Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
CVE-2026-33331 preview

CVE-2026-33331

GitHubabhayclasher/cve-2026-33331

Local lab reproducing stored XSS in oRPC's OpenAPI docs generation (CVE-2026-33331), with vulnerable and patched versions for comparison and a…

educationexploitationlabs-practice+3
6 months ago
Poc-CVE-2025-9519 preview

Poc-CVE-2025-9519

GitHubnimisha17/poc-cve-2025-9519

Proof-of-concept exploit for CVE-2025-9519, demonstrating remote code execution in WordPress Easy Timer plugin via a crafted shortcode filter, with…

exploitationpenetration-testingvulnerability-analysis+2
211 months ago
oathkeeper preview

oathkeeper

GitHubory/oathkeeper

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

api-securityauthenticationauthentication-authorization+5
3.6k2 months ago
drupal-openai-provider-ssrf-cve-2026-13233 preview

drupal-openai-provider-ssrf-cve-2026-13233

GitHubkuninogu/drupal-openai-provider-ssrf-cve-2026-13233

CVE-2026-13233 (Drupal OpenAI Provider, SA-CONTRIB-2026-053): response-URL SSRF / local file read. Untrusted upstream, not the prompt. Safe…

educationvulnerability-analysisweb-security
2 months ago
CVE-1999-0678 preview

CVE-1999-0678

GitHublto7777777/cve-1999-0678

CVE-1999-0678- /doc directory browsable

configuration-auditingeducationintrusion-detection+4
9 months ago
wargame_Re-LS preview

wargame_Re-LS

GitHubm0d0ri205/wargame_re-ls

CTF challenge exploiting CVE-2025-0184 DOCX SSRF vulnerability to access internal admin service and retrieve a flag. Includes exploit generator and…

ctfeducationexploitation+3
11 year ago
Magento-APSB22-48-Security-Patches preview

Magento-APSB22-48-Security-Patches

GitHubemicoecommerce/magento-apsb22-48-security-patches

This repository contains potential security patches for the Magento APSB22-48 and CVE-2022-35698 security vulnerability

code-analysismisconfigurationstatic-analysis+3
373 years ago
CVE-2026-30691 preview

CVE-2026-30691

GitHubwalidriouah/cve-2026-30691

CVE-2026-30691: Stored Cross-Site Scripting (XSS) in @cyntler/react-doc-viewer

educationpapers-researchvulnerability-analysis+2
4 months ago
CVE-2017-11882-Preventer preview

CVE-2017-11882-Preventer

GitHubxdrake1010/cve-2017-11882-preventer

CVE-2017-11882 Preventer for .docx files

defensive-toolseducationexploitation+2
1 year ago
gstack preview

gstack

GitHubgarrytan/gstack

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA

ai-securitycode-analysisdevsecops+8
135.7k4 days ago
phishcollector preview

phishcollector

GitHubolizimmermann/phishcollector

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

crawlereducationinformation-gathering+8
237 months ago
sif preview

sif

GitHubvmfunc/sif

the blazing-fast pentesting suite.

crawlerdns-analysisexploitation+7
5832 days ago
BurpMetaFinder preview

BurpMetaFinder

GitHubjosue87/burpmetafinder

Burp Suite extension for extracting metadata from files

forensicsinformation-gatheringosint+1
205 years ago
Zerodapi preview

Zerodapi

GitHub0dai-ml/zerodapi

0dAPI Official Docs

ai-securityeducationexploit-frameworks+5
12 years ago
caido preview

caido

GitHubcaido/caido

Lightweight web proxy for intercepting, inspecting, and modifying HTTP traffic to audit web applications during penetration testing and bug bounty…

penetration-testingweb-proxies-interceptionweb-security
2.7k4 months ago
SafeLine preview

SafeLine

GitHubchaitin/safeline

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

anti-botapi-securityapi-security-testing+8
22.7k19 days ago