Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
CVE-2024-10958-WPPA-Exploit preview

CVE-2024-10958-WPPA-Exploit

GitHubreinh3rz/cve-2024-10958-wppa-exploit

Proof-of-concept exploit for CVE-2024-10958, an unauthenticated arbitrary shortcode execution vulnerability in WordPress WP Photo Album Plus plugin.

educationexploitationpenetration-testing+2
1
1 year ago
cve-2023-1874 preview

cve-2023-1874

GitHubthomas-osgood/cve-2023-1874

Python exploit script for CVE-2023-1874, a privilege escalation vulnerability in the WP Data Access WordPress plugin. Enables authenticated…

educationexploitationpenetration-testing+3
21 year ago
CVE-2026-2942 preview

CVE-2026-2942

GitHubxxconi/cve-2026-2942

Automated scanner for unauthenticated arbitrary file upload and remote code execution in ProSolution WP Client (CVE-2026-2942). Supports…

educationexploitationpayload-development+3
3 months ago
CVE-2024-54363-Exploit preview

CVE-2024-54363-Exploit

GitHubnxploited/cve-2024-54363-exploit

Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from…

educationexploitationpenetration-testing+3
11 year ago
CVE-2024-27956 preview

CVE-2024-27956

GitHubdevsec23/cve-2024-27956

CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool

educationexploitationpenetration-testing+2
11 year ago
CVE-2025-5947_Exploit preview

CVE-2025-5947_Exploit

GitHubm4rgs/cve-2025-5947_exploit

An mini exploit for the Service Finder -Bookings plugin WP

educationexploitationpenetration-testing+3
111 months ago
CVE-2025-68055-poc preview

CVE-2025-68055-poc

GitHubnosiume/cve-2025-68055-poc

Exploit POC for CVE-2025-68055 SQL injection in WP Hydra Booking Plugin <= 1.1.32

educationexploitationpenetration-testing+2
18 months ago
Job-Manager-Disclosure preview

Job-Manager-Disclosure

GitHubnotrustedx/job-manager-disclosure

CVE-2015-6668, relacionada con el plugin WP Job Manager para WordPress (versiones ≤ 0.7.25).

crawlereducationexploitation+3
1 year ago
wp-ulike-cve-2025-32259-poc preview

wp-ulike-cve-2025-32259-poc

GitHubhossameahmed/wp-ulike-cve-2025-32259-poc

In affected versions of the WP ULike plugin, there is no proper authorization check before allowing certain AJAX actions or vote manipulations. This…

educationexploitationpenetration-testing+2
1 year ago
CVE-2025-32140 preview

CVE-2025-32140

GitHubnxploited/cve-2025-32140

WordPress WP Remote Thumbnail Plugin <= 1.3.2 is vulnerable to Arbitrary File Upload

educationexploitationpayload-generation+3
1 year ago
cve-2017-5487 preview

cve-2017-5487

GitHubtpdlshdmlrkfmcla/cve-2017-5487

cve-2017-5487 wp rest api 취약점

educationexploitationinformation-gathering+3
1 year ago
POC-AIOWPM-CVE-2026-19949 preview

POC-AIOWPM-CVE-2026-19949

GitHub686f6c61/poc-aiowpm-cve-2026-19949

Reproducible Docker-based proof-of-concept for CVE-2026-19949, a second-order SQL injection in All-in-One WP Migration <= 7.109 that leaks the…

educationexploitationlabs-practice+4
15 days ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubjenderal92/cve-2026-8206

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

educationexploitationinformation-gathering+5
33 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubjenderal92/cve-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

authenticationeducationexploitation+3
3 months ago
wp2shell preview

wp2shell

GitHub0xsha/wp2shell

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

command-and-controleducationexploitation+7
1061 month ago
wp_CVE-2020-35489_checker preview

wp_CVE-2020-35489_checker

GitHubreneoliveirajr/wp_cve-2020-35489_checker

WordPress Sites Vulnerability Checker for CVE-2020-35489 - "Educational Use Only"

educationexploitationinformation-gathering+3
132 years ago
CVE-2026-63030-Wp2Shell preview

CVE-2026-63030-Wp2Shell

GitHubghostinexile/cve-2026-63030-wp2shell

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

code-analysiseducationexploitation+3
41 month ago
CVE-2021-29447 preview

CVE-2021-29447

GitHubdnr6419/cve-2021-29447

Automated PoC for CVE-2021-29447, a WordPress XXE injection vulnerability in the media library. Includes Docker-based environment setup and…

educationexploitationpenetration-testing+3
34 years ago
Previous123Next