Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
350 results
Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover preview

Cluster-Chaos-Exploiting-CVE-2025-59359-for-Kubernetes-Takeover

GitHubmrk336/cluster-chaos-exploiting-cve-2025-59359-for-kubernetes-takeover

A hands-on forensic walkthrough of CVE-2025-59359, a critical OS command injection flaw in Chaos-Mesh. Learn how attackers hijack Kubernetes clusters…

cloud-securitycommand-and-controlcontainer-security+8
11 months ago
CVE-2025-4606 preview

CVE-2025-4606

GitHubyucaerin/cve-2025-4606

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

exploitationpassword-attacksprivilege-escalation+3
1 year ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubmrdottt/cve-2021-22911

Exploit for CVE-2021-22911: pre-auth blind NoSQL injection in Rocket Chat 3.12.1 enabling account takeover and remote code execution via webhook…

exploitationpenetration-testingprivilege-escalation+3
3 years ago
CVE-2025-25968 preview

CVE-2025-25968

GitHubpadayali-jd/cve-2025-25968

Proof-of-concept exploit for CVE-2025-25968, an improper access control vulnerability in DDSN Interactive cm3 Acora CMS v10.1.1. Enables…

exploitationinformation-gatheringpenetration-testing+3
11 months ago
fortinet-cve-2024-46671 preview

fortinet-cve-2024-46671

GitHubixec-lab/fortinet-cve-2024-46671

Automated exploit for an authenticated IDOR vulnerability in FortiWeb 7.4.3, enabling privilege escalation and account takeover via a logical bug.

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2023-26866 preview

CVE-2023-26866

GitHublionelmusonza/cve-2023-26866

Proof-of-concept exploit for CVE-2023-26866: remote command injection in GreenPacket WR-1200 and OT-235 routers enabling pre-login root-level device…

command-and-controlexploitationprivilege-escalation+3
3 years ago
CVE-2019-9053 preview

CVE-2019-9053

GitHubso1icitx/cve-2019-9053

Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.

educationexploitationpassword-cracking+3
1 year ago
nepstech-xpon-router-CVE-2024-40119 preview

nepstech-xpon-router-CVE-2024-40119

GitHubbaroi-ai/nepstech-xpon-router-cve-2024-40119

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

exploitationiot-securitypenetration-testing+3
2 years ago
CVE-2024-13513 preview

CVE-2024-13513

GitHubktn1990/cve-2024-13513

Oliver POS – A WooCommerce Point of Sale (POS) <= 2.4.2.3 - Sensitive Information Exposure to Privilege Escalation

exploitationinformation-gatheringpenetration-testing+3
1 year ago
Mass-CVE-2026-23550-Exploit preview

Mass-CVE-2026-23550-Exploit

GitHubdzmind2312/mass-cve-2026-23550-exploit

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

exploitationinformation-gatheringpenetration-testing+3
26 months ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubdebugactiveprocess/cve-2026-18963

Nuclei template to discover exposed Keycloak reset-credentials endpoints across multiple paths, aiding validation of CVE-2026-18963 exposure.

exploitationpenetration-testingreconnaissance+2
3 days ago
CVE-2026-23550 preview

CVE-2026-23550

GitHubdedsecteam-blackhat/cve-2026-23550

Bash script for WordPress user enumeration and automated admin account creation, exploiting CVE-2026-23550 to bypass authentication and achieve…

exploitationinformation-gatheringpenetration-testing+3
16 months ago
CVE-2026-0920 preview

CVE-2026-0920

GitHubjohn-doe-code-a11/cve-2026-0920

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

exploitationpayload-developmentpenetration-testing+2
77 months ago
PySQLRecon preview

PySQLRecon

GitHubtw1sm/pysqlrecon

Offensive MSSQL toolkit written in Python, based off SQLRecon

command-and-controldatabase-securityexploitation+3
2123 months ago
whoc preview

whoc

GitHubtwistlock/whoc

A container image that exfiltrates the underlying container runtime to a remote server

cloud-securitycontainer-securitydata-exfiltration+1
1353 years ago
CVE-2021-2109 preview

CVE-2021-2109

GitHubal1ex/cve-2021-2109

CVE-2021-2109 && Weblogic Server RCE via JNDI

educationexploitationpayload-generation+3
315 years ago
CVE-2023-30943 preview

CVE-2023-30943

GitHubd0rb/cve-2023-30943

This repository contains combined exploits for two vulnerabilities in Moodle, a widely used open-source learning management system (LMS)

educationexploitationpenetration-testing+2
182 years ago
CVE-2025-2304-POC preview

CVE-2025-2304-POC

GitHubd3vn0mi/cve-2025-2304-poc

Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.

educationexploitationpayload-generation+4
103 months ago
Previous1…567…20Next