Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
157 results
bucketbuster preview

bucketbuster

GitHubooafa/bucketbuster

Scans public cloud object-storage endpoints across Yandex, VK, Selectel, Sber, Alibaba, Tencent, Huawei, and Baidu to find listable buckets and…

cloud-infrastructure-securitycloud-securitydata-exfiltration+6
2
5 days ago
CVE-2025-6325_CVE-2025-6327 preview

CVE-2025-6325_CVE-2025-6327

GitHubjohenlastgen-jlg/cve-2025-6325_cve-2025-6327

Python PoC validating CVE-2025-6325 unauthenticated privilege escalation and CVE-2025-6327 arbitrary file upload RCE in King Addons for Elementor <=…

crawlerexploitationpayload-development+7
17 days ago
news-8.6.0-cve-2026-8726-backport preview

news-8.6.0-cve-2026-8726-backport

GitHubshentao83/news-8.6.0-cve-2026-8726-backport

Minimal security backport for CVE-2026-8726 in georgringer/news 8.6.0

database-securitydefensive-toolsstatic-code-analysis+3
10 days ago
XXStrike preview

XXStrike

GitHubanonmoty/xxstrike

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

dynamic-code-analysisfuzzingpenetration-testing+5
314 days ago
alibi preview

alibi

GitHubowasp-noir/alibi

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

api-securitycode-analysisconfiguration-auditing+7
1118 days ago
gori preview

gori

GitHubhahwul/gori

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

api-security-testingfuzzinginformation-gathering+8
1113 days ago
Internet-Security-Project preview

Internet-Security-Project

GitHubmattia-maria-scivoletto/internet-security-project

Academic report and LaTeX sources analyzing Maltego vulnerability CVE-2020-24656, an XXE injection enabling data exfiltration, written for an…

curated-resourceseducationpapers-research+2
5 years ago
CVE-2026-84118-who-labeled-the-crit-as-a-high preview

CVE-2026-84118-who-labeled-the-crit-as-a-high

GitHubsneakynachos/cve-2026-84118-who-labeled-the-crit-as-a-high

Proof-of-concept for CVE-2026-84118, a SpiderMonkey GC use-after-free leading to out-of-bounds read/write and potential code execution. Includes…

binary-exploitationexploitationmemory-forensics+2
120 days ago
CVE-2026-19516 preview

CVE-2026-19516

GitHubhorkimhab/cve-2026-19516

Proof-of-concept for CVE-2026-19516, demonstrating session spoofing and SSRF in Grafana MCP. Intended for authorized security research and education…

curated-resourceseducationexploitation+2
24 days ago
CVE-2026-85046 preview

CVE-2026-85046

GitHubhorkimhab/cve-2026-85046

Proof-of-concept for Chrome V8 zero-day CVE-2026-85046, providing educational exploit code and setup instructions for authorized security research in…

curated-resourceseducationexploitation+2
125 days ago
CVE-2026-PSA-2026-00043-1 preview

CVE-2026-PSA-2026-00043-1

GitHubhorkimhab/cve-2026-psa-2026-00043-1

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

authenticationeducationexploitation+3
27 days ago
admin-panel-finder preview

admin-panel-finder

GitHubbdblackhat/admin-panel-finder

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

information-gatheringpenetration-testingreconnaissance+2
1914 years ago
CVE-2026-33555 preview

CVE-2026-33555

GitHubr3verii/cve-2026-33555

One zero-byte QUIC packet is enough to desynchronize HAProxy's backend connection pool and smuggle HTTP requests across unrelated users — even users…

exploitationnetwork-securitypapers-research+3
25 months ago
CVE-2026-2763-POC preview

CVE-2026-2763-POC

GitHubppwwiinn/cve-2026-2763-poc

Proof-of-concept exploit for CVE-2026-2763, a use-after-free in Mozilla's JavaScript engine, demonstrating a constrained 1-bit write primitive…

binary-exploitationexploitationmemory-forensics+2
26 months ago
log4j-scanner preview

log4j-scanner

GitHubmanishkanyal/log4j-scanner

A Log4j vulnerability scanner is used to identify the CVE-2021-44228 and CVE_2021_45046

exploitationfuzzingpenetration-testing+3
14 years ago
CVE-2026-19912-CVE-2026-19913-CVE-2026-19914 preview

CVE-2026-19912-CVE-2026-19913-CVE-2026-19914

GitHubhorkimhab/cve-2026-19912-cve-2026-19913-cve-2026-19914

Proof-of-concept exploits for CVE-2026-19912, CVE-2026-19913, and CVE-2026-19914, demonstrating file read and remote code execution in Kaltura,…

educationexploitationpenetration-testing+3
1 month ago
not-slithering-anywhere preview

not-slithering-anywhere

GitHubtrailofbits/not-slithering-anywhere

The Python Version of our Not Go-ing Anywhere Vulnerable Application

dynamic-analysis-sandboxingeducationlabs-practice+3
112 years ago
not-going-anywhere preview

not-going-anywhere

GitHubtrailofbits/not-going-anywhere

Intentionally vulnerable Golang programs exposing web, gRPC, and database/sql flaws for security training, vulnerability discovery, and remediation…

api-securitydatabase-securityeducation+3
1783 years ago
Previous12…9Next