Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
77 results
Egyscan preview

Egyscan

GitHubdragonked2/egyscan

Automated web vulnerability scanner with multi-threaded crawling and payload injection engine. Detects SQLi, XSS, RCE, LFI, SSRF, XXE, and 30+ other…

crawlerinformation-gatheringpenetration-testing+4
301
6 days ago
creep-web-app-scanner preview

creep-web-app-scanner

GitHubnccgroup/creep-web-app-scanner

Primitive web application scanner that crawls sites, extracts hidden information from comments, errors, and file paths, and performs directory…

crawlerinformation-gatheringpenetration-testing+3
2412 years ago
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
27 days ago
kenzer preview
Archived

kenzer

GitHubarpsyndicate/kenzer

automated web assets enumeration & scanning [DEPRECATED]

crawlerdns-analysisinformation-gathering+8
2883 years ago
sqliv preview
Archived

sqliv

GitHubthe-robot/sqliv

massive SQL injection vulnerability scanner

crawlerinformation-gatheringreconnaissance+2
1.2k8 years ago
bugbounty_tools preview

bugbounty_tools

GitHubdawgyg/bugbounty_tools

Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own personal use, and…

information-gatheringreconnaissancesubdomain-enumeration+3
1528 months ago
fortra-goanywhere-mft-vulnerability-detection preview

fortra-goanywhere-mft-vulnerability-detection

GitHubrxerium/fortra-goanywhere-mft-vulnerability-detection

Nuclei templates for detecting Fortra GoAnywhere MFT vulnerabilities, including CISA KEV exploits and ransomware-associated CVEs, with automatic…

information-gatheringpenetration-testingthreat-intelligence+3
8 months ago
CVE-2026-17543-PHP-Exposure-Validator preview

CVE-2026-17543-PHP-Exposure-Validator

GitHubpratham220/cve-2026-17543-php-exposure-validator

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

defensive-toolsinformation-gatheringpenetration-testing+5
19 days ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsinformation-gatheringpenetration-testing+4
19 days ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubmr-leonardogomes/xss2shell-cve-2026-64638

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

exploitationpenetration-testingreconnaissance+3
116 days ago
CVE-2025-53072-CVE-2025-62481 preview

CVE-2025-53072-CVE-2025-62481

GitHubrxerium/cve-2025-53072-cve-2025-62481

Nuclei template to detect Oracle EBS instances likely vulnerable to CVE-2025-53072 and CVE-2025-62481 via Last-Modified header fingerprinting.

reconnaissancevulnerability-scannersweb-security+1
310 months ago
n8n-vulnerability-detection preview

n8n-vulnerability-detection

GitHubrxerium/n8n-vulnerability-detection

Automated Nuclei templates for scanning n8n Workflow Automation instances, with daily CVE detection, version fingerprinting, and multi-source threat…

penetration-testingreconnaissancethreat-intelligence+3
17 months ago
laravel-ignition-Rxss preview

laravel-ignition-Rxss

GitHubcappricio-securities/laravel-ignition-rxss

Laravel Ignition contains a cross-site scripting vulnerability when debug mode is enabled.

penetration-testingreconnaissancevulnerability-scanners+2
2 years ago
ghe-push-option-rce-scanner preview

ghe-push-option-rce-scanner

GitHubridhinva/ghe-push-option-rce-scanner

Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

penetration-testingreconnaissancered-teaming+4
17 days ago
Sitadel preview

Sitadel

GitHubshenril/sitadel

Modular web application security scanner with fingerprinting (server, CMS, WAF, CDN) and attack modules (SQLi, XSS, RFI, brute-force) for automated…

information-gatheringpenetration-testingvulnerability-scanners+3
6134 days ago
react2shell-scanner preview

react2shell-scanner

GitHubshield-cyber/react2shell-scanner

Scanner to detect the presence of CVE-2025-55182 & CVE-2025-66478 on targeted web services.

exploitationinformation-gatheringpenetration-testing+3
18 months ago
XnlReveal preview

XnlReveal

GitHubxnl-h4ck3r/xnlreveal

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

information-gatheringosintpenetration-testing+3
4524 months ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xwhoknows/cve-2025-29927

Async Python scanner that detects CVE-2025-29927 in Next.js apps by processing URL lists with aiohttp, connection pooling, caching, and chunked…

exploitationinformation-gatheringpenetration-testing+3
31 year ago
Previous12345Next