Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1383 results
phantom-grid preview

phantom-grid

GitHubevkir/phantom-grid

Free Burp Collaborator alternative- OOB interaction capture (HTTP/HTTPS/DNS) with SQLite & exfil reassembly

data-exfiltrationdns-analysisinformation-gathering+7
1
1 month ago
watchTowr-vs-Atlassian-CVE-2026-21589 preview

watchTowr-vs-Atlassian-CVE-2026-21589

GitHubwatchtowrlabs/watchtowr-vs-atlassian-cve-2026-21589

Python detection artifact that checks Atlassian Jira, Confluence, and Bitbucket instances for the CVE-2026-21589 arbitrary file read vulnerability.

exploitationinformation-gatheringpapers-research+5
55 days ago
qyvora-anansi preview

qyvora-anansi

GitHubqyvora/qyvora-anansi

Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

exploitationinformation-gatheringnetwork-mapping+8
46 days ago
Nuke.sh preview

Nuke.sh

GitHubankhcorp/nuke.sh

Bash-based passive reconnaissance + attack surface mapping script using only public APIs + stock Linux tools (curl, dig, openssl, nmap, python3).

dns-analysisdns-subdomain-enumerationinformation-gathering+8
8 days ago
CVE-2026-103978 preview

CVE-2026-103978

GitHubkiwknr/cve-2026-103978

Proof-of-concept and writeup for CVE-2026-103978, an unauthenticated path traversal in OPNMGR's snyk_scan_progress.php allowing arbitrary .json file…

exploitationinformation-gatheringpenetration-testing+3
19 days ago
CVE-2026-103445 preview

CVE-2026-103445

GitHubbombobombone/cve-2026-103445

Report summary and local proof-of-concept for CVE-2026-103445, a stored XSS in MediaWiki PageForms #autoedit via javascript: redirect URLs.

exploitationinformation-gatheringvulnerability-analysis+2
10 days ago
CVE-2026-102971 preview

CVE-2026-102971

GitHubbombobombone/cve-2026-102971

Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs.

exploitationinformation-gatheringpapers-research+3
11 days ago
CVE-2026-102425 preview

CVE-2026-102425

GitHubmurrez/cve-2026-102425

Python PoC for CVE-2026-102425: unauthenticated RCE in Joomla Balbooa Forms (com_baforms) via field shortcode injection in post-submission PHP…

exploitationpayload-developmentpenetration-testing+5
11 days ago
CVE-2026-101110 preview

CVE-2026-101110

GitHubmurrez/cve-2026-101110

Python 3 PoC and mass exploit for CVE-2026-101110, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Book Library <=6.4.6 via…

exploitationinformation-gatheringpenetration-testing+6
12 days ago
CVE-2026-101108 preview

CVE-2026-101108

GitHubmurrez/cve-2026-101108

Python 3 PoC and mass scanner for CVE-2026-101108, an unauthenticated ORDER BY SQL injection in OrdaSoft Joomla Vehicle Manager <=6.5.7…

exploitationinformation-gatheringpenetration-testing+5
12 days ago
CVE-2026-100752 preview

CVE-2026-100752

GitHubmurrez/cve-2026-100752

Python 3 PoC and mass exploit for CVE-2026-100752, an unauthenticated SQL injection in OrdaSoft Joomla Real Estate Manager <=6.7.8 via the…

exploitationinformation-gatheringpenetration-testing+6
12 days ago
CVE-2026-12227 preview

CVE-2026-12227

GitHubbe-keb/cve-2026-12227

Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI in the WordPress Visual Composer plugin (<=45.16.0) enabling file…

exploitationinformation-gatheringpenetration-testing+5
114 days ago
CVE-2026-12227 preview

CVE-2026-12227

GitHubmrdark-ops/cve-2026-12227

Proof-of-concept and technical analysis for CVE-2026-12227, an unauthenticated LFI/RCE in the WordPress Visual Composer plugin via the vcv-template…

exploitationinformation-gatheringpenetration-testing+4
10 days ago
CVE-2026-17089-PoC-pwnVader preview

CVE-2026-17089-PoC-pwnVader

GitHubpwnvader/cve-2026-17089-poc-pwnvader

Shell PoC for CVE-2026-17089, an unauthenticated reflected XSS in the WordPress Events Manager plugin (<= 7.4.0.1); fingerprints the plugin and tests…

exploitationinformation-gatheringpenetration-testing+5
18 days ago
CVE-2026-18143 preview

CVE-2026-18143

GitHubmurrez/cve-2026-18143

Python PoC that checks and exploits CVE-2026-18143, an unauthenticated arbitrary file upload in Addify Request a Quote for WooCommerce ≤ 2.9.2 via…

exploitationpayload-developmentpenetration-testing+5
15 days ago
CVE-2026-48908 preview

CVE-2026-48908

GitHubwinrarzipsexploit/cve-2026-48908

Python exploit suite for CVE-2026-48908, an unauthenticated ZIP upload RCE in Joomla SP Page Builder (<=6.6.1), with fingerprinting, batch mode, and…

exploitationpayload-developmentpenetration-testing+5
23 days ago
dj preview

dj

GitHubejfkdev/dj

Extracts dynamically loaded JavaScript files by statically analyzing website HTML and JS, detecting webpack chunks, import() lazy loading, and source…

anti-botcrawlerfingerprint-spoofing+7
6012 days ago
trawl preview

trawl

GitHubgermondai/trawl

Self-hosted scraping engine — bypasses any JS challenge & captcha: Cloudflare, Turnstile, reCAPTCHA, hCaptcha, GeeTest. FlareSolverr & Byparr…

anti-botcaptcha-bypasscrawler+5
9712 days ago
Previous12…77Next