Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
481 results
cve-2025-23266-migration-bypass preview

cve-2025-23266-migration-bypass

GitHubmindasy/cve-2025-23266-migration-bypass

cve-2025-23266-migration-bypass

container-escapeexploitationpost-exploitation+2
1
1 year ago
looneyCVE preview

looneyCVE

GitHubteragl/looneycve

Looney Tunables CVE-2023-4911

binary-exploitationexploitationpenetration-testing+2
12 years ago
CVE-2026-31431-Copy-Fail-Container-Escape preview

CVE-2026-31431-Copy-Fail-Container-Escape

GitHubhans362/cve-2026-31431-copy-fail-container-escape

Container escape on any docker container with healthcheck enabled via CVE-2026-31431

cloud-securitycontainer-escapecontainer-security+3
4 months ago
pysho preview

pysho

GitHubkr0ff/pysho

A python tool to search Shodan using the Shodan API

information-gatheringnetwork-securityosint+1
14 years ago
CVE-2004-2271-MiniShare-1.4.1-BOF preview

CVE-2004-2271-MiniShare-1.4.1-BOF

GitHubpwncone/cve-2004-2271-minishare-1.4.1-bof

A python implementation of CVE-2004-2271 targeting MiniShare 1.4.1.

binary-exploitationexploitationpayload-development+3
6 years ago
CVE-2023-4220 preview

CVE-2023-4220

GitHubnr4x4/cve-2023-4220

CVE-2023–4220 Exploit

exploitationpayload-developmentpenetration-testing+3
2 years ago
CVE-2022-0739 preview

CVE-2022-0739

GitHubelganz0/cve-2022-0739

BookingPress < 1.0.11 - Unauthenticated SQL Injection

exploitationinformation-gatheringpenetration-testing+2
3 years ago
Wordpress-ebook-CVE-2016-10924 preview

Wordpress-ebook-CVE-2016-10924

GitHublgenagul/wordpress-ebook-cve-2016-10924

Exploits CVE-2016-10924 file disclosure in WordPress eBook Download plugin to brute-force server processes and retrieve sensitive files.

exploitationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2002-0082 preview

CVE-2002-0082

GitHubratiros01/cve-2002-0082

CVE-2002-0082

binary-exploitationexploitationvulnerability-analysis+2
1 year ago
CVE_Project preview

CVE_Project

GitHubmhe18/cve_project

CVE-2016-1240 exploit and patch

binary-exploitationexploitationprivilege-escalation+2
7 years ago
InstagramOSINT preview
Archived

InstagramOSINT

GitHubsc1341/instagramosint

An Instagram Open Source Intelligence Tool - Archive

information-gatheringmobile-securityosint+3
1.7k2 years ago
CVE-2020-27368 preview
Archived

CVE-2020-27368

GitHubswzhouu/cve-2020-27368

TOTOLINK-A702R-V1.0.0-B20161227.1023 Directory Indexing Vulnerability

embedded-systems-securityinformation-gatheringiot-security+3
13 years ago
dns-honeypot preview
Archived

dns-honeypot

GitHubtg12/dns-honeypot

dns-honeypot

dns-analysisincident-responseinformation-gathering+4
994 months ago
WPSniper preview

WPSniper

GitHubynsmroztas/wpsniper

CVE-2026-87902 detector. WordPress get_page_template LFI class. Detect-only. Authorized lab.

information-gatheringpenetration-testingreconnaissance+4
1 day ago
sterraxcyl preview
Archived

sterraxcyl

GitHubnovitae/sterraxcyl

Instagram OSINT tool to export and analyse followers | following with their details

crawlerinformation-gatheringosint+2
6802 years ago
instantbox preview

instantbox

GitHubinstantbox/instantbox

📦 Get a clean, ready-to-go Linux box in seconds.

educationgeneral-purpose-utilitieslabs-practice
4.2k7 years ago
HTB-Reactor-Linux-Machine-Walkthrough preview

HTB-Reactor-Linux-Machine-Walkthrough

GitHubsonnycroco/htb-reactor-linux-machine-walkthrough

Full walkthrough of HTB's Reactor machine — exploit CVE-2025-55182 to gain a shell, then get root via an exposed Node.js debugger. Step-by-step with…

ctfeducationexploitation+8
13 months ago
mvn_pwn preview

mvn_pwn

GitHubmbadanoiu/mvn_pwn

Malicious Maven pom.xml that uses "groovy-maven-plugin" to get RCE

educationexploitationpayload-development+3
3 months ago
Previous1…24252627Next