Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
155 results
CVE-2026-30251 preview

CVE-2026-30251

GitHubvenablee/cve-2026-30251

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

exploitationpenetration-testingvulnerability-analysis+2
3 days ago
CVE-2026-30252 preview

CVE-2026-30252

GitHubvenablee/cve-2026-30252

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

educationexploitationpapers-research+2
3 days ago
web3-decoder preview

web3-decoder

GitHubuwctcjnwlk/web3-decoder

Burp Suite extension for decoding Ethereum JSON-RPC calls and smart contract interactions, supporting multiple chains and automatic ABI retrieval.

api-securitypenetration-testingreverse-engineering+2
21514 days ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubdebugactiveprocess/cve-2026-18963

Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple paths, aiding validation of CVE-2026-18963 exposure.

exploitationpenetration-testingreconnaissance+2
9 days ago
log4j-fuzzer preview

log4j-fuzzer

GitHubmr-vill4in/log4j-fuzzer

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.

exploitationfuzzingpenetration-testing+2
34 years ago
CVE-2026-25890-FileBrowser-Access-Control-Bypass preview

CVE-2026-25890-FileBrowser-Access-Control-Bypass

GitHubmbanyamer/cve-2026-25890-filebrowser-access-control-bypass

Exploit for CVE-2026-25890, a path-based authorization bypass in FileBrowser <= v2.57.0, allowing authenticated low-privileged users to read, upload,…

exploitationpenetration-testingvulnerability-analysis+2
6 months ago
CVE-2026-24854-ChurchCRM-6.7.2-Authenticated-Numeric-SQL-Injection preview

CVE-2026-24854-ChurchCRM-6.7.2-Authenticated-Numeric-SQL-Injection

GitHubmbanyamer/cve-2026-24854-churchcrm-6.7.2-authenticated-numeric-sql-injection

Proof-of-concept demonstrating authenticated numeric SQL injection in ChurchCRM before 6.7.2, enabling logic manipulation to bypass WHERE clauses and…

educationexploitationpenetration-testing+3
7 months ago
POC-CVE-2025-52970 preview

POC-CVE-2025-52970

GitHubimbas007/poc-cve-2025-52970

Proof-of-concept exploit for CVE-2025-52970, allowing security researchers to test single or multiple target URLs for the vulnerability.

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
HotelDruid-CVE-2021-42948 preview

HotelDruid-CVE-2021-42948

GitHubdhammon/hoteldruid-cve-2021-42948

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
Expression-Sandbox-Escape-Simulation-Lab preview

Expression-Sandbox-Escape-Simulation-Lab

GitHubotakuliu/expression-sandbox-escape-simulation-lab

Educational lab demonstrating JavaScript expression sandbox escape techniques and patch evolution through multiple vulnerable sandbox versions, with…

educationexploitationstatic-analysis+2
16 months ago
Reserch-CVE-2021-41773 preview

Reserch-CVE-2021-41773

GitHubdotuan1/reserch-cve-2021-41773

Python-based exploit scanner for CVE-2021-41773, allowing single-target or batch scanning to detect vulnerable Apache servers.

exploitationinformation-gatheringpenetration-testing+2
4 years ago
CVE-2026-40487 preview

CVE-2026-40487

GitHubastaruf/cve-2026-40487

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

exploitationpayload-developmentpenetration-testing+3
34 months ago
Mass-Scanner-CVE-2026-1405 preview

Mass-Scanner-CVE-2026-1405

GitHubanggatechi/mass-scanner-cve-2026-1405

WordPress mass scanner for detecting CVE-2026-1405 exposure.

information-gatheringpenetration-testingreconnaissance+2
44 months ago
ai-captcha-bypass preview

ai-captcha-bypass

GitHubaydinnyunus/ai-captcha-bypass

Automates CAPTCHA solving with multimodal AI models (GPT-4o, Gemini) and Selenium, supporting text, audio, slider puzzles, and reCAPTCHA v2 via a…

ai-securityanti-botcaptcha-bypass+1
1.2k3 months ago
vuln-bank preview

vuln-bank

GitHubcommando-x/vuln-bank

Intentionally vulnerable banking platform for practicing web application, API, and AI/LLM security testing, secure code review, and DevSecOps…

ai-securityapi-securitycode-analysis+5
9272 months ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubmr-leonardogomes/xss2shell-cve-2026-64638

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

exploitationpenetration-testingreconnaissance+3
126 days ago
CVE-2018-7600 preview

CVE-2018-7600

GitHubtpdlshdmlrkfmcla/cve-2018-7600

CVE-2018-7600 POC (Drupal RCE)

exploitationpenetration-testingvulnerability-analysis+2
16 years ago
BurpSuite-Team-Extension preview

BurpSuite-Team-Extension

GitHubstatic-flow/burpsuite-team-extension

This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes through your…

penetration-testingred-teamingutilities-frameworks+2
2603 years ago
Previous12…9Next