Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
26 results
CVE-2021-44228-Test-Server preview

CVE-2021-44228-Test-Server

GitHubzlepper/cve-2021-44228-test-server

A small server for verifing if a given java program is succeptibel to CVE-2021-44228

educationexploitationpenetration-testing+2
3
4 years ago
WPScan preview

WPScan

GitHubalessiodallapiazza/wpscan

WordPress security scanner that enumerates vulnerable plugins, themes, and users to identify misconfigurations and known vulnerabilities for…

information-gatheringpenetration-testingreconnaissance+3
3113 years ago
wordpress-really-simple-security-authn-bypass-exploit preview

wordpress-really-simple-security-authn-bypass-exploit

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-exploit

Python exploit for CVE-2024-10924 authentication bypass in Really Simple Security < 9.1.2. Enables unauthenticated login as any existing WordPress…

authentication-authorizationexploitationpenetration-testing+3
191 year ago
Corsy preview

Corsy

GitHubs0md3v/corsy

CORS Misconfiguration Scanner

misconfigurationvulnerability-scannersweb-security
1.5k4 years ago
PathFinder preview

PathFinder

GitHubhalildeniz/pathfinder

Python-based web reconnaissance tool that extracts site metadata, DNS records, subdomains, firewall names, technologies, and certificate details for…

information-gatheringosintreconnaissance+1
602 years ago
wordpress-jetpack-broken-access-control-exploit preview

wordpress-jetpack-broken-access-control-exploit

GitHubm3ssap0/wordpress-jetpack-broken-access-control-exploit

Python exploit for Jetpack < 13.9.1 broken access control (CVE-2024-9926). Allows authenticated users to read visitor-submitted forms on WordPress…

exploitationinformation-gatheringpenetration-testing+3
31 year ago
privacytests preview

privacytests

GitHubprivacytests/privacytests

Automates browser privacy testing and renders human-readable results across fingerprinting, tracking, and data-leak vectors.

fingerprint-spoofinginformation-gatheringnetwork-security+2
1.2k1 day ago
waf-tester preview

waf-tester

GitHubkpomin57/waf-tester

A program for testing WAF functionality

api-security-testingeducationids-ips-evasion+5
264 months ago
CVE-2023-23752 preview

CVE-2023-23752

GitHubz3n70/cve-2023-23752

simple program for joomla CVE-2023-23752 scanner for pentesting and educational purpose

educationexploitationpenetration-testing+2
173 years ago
GitDorker preview

GitDorker

GitHubobheda12/gitdorker

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

information-gatheringosintreconnaissance+2
2.6k5 years ago
cve-2021-3449 preview

cve-2021-3449

GitHubriptl/cve-2021-3449

CVE-2021-3449 OpenSSL denial-of-service exploit 👨🏻‍💻

exploitationpenetration-testingvulnerability-analysis+1
2245 years ago
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k20 days ago
CVE-2026-14382 preview

CVE-2026-14382

GitHubjaf0rk/cve-2026-14382

Proof-of-concept exploit for CVE-2026-14382, a high-severity ANGLE vulnerability in Chromium, with 32-bit and AArch64 PoCs achieving program counter…

android-securitybinary-exploitationexploitation+4
71 month ago
WP-Ateck preview

WP-Ateck

GitHubero-hack/wp-ateck

With this program you can penetrate WordPress sites.

penetration-testingvulnerability-scannersweb-security
32 years ago
Log4j_Vulnerability_Demo preview

Log4j_Vulnerability_Demo

GitHubchandanshastri/log4j_vulnerability_demo

A simple program to demonstrate how Log4j vulnerability can be exploited ( CVE-2021-44228 )

educationexploitationlog-analysis+2
34 years ago
CVE-2014-0094-test-program-for-struts1 preview

CVE-2014-0094-test-program-for-struts1

GitHubhasegawatadamitsu/cve-2014-0094-test-program-for-struts1

CVE-2014-0094 test program for struts1

educationexploitationpenetration-testing+3
18 years ago
MasterHttpRelayVPN-RUST preview

MasterHttpRelayVPN-RUST

GitHubtherealaleph/masterhttprelayvpn-rust

Rust port of @masterking32's MasterHttpRelayVPN — all credit to @masterking32 for the original idea and Python implementation. Free DPI bypass via a…

dns-analysisweb-security
3.6k5 days ago
subzy preview

subzy

GitHubpentestpad/subzy

Subdomain takeover vulnerability checker

misconfigurationpenetration-testingreconnaissance+2
1.6k1 year ago
Previous12Next