Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
104 results
ghauri preview

ghauri

GitHubr0oth3x49/ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

database-securitypenetration-testingvulnerability-scanners+2
4.1k
1 year ago
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
3252 months ago
PhEmail preview

PhEmail

GitHubdionach/phemail

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

email-harvestinginformation-gatheringosint+4
3477 years ago
TProxer preview

TProxer

GitHubethicalhackingplayground/tproxer

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

api-security-testingpenetration-testingvulnerability-analysis+2
1844 years ago
POC-for-CVE-2023-41993 preview

POC-for-CVE-2023-41993

GitHubpo6ix/poc-for-cve-2023-41993

Proof-of-concept exploit for CVE-2023-41993, a WebKit JIT type confusion in Safari. Provides addrof/fakeobj primitives via heap manipulation and…

binary-exploitationexploitationpayload-development+2
2022 years ago
CVE-2013-2729 preview

CVE-2013-2729

GitHubfeliam/cve-2013-2729

Python-based exploit generator for Adobe Reader BMP/RLE heap corruption (CVE-2013-2729). Demonstrates arbitrary code execution via malicious BMP…

binary-exploitationexploitationfuzzing+3
246 years ago
CVE-2024-7971 preview

CVE-2024-7971

GitHubmistymntncop/cve-2024-7971

Proof-of-concept writeup for CVE-2024-7971, detailing the vulnerability discovery process and providing a functional POC for security researchers and…

exploitationinformation-gatheringpenetration-testing+2
361 year ago
CVE-2020-26259 preview

CVE-2020-26259

GitHubjas502n/cve-2020-26259

CVE-2020-26259: XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has…

code-analysisexploitationpenetration-testing+2
255 years ago
reSolver preview

reSolver

GitHubtheqmaks/resolver

This extension integrates popular CAPTCHA solution services into BurpSuite to process different types of CAPTCHAs without manual intervention.

anti-botapi-security-testingcaptcha-bypass+5
177 months ago
CVE-2022-42889-Text4Shell-POC preview

CVE-2022-42889-Text4Shell-POC

GitHubalealeluyah/cve-2022-42889-text4shell-poc

This repository contains a Python script to automate the process of testing for a vulnerability known as Text4Shell, referenced under the CVE id:…

exploitationpayload-generationpenetration-testing+2
133 years ago
CVE-2024-0012_CVE-2024-9474_PoC preview

CVE-2024-0012_CVE-2024-9474_PoC

GitHubtalatumlabs/cve-2024-0012_cve-2024-9474_poc

This PoC is targeting vulnerabilities in Palo Alto PAN-OS, specifically CVE-2024-0012 and CVE-2024-9474. This script automates the exploitation…

educationexploitationpayload-generation+3
81 year ago
Unauthenticated-RCE-FUXA-CVE-2023-33831 preview

Unauthenticated-RCE-FUXA-CVE-2023-33831

GitHubrodolfomarianocy/unauthenticated-rce-fuxa-cve-2023-33831

Description and exploit of CVE-2023-33831 affecting FUXA web-based Process Visualization (SCADA/HMI/Dashboard) software.

exploitationpayload-generationpenetration-testing+4
131 year ago
CVE-2021-31761 preview

CVE-2021-31761

GitHubelectronicbots/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

command-and-controlexploitationpenetration-testing+3
45 years ago
CVE-2024-25600-Bricks-Builder-plugin-for-WordPress preview

CVE-2024-25600-Bricks-Builder-plugin-for-WordPress

GitHubtornad0007/cve-2024-25600-bricks-builder-plugin-for-wordpress

This tool is designed to exploit the CVE-2024-25600 vulnerability found in the Bricks Builder plugin for WordPress. The vulnerability allows for…

command-and-controlexploitationpayload-generation+3
82 years ago
CVE-2024-25641 preview

CVE-2024-25641

GitHub5ma1l/cve-2024-25641

This repository automates the process of exploiting CVE-2024-25641 on Cacti 1.2.26

exploitationpayload-generationpenetration-testing+2
82 years ago
CVE-2022-46080 preview

CVE-2022-46080

GitHubgeniuszly/cve-2022-46080

it is script that enables Telnet on routers by sending a specially crafted request. The script allows users to specify the router's URL, Telnet port,…

educationexploitationpenetration-testing+3
82 years ago
CVE-2025-8110 preview

CVE-2025-8110

GitHubr3vpwnx/cve-2025-8110

Proof-of-concept exploit for CVE-2025-8110 in Gogs <=0.13.x, enabling authenticated symlink bypass to arbitrary file write as the Gogs process user,…

exploitationpenetration-testingprivilege-escalation+2
28 days ago
CVE-2021-31761 preview

CVE-2021-31761

GitHubmesh3l911/cve-2021-31761

Exploiting a Reflected Cross-Site Scripting (XSS) attack to get a Remote Command Execution (RCE) through the Webmin's running process feature

exploitationpenetration-testingremote-access-tool+2
55 years ago
Previous123456Next