer for CVE-2026-40022: Apache Camel camel-platform-http-main authentication bypass on non-root context paths

authenticationexploitationmisconfiguration+3
1 month ago
JQShell preview

JQShell

GitHubstahlz/jqshell

Automated exploit tool for CVE-2018-9206 (jQuery File Upload) with single/multi-target scanning, Tor proxy support, and output logging for…

educationexploitationpenetration-testing+2
627 years ago
CVE-2026-15409-15410-Framework preview

CVE-2026-15409-15410-Framework

GitHubtc4dy/cve-2026-15409-15410-framework

Multi-exploit framework for SonicWall SMA1000 chaining SSRF (CVE-2026-15409) to Erlang RCE and root privilege escalation (CVE-2026-15410). Features…

command-and-controleducationexploitation+7
51 month ago
CVE-2022-22954 preview

CVE-2022-22954

GitHubaniqfakhrul/cve-2022-22954

Python exploit for CVE-2022-22954, a VMware Workspace ONE SSTI vulnerability, with batch scanning and Shodan integration for vulnerable host…

educationexploitationreconnaissance+2
44 years ago
CVE-2026-6433 preview

CVE-2026-6433

GitHubmurrez/cve-2026-6433

PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk…

educationexploitationpayload-development+4
22 months ago
CVE-2023-46604-RCE preview

CVE-2023-46604-RCE

GitHubnkeshawarz/cve-2023-46604-rce

Python-based remote code execution exploit for Apache ActiveMQ deserialization vulnerability (CVE-2023-46604) with multi-threaded scanning and XML…

educationexploitationpenetration-testing+3
42 years ago
CVE-2026-13001 preview

CVE-2026-13001

GitHubghostpels/cve-2026-13001

Exploit for CVE-2026-13001: Unauthenticated RCE in Podlove Podcast Publisher via extension confusion. Includes mass scanning, interactive shell, and…

educationexploitationpayload-development+3
1 month ago
Burp_VulPscan preview

Burp_VulPscan

GitHubkkx600/burp_vulpscan

Passive Burp Suite plugin for scanning CVE-2022-22947 and integrating high-threat POCs into automated web vulnerability detection workflows.

educationexploitationpenetration-testing+3
24 years ago
WordPress-KeepInMind-CVE-2026-9271-Exploit preview

WordPress-KeepInMind-CVE-2026-9271-Exploit

GitHubcerberusmrxi/wordpress-keepinmind-cve-2026-9271-exploit

Authorized stored XSS assessment tool for CVE-2026-9271 in WordPress KeepInMind plugin. Detects vulnerable versions, injects safe test payloads, and…

educationexploitationpenetration-testing+3
11 month ago
CVE-2024-4577 preview

CVE-2024-4577

GitHubphirojshah/cve-2024-4577

Proof-of-concept exploit for PHP CGI argument injection (CVE-2024-4577) enabling remote code execution on vulnerable Windows servers with scanning…

educationexploitationpayload-generation+5
21 year ago
CVE-2025-55182-React2Shell-RCE preview

CVE-2025-55182-React2Shell-RCE

GitHubsyrins/cve-2025-55182-react2shell-rce

A modern, user-friendly GUI application for detecting and exploiting the CVE-2025-55182 vulnerability in React Server Components. Built with Python…

command-and-controleducationexploitation+4
38 months ago
Validate-CVE-2023-29489-scanner- preview

Validate-CVE-2023-29489-scanner-

GitHubmakurorororororororo/validate-cve-2023-29489-scanner-

Automated scanner to verify CVE-2023-29489 XSS vulnerability on Cpanel webcall interfaces, supporting mass IP scanning via CIDR ranges and common…

educationexploitationpenetration-testing+2
22 years ago
Previous1234Next