Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
41 results
nex-forms_SQL-Injection-CVE-2023-2114 preview

nex-forms_SQL-Injection-CVE-2023-2114

GitHubschmidalex/nex-forms_sql-injection-cve-2023-2114

Quick Review about the SQL-Injection in the NEX-Forms Plugin for WordPress

exploitationpenetration-testingvulnerability-analysis+2
2
3 years ago
CVE-2019-10475 preview

CVE-2019-10475

GitHubvesche/cve-2019-10475

Reflected XSS proof-of-concept exploit for Jenkins build-metrics plugin CVE-2019-10475, with a Python weaponization script for generating malicious…

exploitationpayload-generationpenetration-testing+3
134 years ago
hakrawler preview

hakrawler

GitHubhakluke/hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

crawlerinformation-gatheringpenetration-testing+2
5.1k23 days ago
arsenal preview

arsenal

GitHuborange-cyberdefense/arsenal

Arsenal is just a quick inventory and launcher for hacking programs

command-and-controldns-analysisexploitation+6
3.8k1 year ago
pentest-tools preview

pentest-tools

GitHubgwen001/pentest-tools

A collection of custom security tools for quick needs.

dns-subdomain-enumerationfuzzinginformation-gathering+7
3.3k3 years ago
Atlas preview

Atlas

GitHubm4ll0k/atlas

Quick SQLMap Tamper Suggester

penetration-testingvulnerability-scannerswaf-bypass+1
1.4k5 years ago
BurpBounty preview

BurpBounty

GitHubwagiro/burpbounty

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and…

penetration-testingvulnerability-scannersweb-security
1.8k3 years ago
exim-rce-quickfix preview

exim-rce-quickfix

GitHubbananaphones/exim-rce-quickfix

quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centos

exploitationpenetration-testingred-teaming+2
227 years ago
CVE-2020-0688-Scanner preview

CVE-2020-0688-Scanner

GitHubonsec-fr/cve-2020-0688-scanner

Quick tool for checking CVE-2020-0688 on multiple hosts with a non-intrusive method.

exploitationinformation-gatheringpenetration-testing+3
375 years ago
wafparan01d3 preview

wafparan01d3

GitHubalt3kx/wafparan01d3

Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool

configuration-auditingdefensive-toolspenetration-testing+2
244 years ago
Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js preview

Quickcheck-CVE-2025-55182-React-and-CVE-2025-66478-Next.js

GitHubbankkroll/quickcheck-cve-2025-55182-react-and-cve-2025-66478-next.js

Script to quick check CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Critical unauthenticated RCE vulnerabilities in the React Server…

code-analysisexploitationinformation-gathering+3
128 months ago
Invoke-SelfSignedWebRequest preview

Invoke-SelfSignedWebRequest

GitHub0sm0s1z/invoke-selfsignedwebrequest

This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and press on with…

command-and-controlids-ips-evasionpenetration-testing+4
129 years ago
wpjuicer preview

wpjuicer

GitHubtaurusomar/wpjuicer

WP Juicer Tool for quick scanning of confidential information on WordPress endpoints.

information-gatheringreconnaissancevulnerability-scanners+1
102 years ago
acropadetect preview

acropadetect

GitHublordofpipes/acropadetect

Browser-based tool to detect Acropalypse (CVE-2023-21036) by analyzing PNG/GIF images for truncated pixel data, enabling quick vulnerability…

exploitationforensicsinformation-gathering+2
33 years ago
CVE-2024-24919 preview

CVE-2024-24919

GitHubbytenull00/cve-2024-24919

Scans multiple URLs for the CVE-2024-24919 vulnerability in Check Point products, providing a quick and simple batch-checking script.

exploitationpenetration-testingreconnaissance+2
32 years ago
CVE-2023-20198-IOS-XE-Scanner preview

CVE-2023-20198-IOS-XE-Scanner

GitHubmr-r3b00t/cve-2023-20198-ios-xe-scanner

Single-threaded PowerShell PoC scanner for CVE-2023-20198 targeting Cisco IOS XE devices. Quick proof-of-concept for vulnerability detection and…

exploitationnetwork-securitypenetration-testing+2
22 years ago
CVE-2012-1823 preview

CVE-2012-1823

GitHubdrone789/cve-2012-1823

Automated exploit for CVE-2012-1823, a PHP CGI remote code execution vulnerability. Provides a quick check script for vulnerable servers.

exploitationpenetration-testingvulnerability-analysis+2
110 years ago
CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description preview

CVE-2023-43344-Quick-CMS-Stored-XSS---SEO-Meta-description

GitHubsromanhu/cve-2023-43344-quick-cms-stored-xss---seo-meta-description

Quick CMS 6.7 is affected by a Cross-Site Scripting (XSS) vulnerability that allows attackers to execute arbitrary code via a crafted payload to the…

educationexploitationpenetration-testing+3
2 years ago
Previous123Next