Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
376 results
commix preview

commix

GitHubcommixproject/commix

Automated All-in-One OS Command Injection Exploitation Tool

exploitationpenetration-testingvulnerability-scanners+2
5.8k
12h 48m ago
CVE-2026-61241 preview

CVE-2026-61241

GitHubgodliveanton/cve-2026-61241

Oracle OID LDAP Server Privileges Management Exploit

exploitationidentity-access-managementnetwork-security+3
1 day ago
POC-CVE-2026-63030-CVE-2026-60137- preview

POC-CVE-2026-63030-CVE-2026-60137-

GitHubtrandonga3/poc-cve-2026-63030-cve-2026-60137-

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

api-securityeducationexploitation+6
1 day ago
sqlmap preview

sqlmap

GitHubsqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

database-securityexploitationpenetration-testing+2
38.2k2 days ago
CVE-2026-41089-Netlogon-RCE preview

CVE-2026-41089-Netlogon-RCE

GitHubopensource-arrozconpollo191/cve-2026-41089-netlogon-rce

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

educationexploitationpenetration-testing+2
12 days ago
s3dns preview

s3dns

GitHubolizimmermann/s3dns

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

cloud-securitydns-analysisinformation-gathering+5
1283 days ago
nuclei preview

nuclei

GitHubprojectdiscovery/nuclei

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

api-security-testingcloud-securityconfiguration-auditing+8
30.6k3 days ago
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k3 days ago
CVE-2026-73847-emlog-PoC preview

CVE-2026-73847-emlog-PoC

GitHubsqueeze440/cve-2026-73847-emlog-poc

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

exploitationpenetration-testingvulnerability-analysis+2
4 days ago
cve-2026-71362-magento-lab preview

cve-2026-71362-magento-lab

GitHubdinosn/cve-2026-71362-magento-lab

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

authentication-authorizationeducationexploitation+4
15 days ago
CVE-2026-72898 preview

CVE-2026-72898

GitHub4minx/cve-2026-72898

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

exploitationpenetration-testingvulnerability-analysis+3
15 days ago
tirreno preview

tirreno

GitHubtirrenotechnologies/tirreno

Open-source security framework for real-time event tracking, threat detection, and risk scoring. Monitors user behavior, detects fraud, bot attacks,…

anomaly-detectionanti-botapi-security+3
1.5k5 days ago
frogy2.0 preview

frogy2.0

GitHubiamthefrogy/frogy2.0

Orbis is an full spectrum automated external attack surface intelligent toolkit.

cloud-securitydns-analysisemail-security+9
4007 days ago
CVE-2026-41452-PoC preview

CVE-2026-41452-PoC

GitHubboreas37/cve-2026-41452-poc

CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

authentication-authorizationexploitationpenetration-testing+3
37 days ago
SubDomainizer preview

SubDomainizer

GitHubnsonaniya2010/subdomainizer

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

cloud-securityinformation-gatheringosint+2
1.9k9 days ago
CVE-2026-19264 preview

CVE-2026-19264

GitHubdarklycn1976/cve-2026-19264

CVE-2026-19264 - Critical unauthenticated path traversal to full instance takeover in Postiz (< 2.22.1). Technical writeup: decode-order bypass,…

code-analysiseducationexploitation+3
10 days ago
By-Poloss..-..CVE-2026-15038-POC preview

By-Poloss..-..CVE-2026-15038-POC

GitHubpolosss/by-poloss..-..cve-2026-15038-poc

PoC exploit for CVE-2026-15038 in InfiniteWP Client WordPress plugin: bypasses authentication on Multisite, binds attacker RSA key, escalates to…

authenticationexploitationpenetration-testing+3
111 days ago
vibe-coding-security preview

vibe-coding-security

GitHubboxed-dev/vibe-coding-security

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

ai-securityapi-securityauthentication+9
1411 days ago
Previous12…21Next