Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
19 results
CVE-2026-40776 preview

CVE-2026-40776

GitHublorenzofradeani/cve-2026-40776

CVE-2026-40776 — Broken Access Control + IDOR in WordPress Eventin (wp-event-solution) <= 4.1.8

educationexploitationpapers-research+3
2
3 months ago
CVE-2025-11391 preview

CVE-2025-11391

GitHubr3db34rdh4x/cve-2025-11391

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

educationexploitationpapers-research+2
10 months ago
CVE-2024-1208-and-CVE-2024-1210 preview

CVE-2024-1208-and-CVE-2024-1210

GitHubkarlemilnikka/cve-2024-1208-and-cve-2024-1210

Detailed disclosure of CVE-2024-1208 and CVE-2024-1210: sensitive information exposure via REST API in LearnDash WordPress plugin, allowing…

api-securityeducationinformation-gathering+3
32 years ago
CVE-2026-9830 preview

CVE-2026-9830

GitHubchpratik/cve-2026-9830

Threat intelligence report repository for CVE-2026-9830, an authentication bypass vulnerability in BookingPress Pro WordPress plugin, with detailed…

authenticationincident-responsepapers-research+5
11 month ago
CVE-2024-5932 preview

CVE-2024-5932

GitHubnishant-kumar-5173/cve-2024-5932

Proof-of-concept exploit for CVE-2024-5932, a PHP object injection vulnerability in the GiveWP WordPress plugin, enabling unauthenticated remote code…

code-analysiseducationexploitation+5
3 months ago
CVE-2025-0924-different preview

CVE-2025-0924-different

GitHubskrkcb2/cve-2025-0924-different

Technical analysis of CVE-2025-0924, a Stored XSS vulnerability in WP Activity Log plugin for WordPress. Includes root cause analysis, exploitation…

educationexploitationpapers-research+2
1 year ago
kirki-wordpress-account-security-assessment preview

kirki-wordpress-account-security-assessment

GitHubamnsecurity/kirki-wordpress-account-security-assessment

Professional vulnerability assessment report for Kirki WordPress account security risk, including technical impact, remediation, and mitigation…

educationpapers-researchpenetration-testing+2
11 month ago
CVE-2026-6227 preview

CVE-2026-6227

GitHubpixel-defaultbr/cve-2026-6227

Educational proof-of-concept for CVE-2026-6227, an authenticated Local File Inclusion in BackWPup WordPress plugin, including root cause analysis,…

educationexploitationpapers-research+2
4 months ago
CVE-2025-14893 preview

CVE-2025-14893

GitHubd3kc4rt1/cve-2025-14893

Authenticated Stored Cross-Site Scripting (XSS) in IndieWeb WordPress Plugin

educationexploitationpapers-research+3
4 months ago
CVE-2025-14783-POC preview

CVE-2025-14783-POC

GitHubzeroethical/cve-2025-14783-poc

🧨 CVE-2025-14783: Easy Digital Downloads Account Takeover PoC

educationexploitationpapers-research+4
28 months ago
CVE-2026-63030-Wp2Shell preview

CVE-2026-63030-Wp2Shell

GitHubghostinexile/cve-2026-63030-wp2shell

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

code-analysiseducationexploitation+3
41 month ago
CVE-2025-9776 preview

CVE-2025-9776

GitHubsnailsploit/cve-2025-9776

CVE-2025-9776 — CatFolders WordPress Plugin: Authenticated SQL Injection via CSV Import | POC + Walkthrough

educationexploitationpapers-research+3
3 months ago
CVE-2025-12030 preview

CVE-2025-12030

GitHubsnailsploit/cve-2025-12030

ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - Security flaw allowing authenticated users with Contributor-level access to…

educationexploitationpapers-research+3
3 months ago
CVE-2025-12163 preview

CVE-2025-12163

GitHubsnailsploit/cve-2025-12163

CVE-2025-12163: Stored Cross-Site Scripting in Omnipress WordPress Plugin

educationpapers-researchvulnerability-analysis+2
3 months ago
CVE-2025-31033 preview

CVE-2025-31033

GitHubnxploited/cve-2025-31033

WordPress Buddypress Humanity Plugin <= 1.2 is vulnerable to Cross Site Request Forgery (CSRF)

educationexploitationpapers-research+3
1 year ago
CVE-2026-82221-PoC preview

CVE-2026-82221-PoC

GitHubgabrielftanaka/cve-2026-82221-poc

PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

educationexploitationpapers-research+2
1 day ago
CVE-2026-13156 preview

CVE-2026-13156

GitHubminhhk68/cve-2026-13156

CVE-2026-13156 Vulnerability Advisory & PoC — Discovered by Huynh Kien Minh (MinhHK).

educationexploitationpapers-research+3
1 month ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubdungsocool/cve-2026-8206

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

authenticationeducationexploitation+6
11 month ago
Previous12Next