Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
vulnerability-in-Remix-React-Router-CVE-2025-31137- preview

vulnerability-in-Remix-React-Router-CVE-2025-31137-

GitHubpouriam23/vulnerability-in-remix-react-router-cve-2025-31137-

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

ctfeducationexploitation+3
1
1 year ago
waf-checker preview

waf-checker

GitHubpapamica/waf-checker

Tests your WAF with +160 payloads

api-security-testingdns-analysisids-ips-evasion+8
5616 months ago
BoxPwnr preview

BoxPwnr

GitHub0ca/boxpwnr

A modular framework for benchmarking LLMs and agentic strategies on security challenges across HackTheBox, TryHackMe, PortSwigger Labs, Cybench,…

ai-securityctfeducation+8
4602 months ago
wafparan01d3 preview

wafparan01d3

GitHubalt3kx/wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

configuration-auditingdefensive-toolspenetration-testing+2
244 years ago
headerpwn preview

headerpwn

GitHubdevanshbatham/headerpwn

A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers

fuzzingvulnerability-analysisweb-security
3703 years ago
Interview_Tips preview

Interview_Tips

GitHubjigerjain/interview_tips

Summary of Cyber Security interview questions I have been through, hope this helps

binary-exploitationcloud-securitycryptography+5
716 years ago
PP_CVE-2024-38998 preview

PP_CVE-2024-38998

GitHubcesarbtakeda/pp_cve-2024-38998

Analyzes CVE-2024-38998, a prototype pollution vulnerability in requirejs 2.3.6, demonstrating how malicious config inputs can lead to DoS, RCE, or…

educationexploitationpapers-research+2
11 year ago
log4j-2021-vulnerability-study preview

log4j-2021-vulnerability-study

GitHubotaviokr/log4j-2021-vulnerability-study

This is a showcase how the Log4J vulnerability (CVE-2021-44228) could be explored. This code is safe to run, but understand what it does and how it…

code-analysiseducationexploitation+2
4 years ago
WordPressMassExploiter preview

WordPressMassExploiter

GitHubdmonst3r/wordpressmassexploiter

[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS

exploitationinformation-gatheringreconnaissance+3
318 years ago
vuln-chain-lab preview

vuln-chain-lab

GitHubechosecure/vuln-chain-lab

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

ctfeducationlabs-practice+5
16 months ago
A2SV--SSL-VUL-Scan preview

A2SV--SSL-VUL-Scan

GitHubanthophilee/a2sv--ssl-vul-scan

A2SV = Auto Scanning to SSL Vulnerability HeartBleed, CCS Injection, SSLv3 POODLE, FREAK... etc Support Vulnerability [CVE-2007-1858] Anonymous…

encryption-decryption-toolsexploitationnetwork-security+3
55 years ago
CVE-2025-60378 preview

CVE-2025-60378

GitHubajansha/cve-2025-60378

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

educationexploitationphishing+3
0 years ago
HotelDruid-CVE-2021-42948 preview

HotelDruid-CVE-2021-42948

GitHubdhammon/hoteldruid-cve-2021-42948

Analyzes CVE-2021-42948, a session token exposure vulnerability in HotelDruid, demonstrating how GET parameters leak session IDs and enable session…

exploitationinformation-gatheringpenetration-testing+2
4 years ago
nowafpls preview

nowafpls

GitHubassetnote/nowafpls

Burp Plugin to Bypass WAFs through the insertion of Junk Data

ids-ips-evasionpenetration-testingred-teaming+3
1.5k1 year ago
CVE-2025-29927-PoC preview

CVE-2025-29927-PoC

GitHubalihussainzada/cve-2025-29927-poc

PoC for CVE-2025-29927: Next.js Middleware Bypass Vulnerability. Demonstrates how x-middleware-subrequest can bypass authentication checks. Includes…

authentication-authorizationexploitationpenetration-testing+3
61 year ago
Suricata-Rule-for-Detecting-CVE-2025-55182 preview

Suricata-Rule-for-Detecting-CVE-2025-55182

GitHubsolidevil14/suricata-rule-for-detecting-cve-2025-55182

CVE‑2025‑55182 Detection

exploitationids-ips-evasionintrusion-detection+3
10 months ago
CVE-2026-34070 preview

CVE-2026-34070

GitHubrickidevs/cve-2026-34070

I Found a Zero-Day Vulnerability in langchain — Here’s How It Went

educationexploitationpapers-research+2
6 months ago
CVE-2025-4102025 preview

CVE-2025-4102025

GitHubimthecopilotnow/cve-2025-4102025

Security advisory detailing a critical CVE in Copilot AI where RAG-based citation links are forged to a third-party domain, enabling source…

educationmisconfigurationpapers-research+3
1 year ago
Previous1234Next