Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
372 results
cve-2025-66723 preview

cve-2025-66723

GitHubaudiopump/cve-2025-66723

CVE-2025-66723: inMusic Brands Engine DJ >=3.0.0 through <4.3.4 exposes local and network files to external parties

data-exfiltrationexploitationinformation-gathering+3
8 months ago
Tools preview

Tools

GitHubcyberguideme/tools

Cyber Security Tools

cryptographycurated-resourceseducation+6
4447 years ago
CVE-2025-4322-Exploit preview

CVE-2025-4322-Exploit

GitHubindominusrexes/cve-2025-4322-exploit

Critical CVE-2025-4322 exploit for Firefox on Windows enabling sandbox escape and arbitrary code execution. Includes download link and technical…

exploitationmalware-analysispenetration-testing+2
11 year ago
CVE-2018-8065 preview

CVE-2018-8065

GitHubegebalci/cve-2018-8065

Flexense HTTP Server <= 10.6.24 - Denial Of Service Exploit

exploitationpenetration-testingvulnerability-analysis+1
68 years ago
CVE-2023-29808 preview

CVE-2023-29808

GitHubzprototype/cve-2023-29808

Reflected cross-site scripting (XSS) proof-of-concept exploit for CVE-2023-29808 targeting the /index.php?map=overview&findme= endpoint in cmaps…

exploitationpenetration-testingvulnerability-analysis+2
43 years ago
CVE-2026-25253 preview

CVE-2026-25253

GitHubkajzingerakos/cve-2026-25253

Proof-of-concept exploit for CVE-2026-25253, demonstrating one-click remote code execution in OpenClaw via authentication token theft and cross-site…

authenticationexploitationred-teaming+3
15 months ago
ZeroPoint preview

ZeroPoint

GitHubgmh5225/zeropoint

This PowerShell script detects indicators of compromise for CVE-2025-53770 — a critical RCE vulnerability in Microsoft SharePoint. Created by…

defensive-toolsexploitationincident-response+3
1 year ago
Dissecting-CVE-2026-0628-Chromium-Extension-Privilege-Escalation preview

Dissecting-CVE-2026-0628-Chromium-Extension-Privilege-Escalation

GitHubsastraadiwiguna-purpleeliteteaming/dissecting-cve-2026-0628-chromium-extension-privilege-escalation

Technical dissection of CVE-2026-0628, a Chromium WebView privilege escalation vulnerability, including root cause analysis, PoC exploit, detection…

digital-forensicsexploitationmalware-analysis+3
18 months ago
webstor preview

webstor

GitHubrossgeerlings/webstor

Enumerates all websites across an organization's networks via DNS zone transfers and masscan, stores responses, and enables querying for known…

dns-analysisinformation-gatheringreconnaissance+2
1582 years ago
Project-CVE-2026-75604 preview

Project-CVE-2026-75604

GitHube4zyy/project-cve-2026-75604

Python-based exploitation framework for CVE-2026-75604, enabling authorized pentesters to validate Next.js Windows cache traversal vulnerabilities…

exploitationpayload-developmentpenetration-testing+4
31 month ago
bluekeep preview

bluekeep

GitHubdavidfortytwo/bluekeep

Python-based checker and exploit for BlueKeep (CVE-2019-0708) RDP vulnerability. Scans multiple IPs to identify unpatched Windows systems and enables…

exploitationnetwork-securitypenetration-testing+3
3 years ago
CVE-2024-32002-EXP preview

CVE-2024-32002-EXP

GitHub10cks/cve-2024-32002-exp

Bash PoC for CVE-2024-32002 that exploits Git clone with malicious submodules and symlinks to execute arbitrary commands on Windows and macOS.

educationexploitationpayload-development+3
22 years ago
CVE-2002-0200 preview

CVE-2002-0200

GitHubalt3kx/cve-2002-0200

Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name.

exploitationpenetration-testingvulnerability-analysis+1
8 years ago
CVE-2021-3130 preview

CVE-2021-3130

GitHubjet-pentest/cve-2021-3130

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

authenticationmisconfigurationpenetration-testing+2
5 years ago
CVE-2021-31166 preview

CVE-2021-31166

GitHubcorelight/cve-2021-31166

Detection rules (Suricata + Zeek) for CVE-2021-31166 HTTP Protocol Stack vulnerability, providing network-level alerts on exploit attempts against…

exploitationintrusion-detectionnetwork-security+3
121 year ago
restler-fuzzer preview

restler-fuzzer

GitHubmicrosoft/restler-fuzzer

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

api-security-testingcloud-securityfuzzing+2
3.0k7 months ago
PenCrawLer preview

PenCrawLer

GitHubthem4hd1/pencrawler

An Advanced Web Crawler and DirBuster

crawlerinformation-gatheringpenetration-testing+2
1144 years ago
thief_raccoon preview

thief_raccoon

GitHubdavenisc/thief_raccoon

Educational phishing simulation tool that mimics OS login screens to capture credentials for cybersecurity awareness training. Supports Windows,…

educationphishingphishing-tools+2
1832 years ago
Previous12…21Next