Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
88 results
CVE-2022-39841 preview

CVE-2022-39841

GitHubstealthcopter/cve-2022-39841

Proof-of-concept exploit for CVE-2022-39841 demonstrating plaintext credential leakage via unauthenticated WebSocket in Medusa. Includes blog post…

exploitationinformation-gatheringpenetration-testing+2
1
4 years ago
CVE-2024-9166 preview

CVE-2024-9166

GitHubandrysqui/cve-2024-9166

A vulnerability scanner that searches for the CVE-2024-9166 vulnerability on websites, more info about this vulnerability here:…

exploitationinformation-gatheringpenetration-testing+3
42 years ago
lucky13 preview

lucky13

GitHubwearohat/lucky13

Exploit for cve-2013-0169

cryptographyencryption-decryption-toolsexploitation+3
41 year ago
CVE-2023-22960 preview

CVE-2023-22960

GitHubt3l3machus/cve-2023-22960

This vulnerability allows an attacker to bypass the credentials brute-force prevention mechanism of the Embedded Web Server (interface) of more than…

exploitationpassword-attackspenetration-testing+1
913 years ago
CVE-2023-33977 preview

CVE-2023-33977

GitHubmnqazi/cve-2023-33977

Read more at Medium

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
Duplicate-of-CVE-2023-26982 preview

Duplicate-of-CVE-2023-26982

GitHubbypazs/duplicate-of-cve-2023-26982

Trudesk version 1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the tickets `Create/Modify Ticket Tags` on…

educationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2025-9215 preview

CVE-2025-9215

GitHubd0n601/cve-2025-9215

StoreEngine – Powerful WordPress eCommerce Plugin for Payments, Memberships, Affiliates, Sales & More <= 1.4.0 - Authenticated (Subscriber+)…

exploitationinformation-gatheringpenetration-testing+3
1 year ago
Parth preview

Parth

GitHubs0md3v/parth

Heuristic Vulnerable Parameter Scanner

information-gatheringpenetration-testingreconnaissance+2
6014 years ago
-CVE-2022-48150 preview

-CVE-2022-48150

GitHubsahilh4ck4you/-cve-2022-48150

I Found the reflected xss vulnerability in shopware 5 .for more details check my poc video

information-gatheringpenetration-testingvulnerability-analysis+2
13 years ago
cli preview

cli

GitHubhttpie/cli

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

api-security-testinggeneral-purpose-utilitiesweb-security
38.7k1 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubsagsooz/cve-2025-29927

🔐 Python-based smart scanner for CVE-2025-29927 — Next.js middleware authentication bypass vulnerability. Detects meta refresh, keyword-based…

authenticationeducationpenetration-testing+3
1 year ago
bbot preview

bbot

GitHubblacklanternsecurity/bbot

The recursive internet scanner for hackers. 🧡

crawlerdns-analysisemail-harvesting+8
10.7k1 month ago
eos preview

eos

GitHubsynacktiv/eos

Enemies Of Symfony - Debug mode Symfony looter

information-gatheringmisconfigurationpenetration-testing+3
3631 year ago
WebFEET preview

WebFEET

GitHubnccgroup/webfeet

Web Filter External Enumeration Tool (WebFEET)

information-gatheringpenetration-testingreconnaissance+2
7812 years ago
CVE-2026-71518 preview

CVE-2026-71518

GitHubilhomjonr/cve-2026-71518

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

authentication-authorizationexploitationpenetration-testing+3
11 month ago
apache__jspwiki_CVE-2019-10077_2-11-0-M3 preview

apache__jspwiki_CVE-2019-10077_2-11-0-M3

GitHubshoucheng3/apache__jspwiki_cve-2019-10077_2-11-0-m3

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

authentication-authorizationconfiguration-auditingexploitation+3
1 year ago
apache__jspwiki_CVE-2019-10078_2_11_0_M4_fixed preview

apache__jspwiki_CVE-2019-10078_2_11_0_M4_fixed

GitHubshoucheng3/apache__jspwiki_cve-2019-10078_2_11_0_m4_fixed

Exploit testing repository for Apache JSPWiki CVE-2019-10078, demonstrating a cross-site scripting vulnerability in a Java-based wiki platform with…

authentication-authorizationconfiguration-auditingeducation+3
1 year ago
apache__jspwiki_CVE-2019-10089_2-11-0-M4 preview

apache__jspwiki_CVE-2019-10089_2-11-0-M4

GitHubshoucheng3/apache__jspwiki_cve-2019-10089_2-11-0-m4

Java-based wiki platform with detailed access control and JAAS security integration, provided as a vulnerable version for security testing and CVE…

authentication-authorizationconfiguration-auditingeducation+3
1 year ago
Previous12345Next