Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
155 results
web3-decoder preview

web3-decoder

GitHubuwctcjnwlk/web3-decoder

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

api-securitypenetration-testingreverse-engineering+2
215
14 days ago
CVE-2023-34599 preview

CVE-2023-34599

GitHubmaddsec/cve-2023-34599

Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript…

exploitationpenetration-testingvulnerability-analysis+2
33 years ago
CVE-2025-45407 preview

CVE-2025-45407

GitHubyallasec/cve-2025-45407

CVE-2025-45407: Multiple XSS Vulnerabilities in DiscoveryNG v6.0.8 Hotfix 2 Discovered by: YallaSec Security Research Team CVE ID: CVE-2025-45407…

educationpapers-researchvulnerability-analysis+2
1 year ago
CVE-2022-30780_Checker preview

CVE-2022-30780_Checker

GitHubxiw1ll/cve-2022-30780_checker

Lighttpd CVE-2022-30780 checker

exploitationpenetration-testingvulnerability-analysis+1
2 years ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
9272 months ago
ai-captcha-bypass preview

ai-captcha-bypass

GitHubaydinnyunus/ai-captcha-bypass

Automates CAPTCHA solving with multimodal AI models (GPT-4o, Gemini) and Selenium, supporting text, audio, slider puzzles, and reCAPTCHA v2 via a…

ai-securityanti-botcaptcha-bypass+1
1.2k3 months ago
CVE-2025-29927_Scanner preview

CVE-2025-29927_Scanner

GitHubaleongx/cve-2025-29927_scanner

Este script verifica la vulnerabilidad CVE-2025-29927 en servidores Next.js, probando múltiples cargas en la cabecera x-middleware-subrequest para…

exploitationpenetration-testingred-teaming+3
1 year ago
awesome-hacking-lists preview

awesome-hacking-lists

GitHubtaielab/awesome-hacking-lists

A curated collection of top-tier penetration testing tools and productivity utilities across multiple domains. Join us to explore, contribute, and…

curated-resourceseducationexploit-frameworks+6
1.4k9 months ago
secureCodeBox preview

secureCodeBox

GitHubsecurecodebox/securecodebox

Kubernetes-native security scanning orchestrator that automates continuous vulnerability detection by integrating multiple open-source scanners into…

cloud-securitycontainer-securitydevsecops+3
9881 day ago
SecLists preview

SecLists

GitHubdanielmiessler/seclists

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

ctfcurated-resourcesdns-fuzzing+11
73.3k18h 20m ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubtpdlshdmlrkfmcla/cve-2018-7600

CVE-2018-7600 POC (Drupal RCE)

exploitationpenetration-testingvulnerability-analysis+2
16 years ago
CVE-2023-43879-RiteCMS-Stored-XSS---GlobalContent preview

CVE-2023-43879-RiteCMS-Stored-XSS---GlobalContent

GitHubsromanhu/cve-2023-43879-ritecms-stored-xss---globalcontent

About RiteCMS 3.0 is affected by a Multiple Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2020-17453 preview

CVE-2020-17453

GitHubkarthi-the-hacker/cve-2020-17453

CLI scanner for CVE-2020-17453 that tests single or multiple URLs for the vulnerability, designed for bug bounty hunters and penetration testers.

information-gatheringpenetration-testingvulnerability-scanners+2
53 years ago
Vehicle-Service-Management-System-Multiple-Cross-Site-Request-Forgery-CSRF-Leads-to-XSS preview

Vehicle-Service-Management-System-Multiple-Cross-Site-Request-Forgery-CSRF-Leads-to-XSS

GitHubsanupl/vehicle-service-management-system-multiple-cross-site-request-forgery-csrf-leads-to-xss

CVE-2021-46080 - A Cross Site Request Forgery (CSRF) vulnerability exists in Vehicle Service Management System 1.0. An successful CSRF attacks leads…

exploitationpenetration-testingvulnerability-analysis+2
3 months ago
SQLiDetector preview

SQLiDetector

GitHubeslam3kl/sqlidetector

Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14…

penetration-testingvulnerability-scannersweb-security+1
6404 days ago
pegasus-neo preview

pegasus-neo

GitHubsobri3195/pegasus-neo

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

exploitationforensicsosint+9
1246 months ago
mzap preview

mzap

GitHubhahwul/mzap

⚡️ Multiple target ZAP Scanning

api-security-testingdevsecopsdynamic-analysis-sandboxing+3
1141 day ago
owtf preview

owtf

GitHubowtf/owtf

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

exploit-frameworkspenetration-testingpenetration-testing-frameworks+2
2.0k15h 16m ago
Previous12…9Next