Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
390 results
CVE-2019-17638-Jetty preview

CVE-2019-17638-Jetty

GitHubforse01/cve-2019-17638-jetty

Exploit for CVE-2019-17638 targeting Jetty Java HTTP server, enabling remote code execution via crafted HTTP requests for security testing and…

exploitationpenetration-testingvulnerability-analysis+2
1
5 years ago
HTTP-2-RapidReset-CVE-2023-44487-Testlab preview

HTTP-2-RapidReset-CVE-2023-44487-Testlab

GitHubtlevente20/http-2-rapidreset-cve-2023-44487-testlab

Docker lab for reproducing and studying CVE-2023-44487 (HTTP/2 Rapid Reset) for thesis research, providing a controlled environment for vulnerability…

educationexploitationlabs-practice+2
3 months ago
wpscan preview

wpscan

GitHubwpscanteam/wpscan

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

crawlerdynamic-code-analysisinformation-gathering+7
9.8k20h 3m ago
cyberpanel preview

cyberpanel

GitHubusmannasir/cyberpanel

Cyber Panel - The hosting control panel for OpenLiteSpeed

ai-securitycloud-infrastructure-securityconfiguration-auditing+4
2.0k2 days ago
CVE-2012-4431 preview

CVE-2012-4431

GitHubimjdl/cve-2012-4431

Apache Tomcat source code repository for CVE-2012-4431, a Java servlet container vulnerability. Provides the vulnerable codebase for analysis and…

general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
7 years ago
CVE-2025-47445-PoC preview

CVE-2025-47445-PoC

GitHubinverterad/cve-2025-47445-poc

Proof-of-concept exploit for CVE-2025-47445, a path traversal vulnerability in the WordPress Eventin plugin. Includes setup instructions for a local…

educationexploitationpenetration-testing+3
7 months ago
REACT-CVE-2025-55182-Lab preview

REACT-CVE-2025-55182-Lab

GitHubandroidteacher/react-cve-2025-55182-lab

Lab with PoC

ctfeducationexploitation+5
7 months ago
motionEye-RCE-through-config-parameter preview

motionEye-RCE-through-config-parameter

GitHubprabhatverma47/motioneye-rce-through-config-parameter

PoC steps for this vulnerability

exploitationpenetration-testingred-teaming+3
20 years ago
jackhammer preview

jackhammer

GitHubolacabs/jackhammer

Jackhammer - One Security vulnerability assessment/management tool to solve all the security team problems.

code-analysisconfiguration-auditingdevsecops+9
7397 years ago
opentaint preview

opentaint

GitHubseqra/opentaint

Formal inter-procedural taint analysis engine for application security. Tracks untrusted data across function boundaries, persistence layers, and…

ai-securityapi-securitycode-analysis+7
1605 days ago
viewstate-security-workshop preview

viewstate-security-workshop

GitHubirsdl/viewstate-security-workshop

This repository is for the Testing ASP.NET ViewState with YSoNet (YSoSerial.NET) workshop.

educationexploitationlabs-practice+5
259 months ago
CVE-2026-39107 preview

CVE-2026-39107

GitHubmgtx2/cve-2026-39107

Detailed disclosure of a stored XSS vulnerability in Kimi AI v1.0's Preview tab, including attack scenario, PoC, and remediation guidance for…

educationpapers-researchvulnerability-analysis+2
3 months ago
CVE-2023-24329-lab preview

CVE-2023-24329-lab

GitHubjithinodattu/cve-2023-24329-lab

Self-contained Docker lab demonstrating CVE-2023-24329, a Python urllib parser differential that bypasses URL scheme and host filters, with…

ctfeducationexploitation+4
5 months ago
mimosa preview

mimosa

GitHubowasp/mimosa

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

ctfeducationlabs-practice+3
3 years ago
wfuzz preview

wfuzz

GitHubxmendez/wfuzz

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

fuzzingpenetration-testingvulnerability-analysis+2
6.6k8 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHuborangmuda/cve-2021-41773

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

educationexploitationlabs-practice+3
24 years ago
VulnLab preview

VulnLab

GitHubyavuzlar/vulnlab

Deliberately vulnerable web application lab for practicing exploitation of SQLi, XSS, CSRF, SSTI, IDOR, XXE, and 15+ other common web security flaws…

educationlabs-practiceweb-application-exploitation+1
5291 year ago
owtf preview

owtf

GitHubowtf/owtf

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

exploit-frameworkspenetration-testingpenetration-testing-frameworks+2
2.0k25 days ago
Previous1…456…22Next