Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k2 years ago
ChangeTower preview

ChangeTower

GitHubdc4ts/changetower

Lightweight web page change monitor written in Go. Detects updates on target URLs and sends notifications via Telegram or other services, ideal for…

crawlerinformation-gatheringweb-security
415 years ago
getrails preview

getrails

GitHubjul10l1r4/getrails

Get trails lib: Get all urls indexed of target

dns-subdomain-enumerationinformation-gatheringosint+1
4 years ago
CVE-2026-87902 preview

CVE-2026-87902

GitHubcrowsec-edtech/cve-2026-87902

Python PoC exploiting CVE-2026-87902, an unauthenticated path traversal in WordPress locate_template() leading to LFI and PEAR-based RCE, with safe…

exploitationlabs-practicepayload-development+5
311 days ago
CVE-2025-44136 preview

CVE-2025-44136

GitHubmheranco/cve-2025-44136

Proof-of-concept exploit for unauthenticated reflected XSS in MapTiler Tileserver-php v2.0 via the 'layer' GET parameter, enabling arbitrary HTML/JS…

exploitationpenetration-testingvulnerability-analysis+2
5 months ago
CVE-2025-10035_GoAnywhere preview

CVE-2025-10035_GoAnywhere

GitHuborange0mint/cve-2025-10035_goanywhere

CVE-2025-10035_GoAnywhere Get RCE

exploitationinformation-gatheringpenetration-testing+3
1 year ago
CVE-2023-33405 preview

CVE-2023-33405

GitHubhacip/cve-2023-33405

Proof-of-concept exploit for an open redirect vulnerability (CVE-2023-33405) in BlogEngine.NET CMS versions 3.3.8.0 and earlier, demonstrating…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2002-0748 preview

CVE-2002-0748

GitHubfauzanwijaya/cve-2002-0748

Proof of concept for LabVIEW Web Server HTTP Get Newline DoS vulnerability

exploitationpenetration-testingvulnerability-analysis+1
3 years ago
changedetection.io preview

changedetection.io

GitHubdgtlmoon/changedetection.io

Best and simplest tool for website change detection, web page monitoring, and website change alerts. Perfect for tracking content changes, price…

crawlerinformation-gatheringosint+2
34.7k9 days ago
Http11Probe preview

Http11Probe

GitHubmda2av/http11probe

An open testing platform that probes HTTP/1.1 servers against RFC 9110/9112 requirements, smuggling vectors, and malformed input handling. Add your…

api-security-testingfuzzingmisconfiguration+2
3014 days ago
CVE-2026-15282 preview

CVE-2026-15282

GitHubshinthink/cve-2026-15282

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

educationexploitationpayload-generation+5
2 months ago
permanet preview

permanet

GitHubpermanet/permanet

Cryptographically verifiable web archiving. Playwright capture → SHA-256 Merkle hash → Bitcoin-anchored OpenTimestamps → permanent Arweave storage.

cloud-securitycryptographydata-recovery+2
86 months ago
trellis-cve-2018-6389 preview
Archived

trellis-cve-2018-6389

GitHubitinerisltd/trellis-cve-2018-6389

Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks

configuration-auditingdefensive-toolsdevsecops+3
138 years ago
CVE-2026-76569 preview

CVE-2026-76569

GitHubtoanln-cov/cve-2026-76569

Reflected XSS via search GET Parameter in Phoca Download

exploitationpenetration-testingvulnerability-analysis+2
1 month ago
CVE-2026-7028-SQLI preview

CVE-2026-7028-SQLI

GitHubxmyronn/cve-2026-7028-sqli

Proof-of-concept exploit for SQL injection in CodeAstro Online Job Portal allowing authenticated deletion of all job records via crafted GET request.

exploitationpenetration-testingvulnerability-analysis+2
6 months ago
AutoPWN-Suite preview

AutoPWN-Suite

GitHubgamehunterkaan/autopwn-suite

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

exploitationinformation-gatheringnetwork-security+5
1.1k8 days ago
CVE-2020-0688 preview

CVE-2020-0688

GitHubzcgonvh/cve-2020-0688

Exploit and detect tools for CVE-2020-0688

exploitationinformation-gatheringpenetration-testing+2
3536 years ago
Phisher-man preview

Phisher-man

GitHubfdx100/phisher-man

Samples Phishing tools made for Linux it contains 30 different type of Phishing Pages made with flask

phishing-toolssocial-engineeringweb-security
1084 years ago
Previous12345Next