Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
171 results
CVE-2025-14598 preview

CVE-2025-14598

GitHubafnaan-ahmed/cve-2025-14598

CVE-2025-14598 Remote Unauthenticated SQL Injection leading to Remote Code Execution.

database-securityeducationexploitation+3
1
7 months ago
Prineo_RE preview

Prineo_RE

GitHubexifdev/prineo_re

Reverse engineering of the engine powering the PriPara games on arcade.

binary-analysiscryptographyeducation+3
54 months ago
CVE-2022-23779 preview

CVE-2022-23779

GitHubrishi-kaul/cve-2022-23779

CVE-2022-23779 is a security vulnerability in Zoho ManageEngine Desktop Central ,Testing for CVE-2022-23779 using curl

exploitationinformation-gatheringpenetration-testing+3
7 months ago
CVE-2023-7231 preview

CVE-2023-7231

GitHubbbo513/cve-2023-7231

PoC and Disclosure for CVE-2023-7231 – Memcached Gopher RCE chain

cloud-securitycontainer-securitydata-exfiltration+6
11 year ago
CVE-2017-5638-Attack-and-Defense preview

CVE-2017-5638-Attack-and-Defense

GitHubacharaf06/cve-2017-5638-attack-and-defense
defensive-toolseducationlabs-practice+4
18 months ago
CVE-2026-999999 preview

CVE-2026-999999

GitHub24520597-blip/cve-2026-999999

A critical Server-Side Template Injection (SSTI) vulnerability exists in the X-Trading Portal v1.4.2 dashboard metadata rendering engine. The flaw…

educationexploitationpenetration-testing+3
2 months ago
log4j-honeypot-flask preview

log4j-honeypot-flask

GitHubbinarydefense/log4j-honeypot-flask

Internal network honeypot for detecting if an attacker or insider threat scans your network for log4j CVE-2021-44228

defensive-toolsintrusion-detectionnetwork-security+2
1494 years ago
CVE-2021-32819 preview

CVE-2021-32819

GitHubabady0x1/cve-2021-32819

SquirrellyJS mixes pure template data with engine configuration options through the Express render API. By overwriting internal configuration…

exploitationpayload-generationremote-access-tool+2
105 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xnxt1me/cve-2025-29927
authentication-authorizationeducationlabs-practice+3
11 year ago
cve-2025-29927 preview

cve-2025-29927

GitHubbalajih4kr/cve-2025-29927

CVE-2025-29927 is a critical vulnerability in Next.js, a popular React-based web framework. The flaw exists in how the middleware feature handles…

exploitationmisconfigurationvulnerability-analysis+2
1 year ago
tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE preview

tugtainer-1.30.2-CVE-2026-55494-and-CVE-2026-62308-to-RCE

GitHub4qu4r1um/tugtainer-1.30.2-cve-2026-55494-and-cve-2026-62308-to-rce

A combination of CVE-2026-55494 and CVE-2026-62308 to get root privilege RCE in tugtainer

container-escapecontainer-securityeducation+5
1 month ago
js2py-Sandbox-Escape-CVE-2024-28397-RCE preview

js2py-Sandbox-Escape-CVE-2024-28397-RCE

GitHub0xdtc/js2py-sandbox-escape-cve-2024-28397-rce
educationexploitationpayload-generation+3
11 months ago
CVE-2023-27163-ssrf-to-port-scanning preview

CVE-2023-27163-ssrf-to-port-scanning

GitHubrishabh-kumar-cyber-sec/cve-2023-27163-ssrf-to-port-scanning

It is a simple script to automate internal port scanning dueto SSRF in requests-baskets v 1.2.1. this script can also assisst in solving 'SAU'…

ctfpenetration-testingport-scanning+2
2 years ago
CVE-2025-6554 preview

CVE-2025-6554

GitHubpwntoday/cve-2025-6554
binary-exploitationeducationexploitation+2
211 months ago
token-proxy preview

token-proxy

GitHubzolderio/token-proxy

A transparent PII redaction proxy for LLM API traffic. Sits between an application and an LLM provider (currently Anthropic), pseudonymizing…

ai-securityapi-securitycloud-security+6
284 months ago
vercel-april2026-incident-response preview

vercel-april2026-incident-response

GitHubopensourcemalware/vercel-april2026-incident-response

This is an incident response playbook we created for the Vercel April 2026 compromise

cloud-securitydigital-forensicsincident-response+3
324 months ago
duckLogger preview

duckLogger

GitHubitsmmdoha/ducklogger

A ESP32-S3–based usb keylogger with wifi, easy DIY-able with widely available hardware.

command-and-controldata-exfiltrationembedded-systems-security+8
864 months ago
mcp-security-checklist preview

mcp-security-checklist

GitHubhelixar-ai/mcp-security-checklist

MCP is being adopted rapidly. Security guidance is lagging behind. This checklist gives security engineers, platform teams, and technical leaders a…

ai-securityapi-securityauthentication-authorization+5
225 months ago
Previous1…678…10Next