Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
2485 results
CVE-2019-11043 preview

CVE-2019-11043

GitHubfairyming/cve-2019-11043

Proof-of-concept exploit for CVE-2019-11043, a PHP-FPM underflow vulnerability, built on the pocsuite framework for automated web application…

exploitationpayload-developmentpenetration-testing+2
1
6 years ago
INT14107_CVE-2021-35042 preview

INT14107_CVE-2021-35042

GitHubvutiendat323/int14107_cve-2021-35042

Django-based CTF blog platform with integrated CVE-2021-35042 exploit tool for learning web application security and vulnerability exploitation.

ctfeducationexploitation+3
4 months ago
mimosa preview

mimosa

GitHubowasp/mimosa

Open-source web application security challenge platform with auto-approved registration, SQL dump generation, and Docker deployment for hands-on…

ctfeducationlabs-practice+3
3 years ago
vert-x3__vertx-web_CVE-2019-17640_3-9-3 preview

vert-x3__vertx-web_CVE-2019-17640_3-9-3

GitHubshoucheng3/vert-x3__vertx-web_cve-2019-17640_3-9-3

Analysis and exploitation code for CVE-2019-17640, a vulnerability in Vert.x-Web. Provides a targeted test case for security researchers validating…

general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
1 year ago
CVE-2025-44603-CSRF-Leads_to_Create_FakeUsers preview

CVE-2025-44603-CSRF-Leads_to_Create_FakeUsers

GitHubmoulish2004/cve-2025-44603-csrf-leads_to_create_fakeusers

Proof-of-concept demonstrating a CSRF vulnerability in a PHP-based Client Management System, with HTML exploit code and mitigation strategies for web…

educationexploitationpenetration-testing+3
1 year ago
CVE-2012-4431 preview

CVE-2012-4431

GitHubimjdl/cve-2012-4431

Apache Tomcat source code repository for CVE-2012-4431, a Java servlet container vulnerability. Provides the vulnerable codebase for analysis and…

general-purpose-utilitiesvulnerability-analysisweb-application-exploitation+1
7 years ago
Adiscon preview

Adiscon

GitHubcostacoco/adiscon

SQL injection exploit for Adiscon LogAnalyzer v4.1.13 and earlier (CVE-2023-34600). Provides proof-of-concept code for testing web application…

exploitationpenetration-testingvulnerability-analysis+1
3 years ago
apache__jspwiki_CVE-2022-46907_2-11-3 preview

apache__jspwiki_CVE-2022-46907_2-11-3

GitHubshoucheng3/apache__jspwiki_cve-2022-46907_2-11-3

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

authentication-authorizationconfiguration-auditingeducation+3
10 months ago
CVE-2525-25748-Cross-Site-Request-Forgery-CSRF-Vulnerability-in-HotelDruid-3.0.7 preview

CVE-2525-25748-Cross-Site-Request-Forgery-CSRF-Vulnerability-in-HotelDruid-3.0.7

GitHubhuyvo2910/cve-2525-25748-cross-site-request-forgery-csrf-vulnerability-in-hoteldruid-3.0.7

Detailed CVE-2025-25748 proof-of-concept and analysis of a CSRF vulnerability in HotelDruid 3.0.7, including exploitation flow, impact assessment,…

educationpapers-researchpenetration-testing+3
1 year ago
xss-payload-list preview

xss-payload-list

GitHubh3x0v3rl0rd/xss-payload-list

Curated collection of XSS payload vectors for web application security testing, covering various contexts and bypass techniques.

curated-resourceseducationvulnerability-analysis+2
5 years ago
arachni preview
Archived

arachni

GitHubarachni/arachni

Web Application Security Scanner Framework

crawlerdynamic-analysis-sandboxingpenetration-testing+3
4.0k4 months ago
vulpy preview

vulpy

GitHubfportantier/vulpy

Vulnerable Python Application To Learn Secure Development

educationlabs-practicepenetration-testing+2
1286 years ago
NucleiFuzzer preview

NucleiFuzzer

GitHub0xkayala/nucleifuzzer

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

fuzzinginformation-gatheringpenetration-testing+3
1.9k4 months ago
training-application-security preview

training-application-security

GitHubransomleak/training-application-security

Interactive secure coding training with hands-on SCORM exercises covering OWASP Top 10 web and API vulnerabilities, Git/secrets exposure, and…

api-securitydevsecopseducation+7
184 days ago
tbhm preview

tbhm

GitHubjhaddix/tbhm

The Bug Hunters Methodology

curated-resourceseducationlearning-paths-courses+4
4.4k3 years ago
tachyon preview

tachyon

GitHubdelvelabs/tachyon

Fast http dead file finder.

information-gatheringreconnaissancevulnerability-scanners+1
2211 month ago
wvctf preview

wvctf

GitHubsyn-4ck/wvctf

WVCTF or WebVulnCTF is a gamified web platform which promotes training in pentesting and web application development security in an entertaining way.…

ctfeducationlabs-practice+3
12 years ago
Juiceshopgl preview

Juiceshopgl

GitLabmbrandner-group/juiceshopgl

Intentionally vulnerable web application for security training, CTF competitions, and testing security tools. Covers OWASP Top Ten vulnerabilities…

ctfeducationlabs-practice+5
1 year ago
Previous1234…100Next