Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2902 results
VulnerableGWTApp preview

VulnerableGWTApp

GitHubbishopfox/vulnerablegwtapp

An intentionally-vulnerable GWT-based web application to test tooling and techniques

educationexploitationlabs-practice+4
5
2 years ago
bro-shellshock preview

bro-shellshock

GitHubcorelight/bro-shellshock

ShellShock attack and exploit detector for Bro.

intrusion-detectionnetwork-securityvulnerability-analysis+1
28 years ago
http2-bomb-analysis-paper preview

http2-bomb-analysis-paper

GitHubminc-nice-100/http2-bomb-analysis-paper

HTTP/2 Bomb: HPACK indexed-reference amplification + flow-control stall. A high school student's full protocol analysis (LaTeX). CVE-2026-49975,…

educationnetwork-securitypapers-research+2
12 months ago
dmz-security-monitoring-hardening preview

dmz-security-monitoring-hardening

GitHubfreeguy-6/dmz-security-monitoring-hardening

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

configuration-auditingdefensive-toolseducation+5
11 month ago
CVE-2026-14802 preview

CVE-2026-14802

GitHubiamdremig/cve-2026-14802

Compact CVE reference: OS command injection in create-react-app before 5.0.2 on macOS via react-dev-utils openBrowser.js, including affected versions…

exploitationvulnerability-analysisweb-security
127 days ago
CVE-2021-41773 preview

CVE-2021-41773

GitHuborangmuda/cve-2021-41773

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

educationexploitationlabs-practice+3
24 years ago
cve-2020-0601_poc preview

cve-2020-0601_poc

GitHubgremwell/cve-2020-0601_poc

Proof-of-concept exploit for CVE-2020-0601 (Windows CryptoAPI spoofing) that generates rogue CA certificates to intercept HTTPS traffic, with…

cryptographyeducationexploitation+2
26 years ago
litespeed-cpanel-cve-2026-54420-fix preview

litespeed-cpanel-cve-2026-54420-fix

GitHubmahfuzreham/litespeed-cpanel-cve-2026-54420-fix

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

cloud-securityconfiguration-auditingdefensive-tools+7
22 months ago
ImCurvin preview

ImCurvin

GitHubskokoo/imcurvin

Automated web security auditing tool that detects environment misconfigurations, probes backend vulnerabilities, and bypasses WAF/IDS protections…

ids-ips-evasioninformation-gatheringmisconfiguration+5
121 days ago
CVE-2015-9251 preview

CVE-2015-9251

GitHubhackgiver/cve-2015-9251

Proof-of-Concept exploit for CVE-2015-9251, a cross-site scripting (XSS) vulnerability in jQuery versions prior to 3.0.0, demonstrating attack…

exploitationpenetration-testingvulnerability-analysis+2
21 year ago
CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability preview

CVE-2024-23897-Jenkins-Arbitrary-Read-File-Vulnerability

GitHubgraysignal/cve-2024-23897-jenkins-arbitrary-read-file-vulnerability

Unauthenticated Jenkins CLI exploit scanner for CVE-2024-23897 that detects vulnerable versions and reads arbitrary files from the controller through…

data-exfiltrationexploitationinformation-gathering+4
32 years ago
CVE-2025-2005 preview

CVE-2025-2005

GitHubmrmtwoj/cve-2025-2005

WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)

exploitationpayload-generationpenetration-testing+3
31 year ago
CVE-2023-35813 preview

CVE-2023-35813

GitHubher3ticavi/cve-2023-35813

Proof-of-concept script to detect vulnerable Sitecore instances by analyzing server response headers for specific modifications, aiding in…

exploitationpenetration-testingreconnaissance+2
35 months ago
CVE-2025-55888 preview

CVE-2025-55888

GitHub0xzerosec/cve-2025-55888

Proof-of-concept exploit demonstrating an XSS vulnerability in ARD's Ajax transaction manager endpoint through unsanitized accountName input,…

exploitationpenetration-testingvulnerability-analysis+2
411 months ago
CVE-2022-43959 preview

CVE-2022-43959

GitHubsecware-ru/cve-2022-43959

Bitrix Vulnerability CVE-2022-43959

authenticationconfiguration-auditingmisconfiguration+3
43 years ago
CVE-2025-10720-PoC preview

CVE-2025-10720-PoC

GitHublorenzocamilli/cve-2025-10720-poc

Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to…

authentication-authorizationexploitationpenetration-testing+3
3 months ago
CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb- preview

CVE-2026-67185-Unauthenticated-Path-Traversal-Allows-Arbitrary-File-Read-TinyWeb-

GitHubtheopaid/cve-2026-67185-unauthenticated-path-traversal-allows-arbitrary-file-read-tinyweb-

Security Advisory: Unauthenticated Path Traversal Allows Arbitrary File Read (TinyWeb)

code-analysiseducationexploitation+2
1 month ago
cve-2026-34486-tomcat_encrypt_bypass_reproduction preview

cve-2026-34486-tomcat_encrypt_bypass_reproduction

GitHubrazureink/cve-2026-34486-tomcat_encrypt_bypass_reproduction

CVE Reproduction: cve-2026-34486-tomcat_encrypt_bypass_reproduction

educationexploitationpenetration-testing+3
1 month ago
Previous1…979899100Next