Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
618 results
woo preview

woo

GitHubrandomrobbiebf/woo

Exploit woocommerce SQLI and grab user and password hash

data-exfiltrationexploitationinformation-gathering+3
2
5 years ago
CVE-2025-7401 preview

CVE-2025-7401

GitHubnxploited/cve-2025-7401

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

data-exfiltrationexploitationinformation-gathering+5
211 months ago
CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit preview

CVE-2025-55182-Advanced-React-Server-Components-RCE-Exploit

GitHubcerberusmrxi/cve-2025-55182-advanced-react-server-components-rce-exploit

Advanced React Server Components RCE scanner for CVE-2025-55182. Features: multi-stage fingerprinting, vulnerability verification, DNS exfiltration,…

data-exfiltrationexploitationpayload-development+6
11 month ago
CVE-2024-28987 preview

CVE-2024-28987

GitHubdarabium/cve-2024-28987

**CVE-2024-28987** is a critical vulnerability in SolarWinds Web Help Desk (WHD) that allows remote attackers to access sensitive ticket information…

data-exfiltrationexploitationpenetration-testing+2
11 month ago
CVE-2026-16540-SimplyScheduleAppointments preview

CVE-2026-16540-SimplyScheduleAppointments

GitHubhuseyn0vs/cve-2026-16540-simplyscheduleappointments

CVE-2026-16540 — Simply Schedule Appointments < 1.6.12.6 Unauthenticated Appointment Data Disclosure and Mass Deletion

data-exfiltrationinformation-gatheringmisconfiguration+3
11 month ago
CVE-2026-22804 preview

CVE-2026-22804

GitHubthemehackers/cve-2026-22804

This repository contains a Proof of Concept (PoC) exploit for the Stored Cross-Site Scripting (XSS) vulnerability in Termix, which can lead to Local…

data-exfiltrationexploitationpayload-development+2
28 months ago
CVE-2025-65321 preview

CVE-2025-65321

GitHubsmarttfoxx/cve-2025-65321

Language Sloth Sloth Bot 1.0 is vulnerable to Directory Traversal in the gif() and png() functions. The functions build file paths using unsanitized…

data-exfiltrationexploitationinformation-gathering+2
29 months ago
CVE-2026-41653 preview

CVE-2026-41653

GitHubastaruf/cve-2026-41653

Proof-of-concept exploit for CVE-2026-41653, a stored XSS in BentoPDF that enables silent file exfiltration and WASM supply-chain hijacking.

data-exfiltrationexploitationpayload-development+2
4 months ago
CVE-2026-42167-Exploit preview

CVE-2026-42167-Exploit

GitHubefeanilarslan/cve-2026-42167-exploit

Python exploit for CVE-2026-42167 (ProFTPD mod_sql). Features automated file scanning and timing-based blind data exfiltration.

data-exfiltrationexploitationpenetration-testing+2
4 months ago
CVE-2026-5530 preview

CVE-2026-5530

GitHubdavidrxchester/cve-2026-5530

Proof-of-concept exploit for CVE-2026-5530, an SSRF in Ollama's Pull/Push API, enabling internal endpoint enumeration and full response exfiltration…

data-exfiltrationexploitationinformation-gathering+2
5 months ago
CVE-2025-12137 preview

CVE-2025-12137

GitHubjfriedli/cve-2025-12137

Proof-of-concept exploit for CVE-2025-12137 demonstrating local file disclosure via a WordPress plugin's REST API importer endpoint. Includes…

data-exfiltrationexploitationinformation-gathering+3
5 months ago
TFTPlunder preview

TFTPlunder

GitHubysaxon/tftplunder

Info and exploit for CVE-2023-29930: blind file read/write in Genesys TFTP provisioning server configuration

data-exfiltrationexploitationinformation-gathering+3
13 years ago
Fortigate-Belsen-Leak-Dump-CVE-2022-40684- preview

Fortigate-Belsen-Leak-Dump-CVE-2022-40684-

GitHubxalfie/fortigate-belsen-leak-dump-cve-2022-40684-

Extracts passwords from Fortinet VPN leak dumps associated with CVE-2022-40684, processing subfolders for vpn-passwords.txt and outputting cleaned…

data-exfiltrationexploitationinformation-gathering+3
11 year ago
CVE-2026-Discord preview

CVE-2026-Discord

GitHubnicetop1027/cve-2026-discord

Critical vulnerability report detailing zero-day Remote Debugging Port exposure in Discord macOS client leading to account takeover, spyware, worm…

data-exfiltrationexploitationpenetration-testing+3
7 months ago
cve-2025-66723 preview

cve-2025-66723

GitHubaudiopump/cve-2025-66723

CVE-2025-66723: inMusic Brands Engine DJ >=3.0.0 through <4.3.4 exposes local and network files to external parties

data-exfiltrationexploitationinformation-gathering+3
7 months ago
CVE-2026-39047 preview

CVE-2026-39047

GitHubazhariramadhan/cve-2026-39047

Printer exploitation framework for security testing via raw port 9100, featuring PCL payload delivery, DoS bombing, C2 QR codes, phishing QR codes,…

data-exfiltrationexploitationnetwork-security+4
5 months ago
CVE-2025-30208 preview

CVE-2025-30208

GitHubhazavvip/cve-2025-30208

Exploit scanner for CVE-2025-30208 (Vite arbitrary file read) with multi-variant bypass detection, credential harvesting, SSH key extraction, and…

data-exfiltrationexploitationinformation-gathering+3
4 months ago
CVE-2021-27187 preview

CVE-2021-27187

GitHubjet-pentest/cve-2021-27187

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

data-exfiltrationexploitationinformation-gathering+3
5 years ago
Previous1…161718…35Next