Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

data-exfiltrationemail-securityexploitation+6
6 days ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubdungsocool/cve-2026-64638

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

code-analysisexploitationpayload-development+4
12 days ago
OWASSRF preview

OWASSRF

GitHubcrowdstrike/owassrf
email-securityexploitationvulnerability-analysis+3
153 years ago
Ashwesker-CVE-2025-68645 preview

Ashwesker-CVE-2025-68645

GitHubashwesker/ashwesker-cve-2025-68645

POC BLH Magelang CSIRT 2026 by babyrootkid

email-securityexploitationvulnerability-analysis+2
13 days ago
CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form preview

CVE-2026-11113-SMTP-Header-Injection-in-Contact-Form

GitHubgeorge0papasotiriou/cve-2026-11113-smtp-header-injection-in-contact-form
educationemail-securityexploitation+4
17 days ago
JSAnalyzer preview

JSAnalyzer

GitHubjenish-sojitra/jsanalyzer
api-securityemail-harvestinginformation-gathering+4
1.2k6 months ago
responsible-disclosure-email-gathering preview

responsible-disclosure-email-gathering

GitHubrxerium/responsible-disclosure-email-gathering

A workflow to gather responsible disclosure emails from a given host(s).

email-harvestinginformation-gatheringosint+2
11 year ago
ca-clone preview

ca-clone

GitHubbishopfox/ca-clone

Scripts to clone CA certificates for use in HTTPS client attacks.

hardware-iot-securityimpersonation-toolspenetration-testing+4
376 years ago
Flash-player preview

Flash-player

GitHubianxtianxt/flash-player

flash钓鱼源码 中文+英文

impersonation-toolsinformation-gatheringphishing+2
336 years ago
changedetection.io preview

changedetection.io

GitHubdgtlmoon/changedetection.io

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

crawlerinformation-gatheringosint+2
33.3k15h 33m ago
exchange-scanner preview

exchange-scanner

GitHubbishopfox/exchange-scanner

Identify public-facing Microsoft Exchange servers and determine their software versions

email-securityinformation-gatheringreconnaissance+3
12 months ago
wp2shell-Hestia-Scanner preview

wp2shell-Hestia-Scanner

GitHubbytespulse-oe/wp2shell-hestia-scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

ai-securitydefensive-toolsforensics+7
217 days ago
CVE-2026-31283 preview

CVE-2026-31283

GitHubsaykino/cve-2026-31283
api-securityeducationemail-security+3
4 months ago
CVE-2020-28018 preview

CVE-2020-28018

GitHubzr0tt/cve-2020-28018

Exploit for Exim4 4.93 CVE-2020-28018

binary-exploitationemail-securityexploitation+3
35 years ago
CVE-2026-XXXX-atlassian-email-enumeration preview

CVE-2026-XXXX-atlassian-email-enumeration

GitHubwh4l3x/cve-2026-xxxx-atlassian-email-enumeration

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

email-harvestinginformation-gatheringosint+5
11 month ago
CVE-2023-33977 preview

CVE-2023-33977

GitHubmnqazi/cve-2023-33977

Read more at Medium

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2023-43871-WBCE-Arbitrary-File-Upload--XSS---Media preview

CVE-2023-43871-WBCE-Arbitrary-File-Upload--XSS---Media

GitHubsromanhu/cve-2023-43871-wbce-arbitrary-file-upload--xss---media

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager preview

CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager

GitHubsromanhu/cve-2023-43872-cmsmadesimple-arbitrary-file-upload--xss---file-manager

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
Previous123456Next