Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
Log4j_Vulnerability_Demo preview

Log4j_Vulnerability_Demo

GitHubchandanshastri/log4j_vulnerability_demo

A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )

educationexploitationlog-analysis+2
3
4 years ago
privacytests preview

privacytests

GitHubprivacytests/privacytests

Automates browser privacy testing and renders human-readable results across fingerprinting, tracking, and data-leak vectors.

fingerprint-spoofinginformation-gatheringnetwork-security+2
1.2k1 day ago
epson-eh-tw5350-advisories preview

epson-eh-tw5350-advisories

GitHubdpfkdlemtp/epson-eh-tw5350-advisories

Security advisories for CVE-2021-43716/43717/43718 (Epson EH-TW5350)

authenticationembedded-systems-securityhardware-iot-security+2
16 days ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k1 year ago
responsible-disclosure-email-gathering preview

responsible-disclosure-email-gathering

GitHubrxerium/responsible-disclosure-email-gathering

A workflow to gather responsible disclosure emails from a given host(s).

email-harvestinginformation-gatheringosint+2
11 year ago
CVE-2014-0094-test-program-for-struts1 preview

CVE-2014-0094-test-program-for-struts1

GitHubhasegawatadamitsu/cve-2014-0094-test-program-for-struts1

CVE-2014-0094 test program for struts1

educationexploitationpenetration-testing+3
18 years ago
WPScan preview

WPScan

GitHubalessiodallapiazza/wpscan

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

information-gatheringpenetration-testingreconnaissance+3
3113 years ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubz3n70/cve-2023-23752

simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose

educationexploitationpenetration-testing+2
173 years ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubzcgonvh/cve-2020-0688

Exploit and detect tools for CVE-2020-0688

exploitationinformation-gatheringpenetration-testing+2
3546 years ago
wordpress-really-simple-security-authn-bypass-exploit preview

wordpress-really-simple-security-authn-bypass-exploit

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-exploit

Python exploit for CVE-2024-10924 authentication bypass in Really Simple Security < 9.1.2. Enables unauthenticated login as any existing WordPress…

authentication-authorizationexploitationpenetration-testing+3
191 year ago
wordpress-jetpack-broken-access-control-exploit preview

wordpress-jetpack-broken-access-control-exploit

GitHubm3ssap0/wordpress-jetpack-broken-access-control-exploit

Python exploit for Jetpack < 13.9.1 broken access control (CVE-2024-9926). Allows authenticated users to read visitor-submitted forms on WordPress…

exploitationinformation-gatheringpenetration-testing+3
31 year ago
CVE-2021-44228-Test-Server preview

CVE-2021-44228-Test-Server

GitHubzlepper/cve-2021-44228-test-server

A small server for verifing if a given java program is succeptibel to CVE-2021-44228

educationexploitationpenetration-testing+2
34 years ago
cve-2021-3449 preview

cve-2021-3449

GitHubriptl/cve-2021-3449

CVE-2021-3449 OpenSSL denial-of-service exploit 👨🏻‍💻

exploitationpenetration-testingvulnerability-analysis+1
2245 years ago
CVE-2006-0450-phpBB-2.0.15-Multiple-DoS-Vulnerabilities preview

CVE-2006-0450-phpBB-2.0.15-Multiple-DoS-Vulnerabilities

GitHubparcer0/cve-2006-0450-phpbb-2.0.15-multiple-dos-vulnerabilities

CVE-2006-0450. phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users…

educationexploitationpenetration-testing+2
6 years ago
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k20 days ago
CVE-2022-0739 preview

CVE-2022-0739

GitHubdestr4ct/cve-2022-0739

Proof-of-Concept exploit (SQLI BookingPress before 1.0.11)

exploitationpenetration-testingvulnerability-analysis+2
123 years ago
CVE-2026-14382 preview

CVE-2026-14382

GitHubjaf0rk/cve-2026-14382

Proof-of-concept exploit for CVE-2026-14382, a high-severity ANGLE vulnerability in Chromium, with 32-bit and AArch64 PoCs achieving program counter…

android-securitybinary-exploitationexploitation+4
71 month ago
ESXi-Ransomware-Scanner-mi preview

ESXi-Ransomware-Scanner-mi

GitHubcyberthreatanalysis/esxi-ransomware-scanner-mi

ESXi EZ - A custom scanner that takes list of IPs either in JSON, CSV or individually and checks for infection CVE-2021-21974

information-gatheringreconnaissancescripting-automation+2
23 years ago
Previous12Next