Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
7351 results
BobTheSmuggler preview

BobTheSmuggler

GitHubthecyb3ralpha/bobthesmuggler

"Bob the Smuggler": A tool that leverages HTML Smuggling Attack and allows you to create HTML files with embedded 7z/zip archives. The tool would…

educationencryption-decryption-toolspayload-development+4
599
10 months ago
CVE-2024-24919-Exploit preview

CVE-2024-24919-Exploit

GitHubrug4lo/cve-2024-24919-exploit

CVE-2024-24919 Exploit and PoC - Critical LFI for Remote Access VPN or Mobile Access.

educationexploitationinformation-gathering+3
32 years ago
proxylogscan preview

proxylogscan

GitHubdwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

exploitationinformation-gatheringpenetration-testing+3
1664 years ago
CVE-2025-25257 preview

CVE-2025-25257

GitHubimbas007/cve-2025-25257

Python-based exploit tool for CVE-2025-25257 in FortiWeb. Automates SQL injection detection, webshell upload, and remote command execution on…

command-and-controlexploitationinformation-gathering+3
11 year ago
MassExploit-CVE-2024-4577 preview

MassExploit-CVE-2024-4577

GitHubcirqueiradev/massexploit-cve-2024-4577

CVE-2024-4577 Mass Scanner & Exploit Tool

exploitationpayload-generationpenetration-testing+3
59 months ago
CVE-2022-46364-Proof-of-the-concept preview

CVE-2022-46364-Proof-of-the-concept

GitHubcybermaksx/cve-2022-46364-proof-of-the-concept

This vulnerability allows an attacker to perform SSRF (Server-Side Request Forgery) attacks on Apache CXF webservices that accept MTOM/XOP requests.…

educationexploitationinformation-gathering+3
35 months ago
waf-checker preview

waf-checker

GitHubsech0us3/waf-checker

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

api-security-testingids-ips-evasioninformation-gathering+6
341 day ago
react2shell-CVE-2025-55182 preview

react2shell-CVE-2025-55182

GitHubbrianlopezm99/react2shell-cve-2025-55182

An exploitation tool for the Next.js vulnerability CVE-2025-55182 that allows remote command execution through a poisoning prototype in React Server…

exploitationpayload-generationpenetration-testing+3
17 months ago
burpsuite-copy-as-xmlhttprequest preview

burpsuite-copy-as-xmlhttprequest

GitHubvulnbe/burpsuite-copy-as-xmlhttprequest

BurpSuite extension that converts HTTP requests into JavaScript XMLHttpRequest code for streamlined XSS proof-of-concept generation and web…

payload-generationpenetration-testingweb-application-exploitation
335 years ago
CVE-2024-55591-POC preview

CVE-2024-55591-POC

GitHubumchacker/cve-2024-55591-poc

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

authenticationexploitationpenetration-testing+3
21 year ago
CVE-2025-53770-Exploit preview

CVE-2025-53770-Exploit

GitHubsoltanali0/cve-2025-53770-exploit

SharePoint WebPart Injection Exploit Tool

educationexploitationpayload-development+4
3159 months ago
CVE-2022-22963_Reverse-Shell-Exploit preview

CVE-2022-22963_Reverse-Shell-Exploit

GitHubj0ey17/cve-2022-22963_reverse-shell-exploit

CVE-2022-22963 is a vulnerability in the Spring Cloud Function Framework for Java that allows remote code execution. This python script will verify…

exploitationpayload-generationpenetration-testing+3
243 years ago
CVE-2021-3129---Laravel-RCE preview

CVE-2021-3129---Laravel-RCE

GitHublukwagoasuman/cve-2021-3129---laravel-rce

## About The script has been made for exploiting the Laravel RCE (CVE-2021-3129) vulnerability.<br> This script allows you to write/execute commands…

exploitationvulnerability-analysisweb-application-exploitation
11 year ago
CVE-2025-6934-PoC preview

CVE-2025-6934-PoC

GitHubmejbankadir/cve-2025-6934-poc

CVE-2025-6934 Exploit Tool Unauthenticated Administrator Account Creation in WordPress Plugin Opal Estate Pro

educationexploitationpayload-generation+3
5 months ago
metabase-pre-auth-rce-poc preview

metabase-pre-auth-rce-poc

GitHubm3m0o/metabase-pre-auth-rce-poc

This is a script written in Python that allows the exploitation of the Metabase's software security flaw described in CVE-2023-38646.

exploitationpenetration-testingred-teaming+3
22 years ago
CVE-2021-44228-playground preview

CVE-2021-44228-playground

GitHubb-abderrahmane/cve-2021-44228-playground

Docker-based lab to validate CVE-2021-44228 (Log4Shell) in Java apps, test mitigations, and simulate RCE via LDAP and HTTP payloads.

educationexploitationlabs-practice+3
24 days ago
Panoptic preview

Panoptic

GitHublightos/panoptic

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

information-gatheringpenetration-testingreconnaissance+2
3251 month ago
PhEmail preview

PhEmail

GitHubdionach/phemail

PhEmail is a python open source phishing email tool that automates the process of sending phishing emails as part of a social engineering test

email-harvestinginformation-gatheringosint+4
3486 years ago
Previous12…100Next