Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
16 results
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k
3 days ago
awesome-web-security preview

awesome-web-security

GitHubqazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

ctfcurated-resourceseducation+7
13.7k16 days ago
CVE-2026-54415-PoC preview

CVE-2026-54415-PoC

GitHubabdugafforov-bobur/cve-2026-54415-poc

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

authenticationctfeducation+4
21 month ago
ash-authentication-oauth2-oidc-account-takeover-cve-2026-49757-email-based-user-matching preview

ash-authentication-oauth2-oidc-account-takeover-cve-2026-49757-email-based-user-matching

GitHubhunt-benito/ash-authentication-oauth2-oidc-account-takeover-cve-2026-49757-email-based-user-matching
authenticationauthentication-authorizationctf+5
2 months ago
CVE-2025-6254 preview

CVE-2025-6254

GitHubyucaerin/cve-2025-6254

CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation

ctfeducationexploitation+8
2 months ago
pocketbase-CVE-2026-44166 preview

pocketbase-CVE-2026-44166

GitHubalardiians/pocketbase-cve-2026-44166

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

authenticationctfeducation+5
2 months ago
CVE-2026-8206-Lab preview

CVE-2026-8206-Lab

GitHubrootdirective-sec/cve-2026-8206-lab
ctfeducationexploitation+3
2 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubez4rd1x1/cve-2026-8181

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

authentication-authorizationctfeducation+5
2 months ago
CVE-2026-6741 preview

CVE-2026-6741

GitHubxxconi/cve-2026-6741

CVE-2026-6741 is a CVSS 8.8 (High) Authenticated (Agent+) Privilege Escalation vulnerability in the LatePoint – Calendar Booking Plugin

ctfeducationexploitation+4
2 months ago
CVE-2026-11518-XSS preview

CVE-2026-11518-XSS

GitHubxmyronn/cve-2026-11518-xss
ctfeducationpenetration-testing+3
2 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubyucaerin/cve-2026-8181

The Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative) plugin for WordPress is vulnerable to Authentication Bypass

authenticationctfeducation+4
3 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubzycoder0day/cve-2026-8181

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

authenticationctfeducation+4
53 months ago
bug-reaper preview

bug-reaper

GitHubshaniidev/bug-reaper

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.

api-security-testingctfeducation+8
676 months ago
CVE-2025-34157 preview

CVE-2025-34157

GitHubeyodav/cve-2025-34157

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

ctfeducationexploitation+3
11 months ago
moodle-cve preview

moodle-cve

GitHubhxuu/moodle-cve

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

ctfeducationexploitation+3
311 months ago
Blackash-CVE-2025-4322 preview

Blackash-CVE-2025-4322

GitHubgmh5225/blackash-cve-2025-4322

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

ctfeducationexploitation+5
1 year ago