Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
486 results
certbot preview

certbot

GitHubcertbot/certbot

Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any…

authentication-authorizationcloud-securityconfiguration-auditing+3
33.2k
4 days ago
phpinfo-files-leaks preview

phpinfo-files-leaks

GitHubcappricio-securities/phpinfo-files-leaks

This tool is used to find php info page

information-gatheringmisconfigurationpenetration-testing+4
12 years ago
React2Shell-CVE-2025-55182-Detector preview

React2Shell-CVE-2025-55182-Detector

GitHubgarethmsheldon/react2shell-cve-2025-55182-detector

Multi-language detection scripts for CVE-2025-55182 (React2Shell) that scan package.json files to identify vulnerable React dependency versions and…

code-analysisscripting-automationsupply-chain-security+3
18 months ago
dirmap preview

dirmap

GitHubh4ckforjob/dirmap

An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu…

information-gatheringpenetration-testingreconnaissance+2
3.4k1 year ago
CVE-2025-46080 preview

CVE-2025-46080

GitHubyggcwhat/cve-2025-46080

Details

code-analysisexploitationmisconfiguration+3
1 year ago
Praeda preview

Praeda

GitHubpercx/praeda

Automated data harvesting tool for extracting sensitive information (backups, clones, address books) from web servers via targeted scanning and…

crawlerinformation-gatheringnetwork-mapping+3
1922 years ago
Burp_Collector preview

Burp_Collector

GitHubsajibuu/burp_collector

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

api-security-testinginformation-gatheringpenetration-testing+4
102 years ago
Gxss preview
Archived

Gxss

GitHubkathanp19/gxss

A tool to check a bunch of URLs that contain reflecting params.

information-gatheringpenetration-testingreconnaissance+2
6022 years ago
mssharepoint-scanner preview

mssharepoint-scanner

GitHubvirologi-info/mssharepoint-scanner

A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

defensive-toolsinformation-gatheringnetwork-security+3
2 days ago
CVE-2024-27630 preview

CVE-2024-27630

GitHubally-petitt/cve-2024-27630

CVE-2024–27630 Reference

educationinformation-gatheringpapers-research+3
2 years ago
CVE-2018-16373 preview

CVE-2018-16373

GitHubsnappyjack/cve-2018-16373

Frog CMS 0.9.5 has an Upload > vulnerability that can create files via > /admin/?/plugin/file_manager/save

exploitationmisconfigurationpenetration-testing+2
7 years ago
gitbook-xss preview

gitbook-xss

GitHubianxtianxt/gitbook-xss

xss for gitbook

exploitationvulnerability-analysisweb-application-exploitation+1
6 years ago
Check-WP-CVE-2020-35489 preview

Check-WP-CVE-2020-35489

GitHubdn9uy3n/check-wp-cve-2020-35489

The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489

exploitationpenetration-testingvulnerability-scanners+2
312 years ago
CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager preview

CVE-2023-43872-CMSmadesimple-Arbitrary-File-Upload--XSS---File-Manager

GitHubsromanhu/cve-2023-43872-cmsmadesimple-arbitrary-file-upload--xss---file-manager

CMSmadesimple 2.2.18 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
CVE-2023-43871-WBCE-Arbitrary-File-Upload--XSS---Media preview

CVE-2023-43871-WBCE-Arbitrary-File-Upload--XSS---Media

GitHubsromanhu/cve-2023-43871-wbce-arbitrary-file-upload--xss---media

WBCE 1.6.1 is affected by File Upload - XSS vulnerability that allows attackers to upload a PDF file with a hidden XSS that when executed will launch…

exploitationphishing-toolsvulnerability-analysis+2
2 years ago
Extracter preview

Extracter

GitHubk3ystr0k3r/extracter

A nice web-crawler written in Bash that will look for login pages/admin-panels for you on any given website.

crawlerinformation-gatheringosint+2
63 years ago
CVE-2025-56218 preview

CVE-2025-56218

GitHubsaykino/cve-2025-56218

Advisory detailing CVE-2025-56218, an unrestricted file upload vulnerability in Ascertia SigningHub allowing malicious Excel files with phishing…

curated-resourceseducationphishing+2
10 months ago
wwwgrep preview
Archived

wwwgrep

GitHubowasp/wwwgrep

OWASP Foundation Web Respository

code-analysisinformation-gatheringpenetration-testing+3
364 years ago
Previous12…27Next