Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
129 results
CVE-2026-41940 preview

CVE-2026-41940

GitHubasdasddqwdq29-a11y/cve-2026-41940

Redacted cPanel/WHM authentication bypass analysis and authorized checker

authentication-authorizationeducationexploitation+3
4 months ago
sudowp-adminer preview

sudowp-adminer

GitHubsudo-wp/sudowp-adminer

A secure, zero-trust database management tool for WordPress. Fixes critical SSRF vulnerabilities (CVE-2021-21311) by enforcing local connections only.

authentication-authorizationcloud-securitydatabase-security+3
16 months ago
BFuzz preview

BFuzz

GitHubrootup/bfuzz

Fuzzing Browsers

fuzzingvulnerability-analysisweb-security
3183 years ago
bucky preview

bucky

GitHubsmaranchand/bucky

Bucky (An automatic S3 bucket discovery tool)

cloud-securitymisconfigurationvulnerability-scanners+1
1974 years ago
CVE-2026-19598 preview

CVE-2026-19598

GitHubsag-asab/cve-2026-19598

Custom Content Types and Fields plugin for WordPress

authentication-authorizationexploitationvulnerability-analysis+2
21 month ago
CVE-2026-13610 preview

CVE-2026-13610

GitHubghostpels/cve-2026-13610

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

authentication-authorizationexploitationpenetration-testing+4
1 month ago
CVE-2023-4800 preview

CVE-2023-4800

GitHubb0marek/cve-2023-4800

Repository for CVE-2023-4800 vulnerability.

authentication-authorizationinformation-gatheringmisconfiguration+2
3 years ago
globaleaks-whistleblowing-software preview

globaleaks-whistleblowing-software

GitHubglobaleaks/globaleaks-whistleblowing-software

GlobaLeaks is a free and open-source whistleblowing software enabling anyone to easily set up and maintain a secure reporting platform.

defensive-toolsencryption-decryption-toolsprivacy+1
1.5k5 days ago
send preview

send

GitHubtimvisee/send

📬 Simple, private file sharing. Mirror of https://gitlab.com/timvisee/send

encryption-decryption-toolsprivacyutilities-frameworks+1
5.9k1 year ago
sudowp-postgallery preview

sudowp-postgallery

GitHubsudo-wp/sudowp-postgallery

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

authentication-authorizationcode-analysisconfiguration-auditing+3
16 months ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubjvr2022/cve-2026-31802

Proof of concept and technical write-up for CVE-2026-31802, a symlink path traversal in npm tar allowing arbitrary file overwrite outside extraction…

exploitationsupply-chain-securityvulnerability-analysis+1
16 months ago
CVE-2026-1769-WriteUp preview

CVE-2026-1769-WriteUp

GitHubleox48/cve-2026-1769-writeup

Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web)

curated-resourceseducationpapers-research+2
13 days ago
CVE-2026-31802 preview

CVE-2026-31802

GitHubrecorded-texteditor120/cve-2026-31802

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

curated-resourceseducationexploitation+3
11 day ago
CVE-2026-9848 preview

CVE-2026-9848

GitHubaj2108/cve-2026-9848

CVE-2026-9848 is an Unauthenticated SQL Injection (SQLi) vulnerability affecting the WP Ticket (Customer Support Ticket System & Helpdesk) plugin for…

educationvulnerability-analysisweb-application-exploitation+1
2 months ago
Crawlector preview

Crawlector

GitHubmfmokbel/crawlector

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

crawlerinformation-gatheringmalware-analysis+5
1239 months ago
CVE-2024-34312 preview

CVE-2024-34312

GitHubvincentscode/cve-2024-34312

☣️ This repository contains the description and a proof of concept for CVE-2024-34312

educationexploitationpapers-research+3
12 years ago
Heartbleed preview

Heartbleed

GitHubryo-soikutsu/heartbleed

Demonstration of the Heartbleed CVE (CVE-2014-0160), including lab setup instructions and source code to build your own Heartbleed lab for…

ctfeducationexploitation+3
6 months ago
CVE-2021-41773 preview

CVE-2021-41773

GitHuborangmuda/cve-2021-41773

Apache HTTPd (2.4.49) – Local File Disclosure (LFI)

educationexploitationlabs-practice+3
25 years ago
Previous12…8Next