Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
3 months ago
ettercap preview

ettercap

GitHubettercap/ettercap

Ettercap Project

dns-analysisexploitationinformation-gathering+6
2.8k22h 50m ago
Zphisher-GUI-Back_office preview

Zphisher-GUI-Back_office

GitHubmicro-joan/zphisher-gui-back_office

Real-time phishing campaign back-office plugin for Zphisher, capturing credentials, checking account exposure via haveibeenpwned, and evaluating…

information-gatheringosintpassword-attacks+2
2353 years ago
wpbf preview

wpbf

GitHubatarantini/wpbf

Remotely test password strength of WordPress bloging software

information-gatheringpassword-attackspenetration-testing+3
10710 years ago
CVE-2025-12539 preview

CVE-2025-12539

GitHubnxploited/cve-2025-12539

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

educationexploitationinformation-gathering+6
79 months ago
CVE-2026-10580 preview

CVE-2026-10580

GitHub0xgh057r3c0n/cve-2026-10580

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

authentication-authorizationeducationexploitation+4
2 months ago
CVE-2023-32243 preview

CVE-2023-32243

GitHubrandomrobbiebf/cve-2023-32243

CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

exploitationpassword-attackspenetration-testing+3
863 years ago
Burp_AES_Plugin preview

Burp_AES_Plugin

GitHubjas502n/burp_aes_plugin

Burpsuite Plugin For AES Crack

cryptographyencryption-decryption-toolsfuzzing+4
386 years ago
CVE-2026-11387 preview

CVE-2026-11387

GitHub1beelze/cve-2026-11387

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

authenticationexploitationpassword-attacks+4
12 months ago
CVE-2020-35590 preview

CVE-2020-35590

GitHubn4nj0/cve-2020-35590

Brute-force tool for WordPress Plugin Limit Login Attempts Reloaded >=2.13.0 - Login Limit Bypass (CVE-2020-35590)

authenticationexploitationpassword-attacks+3
810 months ago
CVE-2025-14998 preview

CVE-2025-14998

GitHubktn1990/cve-2025-14998

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

authenticationexploitationpassword-attacks+3
28 months ago
CVE-2025-3605 preview

CVE-2025-3605

GitHubnxploited/cve-2025-3605

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

educationexploitationpassword-attacks+4
21 year ago
CVE-2025-3604 preview

CVE-2025-3604

GitHubnxploited/cve-2025-3604

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

authentication-authorizationeducationexploitation+5
11 year ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubrajneeshkarya/cve-2023-3460

Exploit for the vulnerability of Ultimate Member Plugin.

exploitationpassword-attackspenetration-testing+2
12 years ago
CVE-2023-5359 preview

CVE-2023-5359

GitHubenzocipher/cve-2023-5359

CVE-2023-5359 scanner for W3 Total Cache cleartext storage vulnerability. Detects exposed credentials (API keys, OAuth tokens) in publicly accessible…

educationexploitationinformation-gathering+3
10 months ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubdennisec/cve-2025-3102

Exploit script for CVE-2025-3102 targeting SureTriggers WordPress plugin (≤ v1.0.78). Detects vulnerable versions, exploits via REST API, and creates…

educationexploitationpassword-attacks+3
1 year ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
1 month ago
CVE-2025-14736 preview

CVE-2025-14736

GitHubhyunchiya/cve-2025-14736

Unauthenticated Privilege Escalation to Administrator via Role Form Field

exploitationpassword-attackspenetration-testing+4
7 months ago
Previous12Next