Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
21 results
oss-oopssec-store preview

oss-oopssec-store

GitHubkoadt/oss-oopssec-store

Security training for the apps you actually ship. Open your browser and start hacking.

ai-securityctfeducation+7
42
14h 50m ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
188 days ago
CVE-2026-76564 preview

CVE-2026-76564

GitHubtoanln-cov/cve-2026-76564

Stored XSS via User-Agent in Admin Order View in PhocaCart

code-analysisexploitationpapers-research+3
14 days ago
training-security-awareness preview

training-security-awareness

GitHubransomleak/training-security-awareness

Open-source interactive security awareness training library with 130+ SCORM exercises covering phishing, vishing, BEC, MFA fatigue, and OWASP AI/LLM…

ai-securityeducationemail-security+5
1901 month ago
CVE-2026-52217-VTEX-Checkout-CrossTenant-IDOR preview

CVE-2026-52217-VTEX-Checkout-CrossTenant-IDOR

GitHubteteco/cve-2026-52217-vtex-checkout-crosstenant-idor

The VTEX Checkout Service exposes OrderForm data through the endpoints `/api/checkout/pub/orderForm/{orderFormId}` and `/attachments/*`. These…

api-securityauthentication-authorizationinformation-gathering+3
1 month ago
CVE-2026-33146 preview

CVE-2026-33146

GitHub0xmrma/cve-2026-33146

A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public…

educationinformation-gatheringpapers-research+3
2 months ago
CVE-2025-70849-Podinfo preview

CVE-2025-70849-Podinfo

GitHubkazisabu/cve-2025-70849-podinfo

PoC and Advisory for CVE-2025-70849: Unauthenticated Stored XSS in Podinfo /store endpoint.

educationexploitationpenetration-testing+3
4 months ago
CVE-2025-43529 preview

CVE-2025-43529

GitHubjir4vv1t/cve-2025-43529

Technical exploit for CVE-2025-43529, a WebKit DFG JIT compiler vulnerability enabling use-after-free via missing store barrier in concurrent GC,…

binary-exploitationexploitationmemory-forensics+3
868 months ago
CVE-2025-63943 preview

CVE-2025-63943

GitHubredopsx/cve-2025-63943

SQL Injection vulnerability discovered in Grocery Store Management System 1.0

code-analysisdatabase-securityexploitation+3
9 months ago
tough-cookie-patch-cve-2023-26136 preview

tough-cookie-patch-cve-2023-26136

GitHubguy2610/tough-cookie-patch-cve-2023-26136

RFC6265-compliant cookie parsing and CookieJar management library for Node.js, with CVE-2023-26136 security patch. Supports cookie creation,…

authenticationencryption-decryption-toolsgeneral-purpose-utilities+2
1 year ago
CVE-2025-4603 preview

CVE-2025-4603

GitHubd0n601/cve-2025-4603

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion

authenticationexploitationpenetration-testing+3
11 year ago
CVE-2025-4336 preview

CVE-2025-4336

GitHubd0n601/cve-2025-4336

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Upload via set_file Task

exploitationpayload-generationpenetration-testing+3
1 year ago
CVE-2024-46981 preview

CVE-2024-46981

GitHubpublicqi/cve-2024-46981

Proof-of-concept exploit for CVE-2024-46981 targeting Redis 6.2.11, demonstrating a remote code execution vulnerability in the in-memory data store.

database-securityexploitationpenetration-testing+2
51 year ago
CVE-2024-46981 preview

CVE-2024-46981

GitHubxsshk/cve-2024-46981

Proof-of-concept exploit for CVE-2024-46981 targeting Redis 6.2.11, demonstrating a remote code execution vulnerability in the in-memory data store.

database-securityexploitationpenetration-testing+2
1 year ago
CVE-2024-41290 preview

CVE-2024-41290

GitHubparagbagul111/cve-2024-41290

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data

authenticationexploitationinformation-gathering+3
1 year ago
VUL4J-23 preview

VUL4J-23

GitHubepicosy/vul4j-23

Curated Java web framework vulnerability (CVE-2016-5394) for Apache Sling, designed for security testing, exploitation practice, and vulnerability…

code-analysiseducationexploitation+3
2 years ago
openapi-parser preview

openapi-parser

GitHubaress31/openapi-parser

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

api-securityapi-security-testingpenetration-testing+2
2082 years ago
CVE-2023-49540 preview

CVE-2023-49540

GitHubgeraldoalcantara/cve-2023-49540

Book Store Management System v1.0 - Cross-site scripting (XSS) vulnerability in /index.php/history - vulnerable field: "Customer's Name".

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
Previous12Next