Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
1 month ago
Burp_AES_Plugin preview

Burp_AES_Plugin

GitHubjas502n/burp_aes_plugin

Burpsuite Plugin For AES Crack

cryptographyencryption-decryption-toolsfuzzing+4
386 years ago
wpbf preview

wpbf

GitHubatarantini/wpbf

Remotely test password strength of WordPress bloging software

information-gatheringpassword-attackspenetration-testing+3
10710 years ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
12 years ago
CVE-2024-10508 preview

CVE-2024-10508

GitHububaydev/cve-2024-10508

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

authentication-authorizationeducationpassword-attacks+3
1 year ago
teamcity-idea-cve-2020-35667-poc preview

teamcity-idea-cve-2020-35667-poc

GitHubstefan-500/teamcity-idea-cve-2020-35667-poc

TeamCity IntelliJ IDEA Plugin Credential Interception

exploitationinformation-gatheringpassword-attacks+3
10 months ago
CVE-2025-14998 preview

CVE-2025-14998

GitHubktn1990/cve-2025-14998

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

authenticationexploitationpassword-attacks+3
28 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubshootcannon/cve-2026-5076

ARMember Premium <= 7.3.1 Full Admin Account Takeover

exploitationinformation-gatheringpassword-attacks+3
3 months ago
CVE-2025-4094-POC preview

CVE-2025-4094-POC

GitHubpocpioneer/cve-2025-4094-poc

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

authentication-authorizationexploitationpassword-attacks+3
21 year ago
CVE-2025-4094 preview

CVE-2025-4094

GitHubstarawneh/cve-2025-4094

CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass

authenticationexploitationpassword-attacks+3
11 year ago
CVE-2025-3605 preview

CVE-2025-3605

GitHubnxploited/cve-2025-3605

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

educationexploitationpassword-attacks+4
21 year ago
CVE-2025-3604 preview

CVE-2025-3604

GitHubnxploited/cve-2025-3604

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

authentication-authorizationeducationexploitation+5
11 year ago
CVE-2025-12539 preview

CVE-2025-12539

GitHubnxploited/cve-2025-12539

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

educationexploitationinformation-gathering+6
79 months ago
CVE-2023-32243 preview

CVE-2023-32243

GitHubrandomrobbiebf/cve-2023-32243

CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

exploitationpassword-attackspenetration-testing+3
863 years ago
CVE-2020-35590 preview

CVE-2020-35590

GitHubn4nj0/cve-2020-35590

Brute-force tool for WordPress Plugin Limit Login Attempts Reloaded >=2.13.0 - Login Limit Bypass (CVE-2020-35590)

authenticationexploitationpassword-attacks+3
810 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
3 months ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubjenderal92/cve-2026-8206

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

educationexploitationinformation-gathering+5
33 months ago
CVE-2025-15030 preview

CVE-2025-15030

GitHubnxploited/cve-2025-15030

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

exploitationpassword-attackspenetration-testing+3
14 months ago
Previous12Next