Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
5182 results
npm-demo preview

npm-demo

GitHubalonnavon/npm-demo

Browser demo: EJS template injection (CVE-2022-29078) with Seal Security remediation

code-analysiseducationvulnerability-analysis+2
6 months ago
CVE-2026-82221 preview

CVE-2026-82221

GitHubgabrielftanaka/cve-2026-82221

PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

exploitationpenetration-testingvulnerability-analysis+2
18h 36m ago
CVE-2026-27472-and-CVE-2026-27474 preview

CVE-2026-27472-and-CVE-2026-27474

GitHubtrachinus/cve-2026-27472-and-cve-2026-27474

Proof-of-concept for CVE-2026-27472 (blind SSRF) and CVE-2026-27474 (stored XSS) in SPIP 4.4.8 syndication feature, demonstrating exploitation steps…

exploitationpenetration-testingvulnerability-analysis+2
1 day ago
CVE-2026-30251 preview

CVE-2026-30251

GitHubvenablee/cve-2026-30251

Reflected XSS vulnerability disclosure for ZenShare Suite login_newpwd.php, allowing arbitrary JavaScript execution via crafted URL in codice_azienda…

exploitationpenetration-testingvulnerability-analysis+2
1 day ago
CVE-2026-30252 preview

CVE-2026-30252

GitHubvenablee/cve-2026-30252

The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery…

educationexploitationpapers-research+2
1 day ago
cve-2022-29117-assessment preview

cve-2022-29117-assessment

GitHubcharanmv08/cve-2022-29117-assessment

CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework

curated-resourceseducationvulnerability-analysis+1
1 day ago
CVE-2026-76569 preview

CVE-2026-76569

GitHubtoanln-cov/cve-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

exploitationpenetration-testingvulnerability-analysis+2
2 days ago
cacti-cve-2023-39361 preview

cacti-cve-2023-39361

GitHubspartanx-alejandro/cacti-cve-2023-39361

Exploit for CVE-2023-39361 in Cacti, a network graphing solution, demonstrating SQL injection vulnerability for educational and security testing…

exploitationpenetration-testingvulnerability-analysis+2
1 day ago
CVE-2025-0324-axis-vapix-privesc preview

CVE-2025-0324-axis-vapix-privesc

GitHubkemrec/cve-2025-0324-axis-vapix-privesc

Root-cause analysis and safety-gated verification tool for CVE-2025-0324, a privilege-escalation flaw in AXIS OS VAPIX allowing any authenticated…

binary-analysisexploitationfirmware-analysis+4
2 days ago
CVE-2026-60004-Gitea-Validator preview

CVE-2026-60004-Gitea-Validator

GitHubinfosec-db/cve-2026-60004-gitea-validator

🫖 Contract-correlated discovery and authorized validation tool for Gitea CVE-2026-60004

exploitationpenetration-testingreconnaissance+2
2 days ago
admin-panel-finder preview

admin-panel-finder

GitHubbdblackhat/admin-panel-finder

Python script to discover admin panel URLs of websites, aiding in security reconnaissance and penetration testing.

information-gatheringpenetration-testingreconnaissance+2
1924 years ago
enhanced-iframe-protection preview

enhanced-iframe-protection

GitHubmalwarecube/enhanced-iframe-protection

A lightweight extension to automatically detect and provide verbose warnings for embedded iframe elements in order to protect against…

defensive-toolseducationphishing+1
503 years ago
phpBB-CVE-2026-48611 preview

phpBB-CVE-2026-48611

GitHubethicalgrey/phpbb-cve-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

authentication-authorizationexploitationinformation-gathering+5
2 days ago
cve-2026-67363-67364 preview

cve-2026-67363-67364

GitHublulztigre/cve-2026-67363-67364

PoC and detection templates for pre-auth RCE and payment tampering in Balbooa Forms (Joomla), including Python exploit and Nuclei detection template.

exploitationpayload-developmentpenetration-testing+3
2 days ago
WP2Shell-Scanner preview

WP2Shell-Scanner

GitHubsec-dan/wp2shell-scanner

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

information-gatheringpenetration-testingreconnaissance+3
2 days ago
shellshock-cve-lab preview

shellshock-cve-lab

GitHubvaibhav91one/shellshock-cve-lab

Intentionally vulnerable CGI lab for Shellshock (CVE-2014-6271) with a Python RFC-3875 server and GNU bash 4.2, designed for isolated security…

educationexploitationlabs-practice+2
2 days ago
Project-CVE-2026-65351 preview

Project-CVE-2026-65351

GitHube4zyy/project-cve-2026-65351

Browser resource exhaustion payload that crashes target systems via memory, GPU, audio, and rendering overload. Designed for authorized security…

exploitationred-teamingvulnerability-analysis+1
5 days ago
CVE-2026-76581-Detector preview

CVE-2026-76581-Detector

GitHubhackersroot/cve-2026-76581-detector

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

curated-resourceseducationvulnerability-scanners+1
2 days ago
Previous12…100Next