Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
111 results
jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1 preview

jenkinsci__workflow-cps-plugin_CVE-2022-25173_2646-v6ed3b5b01ff1

GitHubshoucheng3/jenkinsci__workflow-cps-plugin_cve-2022-25173_2646-v6ed3b5b01ff1

Exploit for CVE-2022-25173 targeting Jenkins Pipeline Groovy Plugin's CPS interpreter sandbox bypass, enabling arbitrary code execution within…

code-analysisdevsecopsdynamic-analysis-sandboxing+3
10 months ago
mole preview

mole

GitHubcyber-defence-campus/mole

A Binary Ninja plugin using backward slicing of variables as a driver for static taint analysis

ai-assisted-reversingbinary-analysiscode-analysis+4
841 month ago
EXPLOIT-CVE-2026-8832- preview

EXPLOIT-CVE-2026-8832-

GitHubfunixone/exploit-cve-2026-8832-

Automated RCE exploit for WordPress WPCode Lite v2.3.5. Executes 6-step exploitation chain via XML-RPC bypass with 8 built-in PHP payloads, including…

code-analysisexploitationpayload-development+5
3 months ago
EXPLOIT-CVE-2026-8832 preview

EXPLOIT-CVE-2026-8832

GitHubfunixone/exploit-cve-2026-8832

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

code-analysisexploitationpayload-development+5
13 months ago
CVE-2019-9978-Social-Warfare-WordPress-RCE preview

CVE-2019-9978-Social-Warfare-WordPress-RCE

GitHubtokyohunter/cve-2019-9978-social-warfare-wordpress-rce

A complete walkthrough and exploit for CVE-2019-9978 - Unauthenticated Remote Code Execution in Social Warfare WordPress plugin ≤ 3.5.2. Includes…

code-analysiseducationexploitation+3
11 month ago
comission preview

comission

GitHubintrinsec/comission

White-box CMS security scanner that audits core, plugin, and theme versions, detects unauthorized modifications, and cross-references known…

code-analysisconfiguration-auditingvulnerability-scanners+1
686 years ago
halo-2.25.4-backup-write-CVE-2026-67920 preview

halo-2.25.4-backup-write-CVE-2026-67920

GitHubunpredictable21/halo-2.25.4-backup-write-cve-2026-67920

Proof-of-concept exploit for an arbitrary file write vulnerability in Halo CMS backup restoration, enabling RCE via plugin JAR replacement or…

code-analysisexploitationpenetration-testing+3
1 month ago
CVE-2026-3300 preview

CVE-2026-3300

GitHubadamshaikhma/cve-2026-3300

Exploit for CVE-2026-3300, an unauthenticated stored XSS leading to RCE in Everest Forms Pro WordPress plugin, with a Python script to generate a…

code-analysisexploitationpayload-development+3
3 months ago
CVE-2023-6553-PoC preview

CVE-2023-6553-PoC

GitHubmotikan2010/cve-2023-6553-poc

Python proof-of-concept exploit for CVE-2023-6553, demonstrating unauthenticated remote code execution via PHP filter chain in the Backup Migration…

code-analysisexploitationpayload-development+3
42 years ago
0-click-RCE-Exploit-for-CVE-2024-9932 preview

0-click-RCE-Exploit-for-CVE-2024-9932

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-9932

Unauthenticated 0-click RCE exploit for CVE-2024-9932. Exploits an arbitrary file upload vulnerability in the Wux Blog Editor WordPress plugin to…

code-analysisexploitationpayload-development+5
27 months ago
sudowp-clickfunnels-zurich preview

sudowp-clickfunnels-zurich

GitHubsudo-wp/sudowp-clickfunnels-zurich

A security-patched fork of the legacy ClickFunnels Classic WordPress plugin. Fixes critical Stored XSS vulnerabilities (CVE-2022-4782) while…

api-securityauthentication-authorizationcode-analysis+3
15 months ago
-CVE-2015-10137-WordPress-N-Media-Website-Contact-Form-with-File-Upload-1.3.4 preview

-CVE-2015-10137-WordPress-N-Media-Website-Contact-Form-with-File-Upload-1.3.4

GitHubkai-one001/-cve-2015-10137-wordpress-n-media-website-contact-form-with-file-upload-1.3.4

Python exploit for CVE-2015-10137 targeting an arbitrary file upload vulnerability in the WordPress N-Media Website Contact Form plugin, enabling…

code-analysisexploitationpayload-generation+3
11 year ago
CVE-2023-4634-PoC preview

CVE-2023-4634-PoC

GitHubevillm/cve-2023-4634-poc

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

code-analysisexploitationpenetration-testing+3
7 months ago
apache-struts-cve-2017-9805 preview

apache-struts-cve-2017-9805

GitHubrvermeulen/apache-struts-cve-2017-9805

Exploit for Apache Struts CVE-2017-9805, a remote code execution vulnerability in the REST plugin. Enables penetration testing and security…

code-analysisexploitationpenetration-testing+3
5 years ago
CVE-2023-6553 preview

CVE-2023-6553

GitHubdungsocool/cve-2023-6553

Proof-of-concept exploit and technical write-up for CVE-2023-6553, an unauthenticated PHP file inclusion vulnerability enabling remote code execution…

code-analysiseducationexploitation+3
1 month ago
CVE-2024-5932 preview

CVE-2024-5932

GitHubnishant-kumar-5173/cve-2024-5932

Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code…

code-analysiseducationexploitation+5
3 months ago
checkmk-log4j-scanner preview

checkmk-log4j-scanner

GitHubinettgmbh/checkmk-log4j-scanner

Checkmk extension that scans JAR, WAR, EAR, and AAR files for Log4j versions vulnerable to CVE-2021-44228 by inspecting META-INF pom.properties…

code-analysislog-analysisstatic-analysis+2
42 years ago
CVE-2026-13157 preview

CVE-2026-13157

GitHubminhhk68/cve-2026-13157

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

code-analysisexploitationpayload-development+4
1 month ago
Previous1234567Next