Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
CVE-2026-34835-Black-box-Analysis preview

CVE-2026-34835-Black-box-Analysis

GitHubcyber-note/cve-2026-34835-black-box-analysis

A black-box (DAST) security analysis of CVE-2026-34835 focusing on external validation methodology, observable behavior, security impact, and…

dns-analysiseducationpenetration-testing+3
6
2 months ago
BWASP preview

BWASP

GitHubbwasp/bwasp

BoB Web Application Security Project

educationpenetration-testingvulnerability-analysis+3
2248 months ago
WAES preview

WAES

GitHubshiva108/waes

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

ctfeducationinformation-gathering+7
707 months ago
ronin preview

ronin

GitHubronin-rb/ronin

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

cryptographyctfdns-analysis+9
7567 months ago
sqlmc preview

sqlmc

GitHubmalvads/sqlmc

Official Kali Linux tool to check all urls of a domain for SQL injections :)

educationinformation-gatheringpenetration-testing+3
3804 months ago
ASST preview

ASST

GitHubowasp/asst

OWASP ASST (Automated Software Security Toolkit) | A Novel Open Source Web Security Scanner.

code-analysiseducationstatic-code-analysis+2
1881 year ago
CVE-2025-55182 preview

CVE-2025-55182

GitHubl4rm4nd/cve-2025-55182

Docker-based lab for detecting and exploiting CVE-2025-55182 (React2Shell RCE) in Next.js/React Server Components, with pre-configured vulnerable…

educationlabs-practicepenetration-testing+4
868 months ago
react2shell-scanner-rce-react-next-CVE-2025-55182-CVE-2025-66478 preview

react2shell-scanner-rce-react-next-CVE-2025-55182-CVE-2025-66478

GitHubsecurity-phoenix-demo/react2shell-scanner-rce-react-next-cve-2025-55182-cve-2025-66478

Scanner for CVE-2025-55182 (React) and CVE-2025-66478 (Next.js) - Track and remediate a critical React Server Components (RSC) / Flight protocol…

code-analysiseducationexploitation+6
66 months ago
Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954- preview

Exploitation-of-a-Remote-Code-Execution-vulnerability--CVE-2024-7954-

GitHubshivanshkuntal/exploitation-of-a-remote-code-execution-vulnerability--cve-2024-7954-

Exploitation of a Remote Code Execution vulnerability- (CVE-2024-7954)

educationexploitationinformation-gathering+8
18 months ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubiteride/cve-2025-2294

Proof-of-concept exploit for CVE-2025-2294, a critical LFI vulnerability in Kubio AI Page Builder for WordPress. Includes a Python scanner, nuclei…

educationexploitationpenetration-testing+3
11 months ago
Open-Worldwide-Application-Security-Project-OWASP- preview

Open-Worldwide-Application-Security-Project-OWASP-

GitHubwaburig/open-worldwide-application-security-project-owasp-

Automated Web Vulnerability Assessment of DVWA using OWASP ZAP to identify and analyze critical security flaws like Remote Code Execution…

educationpenetration-testingvulnerability-analysis+2
8 months ago
react2shell-checker preview

react2shell-checker

GitHubmuthaiyanmani/react2shell-checker

A security vulnerability scanner for detecting the React2Shell vulnerability (CVE-2025-55182) in Next.js and React applications.

educationinformation-gatheringreconnaissance+3
8 months ago
Vehicle-Service-Management-System-User-List-Stored-Cross-Site-Scripting-XSS preview

Vehicle-Service-Management-System-User-List-Stored-Cross-Site-Scripting-XSS

GitHubsanupl/vehicle-service-management-system-user-list-stored-cross-site-scripting-xss

CVE-2021-46073 - A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the User List…

educationexploitationpenetration-testing+3
3 months ago
CVE-2025-0054 preview

CVE-2025-0054

GitHubz3usx01/cve-2025-0054

Lightweight Python scanner for detecting stored XSS (CVE-2025-0054) in SAP NetWeaver Java. Submits customizable payloads and checks for script…

educationpenetration-testingvulnerability-analysis+2
1 year ago
Sn1per preview

Sn1per

GitHub1n3/sn1per

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

devsecopsexploit-frameworksinformation-gathering+7
11.2k2 months ago
OpenDoor preview

OpenDoor

GitHubstanislav-web/opendoor

OWASP Web Recon & Directory Discovery Platform

information-gatheringpenetration-testingreconnaissance+4
1k1 month ago
SecurityManageFramwork preview

SecurityManageFramwork

GitHubwe1h0/securitymanageframwork

Security Manage Framwork is a security management platform for enterprise intranet, which includes asset management, vulnerability management,…

configuration-auditingnetwork-mappingpassword-cracking+4
4316 years ago
AttackSurfaceManagement preview

AttackSurfaceManagement

GitHub1n3/attacksurfacemanagement

Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam…

exploit-frameworksinformation-gatheringosint+6
1064 years ago
Previous12Next