Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
155 results
msploitego preview

msploitego

GitHubshizzz477/msploitego

Pentesting suite for Maltego based on data in a Metasploit database

exploit-frameworksinformation-gatheringnetwork-mapping+6
148
8 years ago
log4j-fuzzer preview

log4j-fuzzer

GitHubmr-vill4in/log4j-fuzzer

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.

exploitationfuzzingpenetration-testing+2
34 years ago
CVE-2026-40487 preview

CVE-2026-40487

GitHubastaruf/cve-2026-40487

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

exploitationpayload-developmentpenetration-testing+3
34 months ago
CVE-2025-3515 preview

CVE-2025-3515

GitHubprofessor6t9/cve-2025-3515

CVE‑2025‑3515 — Drag and Drop Multiple File Upload for Contact Form 7

exploitationpayload-generationpenetration-testing+3
11 year ago
POC-CVE-2025-52970 preview

POC-CVE-2025-52970

GitHubimbas007/poc-cve-2025-52970

Proof-of-concept exploit for CVE-2025-52970, allowing security researchers to test single or multiple target URLs for the vulnerability.

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
CVE-2022-48197 preview

CVE-2022-48197

GitHubryan412/cve-2022-48197

Reflected XSS vulnerability disclosure for Yahoo YUI library, with proof-of-concept exploits across multiple PHP endpoints for security testing and…

information-gatheringpenetration-testingvulnerability-analysis+2
3 years ago
Bheem preview
Archived

Bheem

GitHubharsh-bothra/bheem

Scope-based reconnaissance automation framework that orchestrates multiple open-source tools for subdomain enumeration, vulnerability scanning, and…

dns-analysisfuzzinginformation-gathering+5
3755 years ago
security-advisories preview

security-advisories

GitHubgregdurys/security-advisories

Curated collection of public security advisories detailing CVEs and CWEs across multiple products, intended for defensive research and educational…

curated-resourceseducationexploitation+3
1 month ago
bluekeep preview

bluekeep

GitHubdavidfortytwo/bluekeep

Python-based checker and exploit for BlueKeep (CVE-2019-0708) RDP vulnerability. Scans multiple IPs to identify unpatched Windows systems and enables…

exploitationnetwork-securitypenetration-testing+3
3 years ago
CVE-2025-3515 preview

CVE-2025-3515

GitHubblueisbeautiful/cve-2025-3515

WordPress File Upload RCE Exploit

exploitationpayload-generationpenetration-testing+3
171 year ago
CVE-2026-5718 preview

CVE-2026-5718

GitHubxxconi/cve-2026-5718

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

code-analysisexploitationpayload-development+5
3 months ago
cisco-CVE-2023-20198-tester preview

cisco-CVE-2023-20198-tester

GitHubsecurityphoenix/cisco-cve-2023-20198-tester

cisco-CVE-2023-20198-tester

exploitationnetwork-securitypenetration-testing+2
12 years ago
xssmap preview

xssmap

GitHubjewel591/xssmap

Python-based XSS vulnerability scanner with support for POST/GET requests, parameter injection in cookies/referer/user-agent, and multiple encoding…

penetration-testingvulnerability-analysisweb-security+1
2706 years ago
CVE-2021-35956 preview

CVE-2021-35956

GitHubtcbutler320/cve-2021-35956

Proof of Concept Exploit for CVE-2021-35956, AKCP sensorProbe - 'Multiple' Cross Site Scripting (XSS)

exploitationpenetration-testingvulnerability-analysis+2
15 years ago
CVE-2023-46003 preview

CVE-2023-46003

GitHubleekenghwa/cve-2023-46003

Proof-of-concept for a stored XSS vulnerability in i-doit Pro 25 and below, demonstrating payload injection via multiple parameters and components…

information-gatheringpenetration-testingvulnerability-analysis+2
2 years ago
multi-juicer preview

multi-juicer

GitHubjuice-shop/multi-juicer

Host and manage multiple Juice Shop instances for security trainings and Capture The Flags

ctfeducationlabs-practice+1
3221 day ago
CVE-2018-25031 preview

CVE-2018-25031

GitHublucasrenaa/cve-2018-25031

Python-based proof-of-concept script demonstrating CVE-2018-25031 XSS vulnerability in Swagger UI using Selenium for automated detection across…

api-securityeducationexploitation+3
2 years ago
pegasus-neo preview

pegasus-neo

GitHubsobri3195/pegasus-neo

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

exploitationforensicsosint+9
1246 months ago
Previous1234…9Next