Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
101 results
Striker preview

Striker

GitHubs0md3v/striker

Striker is an offensive information and vulnerability scanner.

information-gatheringport-scanningreconnaissance+3
2.3k7 years ago
Medusa preview

Medusa

GitHubascotbe/medusa

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

dns-analysisexploit-frameworkspayload-generation+4
2.2k3 years ago
responsible-disclosure-email-gathering preview

responsible-disclosure-email-gathering

GitHubrxerium/responsible-disclosure-email-gathering

A workflow to gather responsible disclosure emails from a given host(s).

email-harvestinginformation-gatheringosint+2
11 year ago
spiderfoot preview

spiderfoot

GitHubsmicallef/spiderfoot

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

dns-analysisemail-harvestinginformation-gathering+7
21.2k2 years ago
Osint-Sync preview

Osint-Sync

GitHubmixaoc/osint-sync

Browser extension for OSINT research enabling username, email, and phone number searches across 20+ platforms with integrated access to GHunt,…

email-harvestinginformation-gatheringosint+5
598 months ago
CVE-2026-54433 preview

CVE-2026-54433

GitHubaramosf/cve-2026-54433

Configurable Python PoC for CVE-2026-54433, a stored XSS in Roundcube's plain-text email renderer. Generates crafted .eml, sends via SMTP, and…

data-exfiltrationemail-securityexploitation+6
6 days ago
CVE-2026-XXXX-atlassian-email-enumeration preview

CVE-2026-XXXX-atlassian-email-enumeration

GitHubwh4l3x/cve-2026-xxxx-atlassian-email-enumeration

CVE-2026-XXXX: Atlassian GraphQL Email Enumeration Oracle (CWE-204, CVSS 5.3 MEDIUM)

email-harvestinginformation-gatheringosint+5
11 month ago
hosting preview

hosting

GitHubdanwin/hosting

Automated Tor-based shared web hosting server with PHP multi-version support, email routing, auto-scaling Tor instances, and built-in security…

configuration-auditingnetwork-securityprivacy+3
3704 months ago
wp2shell-Hestia-Scanner preview

wp2shell-Hestia-Scanner

GitHubbytespulse-oe/wp2shell-hestia-scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

ai-securitydefensive-toolsforensics+7
217 days ago
CVE-2023-5561-PoC preview

CVE-2023-5561-PoC

GitHubpog007/cve-2023-5561-poc

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

exploitationinformation-gatheringreconnaissance+2
42 years ago
CVE-2022-40348_Intern-Record-System-Cross-site-Scripting-V1.0-Vulnerability-Unauthenticated preview

CVE-2022-40348_Intern-Record-System-Cross-site-Scripting-V1.0-Vulnerability-Unauthenticated

GitHubh4md153v63n/cve-2022-40348_intern-record-system-cross-site-scripting-v1.0-vulnerability-unauthenticated

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)

exploitationpenetration-testingvulnerability-analysis+2
32 years ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
11 months ago
CVE-2025-66956 preview

CVE-2025-66956

GitHubthewoodenbench/cve-2025-66956

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute…

exploitationinformation-gatheringreconnaissance+2
6 months ago
CVE-2023-49546 preview

CVE-2023-49546

GitHubgeraldoalcantara/cve-2023-49546

Customer Support System 1.0 - SQL Injection Vulnerability in the "email" Parameter During "save_staff" Operation

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2023-6444-POC preview

CVE-2023-6444-POC

GitHubwayne-ker/cve-2023-6444-poc

Proof of concept on Unauthenticated Administrator Email Disclosure CVE-2023-6444

exploitationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2025-25965 preview

CVE-2025-25965

GitHubsudo-sakib/cve-2025-25965

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

educationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2024-0235-PoC preview

CVE-2024-0235-PoC

GitHubnxploited/cve-2024-0235-poc

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2024-25412 preview

CVE-2024-25412

GitHubparagbagul111/cve-2024-25412

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
Previous123456Next