Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
98 results
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
19
5 months ago
CVE-2024-5522 preview

CVE-2024-5522

GitHubgeniuszly/cve-2024-5522

PoC exploit scanner for CVE-2024-5522 in WordPress. Scans target URLs with custom payloads to identify vulnerable sites, outputting color-coded…

educationexploitationpayload-development+3
101 year ago
BurpWpsScan preview

BurpWpsScan

GitHubteycir/burpwpsscan

Burp extension for wordpress security scanning

api-security-testingeducationexploitation+5
116 months ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubbodoinon/cve-2024-10924

Demonstrates exploitation and mitigation of CVE-2024-10924, an authentication bypass in WordPress Really Simple Security, with automated Python…

authenticationeducationexploitation+3
9 months ago
CVE-2025-4606 preview

CVE-2025-4606

GitHubyetazyyy/cve-2025-4606

Python-based scanner that tests WordPress sites for CVE-2025-4606, a privilege escalation vulnerability in the Sala theme allowing unauthenticated…

educationexploitationpenetration-testing+3
6 months ago
CVE-2023-2732 preview

CVE-2023-2732

GitHubap0dexme0/cve-2023-2732

Perform With Massive Authentication Bypass (Wordpress Mstore-API)

authenticationeducationpenetration-testing+2
23 years ago
rcno-reviews preview

rcno-reviews

GitHubsudotom/rcno-reviews

Recencio Book Reviews - WordPress plugin for managing book reviews. Originally created by Kemory Grubb. Security-patched fork resolving…

code-analysiscurated-resourceseducation+3
17 months ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubdiego-tella/cve-2023-3460

Exploit and scanner for CVE-2023-3460, a WordPress Ultimate Member plugin privilege escalation vulnerability allowing unauthenticated admin account…

educationexploitationpenetration-testing+2
73 years ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubiteride/cve-2025-2294

Proof-of-concept exploit for CVE-2025-2294, a critical LFI vulnerability in Kubio AI Page Builder for WordPress. Includes a Python scanner, nuclei…

educationexploitationpenetration-testing+3
1 year ago
CVE-2026-3844 preview

CVE-2026-3844

GitHubanggatechi/cve-2026-3844

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

educationexploitationpayload-development+3
21 month ago
Mass-Scanner-CVE-2026-3891 preview

Mass-Scanner-CVE-2026-3891

GitHubanggatechi/mass-scanner-cve-2026-3891

Python-based mass scanner for validating a specific WordPress AJAX behavior in authorized environments, supporting URL normalization, endpoint…

educationlabs-practicepenetration-testing+2
25 months ago
cve-2026-87902-wordpress-lfi-lab preview

cve-2026-87902-wordpress-lfi-lab

GitHubdinosn/cve-2026-87902-wordpress-lfi-lab

Reproduction lab + URL-list scanner + PoC for CVE-2026-87902 / GHSA-7hp8-65ch-5whp — WordPress get_page_template() unauthenticated LFI to conditional…

educationexploitationlabs-practice+7
36 days ago
CVE-2026-80467 preview

CVE-2026-80467

GitHubsangsenimanwartefak/cve-2026-80467

Python detection tool that fingerprints ACF Extended forms on WordPress and checks for publicly exposed role fields indicating CVE-2026-80467…

educationpenetration-testingprivilege-escalation+4
12 days ago
CVE-2026-0920 preview

CVE-2026-0920

GitHubdx3iz/cve-2026-0920

Creating a Wordpress Admin User

educationexploitationpenetration-testing+3
2 months ago
CVE-2026-93485 preview

CVE-2026-93485

GitHub0xblackash/cve-2026-93485

Defensive research repository for CVE-2026-93485, a WordPress core stored XSS flaw, with version-check scanner, technical analysis, and patch…

defensive-toolseducationpapers-research+3
7 days ago
cve-2019-9978 preview

cve-2019-9978

GitHubcved-sources/cve-2019-9978

Docker container providing a vulnerable environment for CVE-2019-9978 (WordPress Social Networks Auto Poster RCE) for security training and…

container-securityeducationexploitation+3
5 years ago
ODH-BricksBuilder-CVE-2024-25600-THM preview

ODH-BricksBuilder-CVE-2024-25600-THM

GitHubivanbg2004/odh-bricksbuilder-cve-2024-25600-thm

OD&H's scanner for CVE-2024-25600 vulnerability in the Bricks Builder WordPress plugin. For use in Try Hack Me (THM) environments.

educationexploitationlabs-practice+3
1 year ago
setup-wordpress-with-security-best-practice preview

setup-wordpress-with-security-best-practice

GitHubpassword123456/setup-wordpress-with-security-best-practice

Comprehensive guide for hardening WordPress installations: covers admin user changes, HTTPS enforcement, plugin security, file permissions, and…

configuration-auditingeducationweb-security
292 years ago
Previous123456Next