Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
137 results
CVE-2025-42957-SAP-S-4HANA-Under-Siege preview

CVE-2025-42957-SAP-S-4HANA-Under-Siege

GitHubmrk336/cve-2025-42957-sap-s-4hana-under-siege

CVE‑2025‑42957 exposes an RFC‑enabled SAP S/4HANA module that lets low‑privileged users inject ABAP code to create admin accounts and gain full…

educationexploitationpenetration-testing+4
3
11 months ago
CVE-2025-6254 preview

CVE-2025-6254

GitHubyucaerin/cve-2025-6254

CVE-2025-6254 — Doctreat Core <= 1.6.8 — Unauthenticated Privilege Escalation

ctfeducationexploitation+8
2 months ago
CVE-2026-40791-WP-Time-Slots-Booking-Form-XSS preview

CVE-2026-40791-WP-Time-Slots-Booking-Form-XSS

GitHubrat5ak/cve-2026-40791-wp-time-slots-booking-form-xss

CVE-2026-40791: Unauthenticated stored XSS in WP Time Slots Booking Form <= 1.2.46

educationexploitationpenetration-testing+3
2 months ago
CVE-2026-48908-Joomla-SP-Page-Builder-RCE preview

CVE-2026-48908-Joomla-SP-Page-Builder-RCE

GitHubimxur/cve-2026-48908-joomla-sp-page-builder-rce

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

educationpapers-researchvulnerability-analysis+1
21 month ago
mongobleed-exploit-CVE-2025-14847 preview

mongobleed-exploit-CVE-2025-14847

GitHubfranksec42/mongobleed-exploit-cve-2025-14847

Explot, Lab, Scanner - external and docker container, for SMongobleed-CVE-2025-14847 plus phoenix security uploader

cloud-securitycontainer-securitydatabase-security+6
38 months ago
telegram-phish-simulator preview

telegram-phish-simulator

GitHubmaty156/telegram-phish-simulator

Educational Telegram phishing simulation for cybersecurity training and awareness. Demonstrates credential harvesting via fake login pages in…

educationinformation-gatheringlabs-practice+6
22 months ago
CVE-2026-41089-Netlogon-RCE preview

CVE-2026-41089-Netlogon-RCE

GitHubopensource-arrozconpollo191/cve-2026-41089-netlogon-rce

Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

educationexploitationpenetration-testing+2
16 days ago
CVE-2025-59382-QNAP-Password-Reset-Account-Takeover preview

CVE-2025-59382-QNAP-Password-Reset-Account-Takeover

GitHubrat5ak/cve-2025-59382-qnap-password-reset-account-takeover

Proof-of-concept and technical writeup for CVE-2025-59382, an unauthenticated password reset URL injection in QNAP NAS that enables a…

educationexploitationpenetration-testing+3
11 month ago
CVE-2026-0920- preview

CVE-2026-0920-

GitHubnxploited/cve-2026-0920-

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

educationexploitationprivilege-escalation+3
24 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubez4rd1x1/cve-2026-8181

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

authentication-authorizationctfeducation+5
2 months ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubsariamubeen/cve-2023-7028

Python exploit for CVE-2023-7028, abusing GitLab password reset poisoning to take over accounts including administrators via crafted email requests.

educationexploitationpassword-attacks+3
31 year ago
WordPress-KeepInMind-CVE-2026-9271-Exploit preview

WordPress-KeepInMind-CVE-2026-9271-Exploit

GitHubcerberusmrxi/wordpress-keepinmind-cve-2026-9271-exploit

Authorized stored XSS assessment tool for CVE-2026-9271 in WordPress KeepInMind plugin. Detects vulnerable versions, injects safe test payloads, and…

educationexploitationpenetration-testing+3
11 month ago
CVE-2024-9264 preview

CVE-2024-9264

GitHubcythonic1/cve-2024-9264

A go implementation for CVE-2024-9264 which effect grafana versions 11.0.x, 11.1.x, and 11.2.x.

educationexploitationpenetration-testing+2
31 year ago
kirki-wordpress-account-security-assessment preview

kirki-wordpress-account-security-assessment

GitHubamnsecurity/kirki-wordpress-account-security-assessment

Professional vulnerability assessment report for Kirki WordPress account security risk, including technical impact, remediation, and mitigation…

educationpapers-researchpenetration-testing+2
11 month ago
CVE-2025-24000-exploit preview

CVE-2025-24000-exploit

GitHubbsdrip/cve-2025-24000-exploit

Short Python script for exploiting CVE-2025–24000 based on this blog post: https://medium.com/@security_56355/from-subscriber-to-admin-reproducing-cve…

educationexploitationpenetration-testing+3
4 months ago
CVE-2026-6741 preview

CVE-2026-6741

GitHubxxconi/cve-2026-6741

CVE-2026-6741 is a CVSS 8.8 (High) Authenticated (Agent+) Privilege Escalation vulnerability in the LatePoint – Calendar Booking Plugin

ctfeducationexploitation+4
3 months ago
CVE-2025-14893 preview

CVE-2025-14893

GitHubd3kc4rt1/cve-2025-14893

Authenticated Stored Cross-Site Scripting (XSS) in IndieWeb WordPress Plugin

educationexploitationpapers-research+3
4 months ago
CVE-2022-37932 preview

CVE-2022-37932

GitHubtim-hoekstra/cve-2022-37932

Proof-of-concept exploit for an authentication bypass in HP 1920 Series switches, allowing unauthenticated admin password change via crafted HTTP…

educationexploitationiot-security+3
21 year ago
Previous1…5678Next