Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
569 results
even-you-brutus preview

even-you-brutus

GitHubj-baines/even-you-brutus

Dictionary Brute Force of the Mikrotik RouterOS 6.x Web Interface

authenticationembedded-systems-securityexploitation+5
9
3 years ago
joomla-bruteforce preview

joomla-bruteforce

GitHubajnik/joomla-bruteforce

Python script that brute-forces Joomla administrator login credentials using wordlists, with proxy and verbose options for penetration testing.

authenticationpassword-attackspassword-cracking+4
1382 years ago
GoFileX preview

GoFileX

GitHubabraxas/gofilex

Wordlist Bruteforcer for GoFile (gofile.io) Download Passwords

ctfinformation-gatheringpassword-attacks+5
1 month ago
Kimai-CVE-2026-52824-POC preview

Kimai-CVE-2026-52824-POC

GitHubcyeezy08/kimai-cve-2026-52824-poc

PoC exploits for CVE-2026-52824 (GHSA-jr9p-4h4j-6c58) — Kimai time-tracking default APP_SECRET authentication bypass affecting versions ≤ 2.57.0

authenticationexploitationinformation-gathering+7
17 days ago
CVE-2026-48611-phpBB preview

CVE-2026-48611-phpBB

GitHublxdwnpiper/cve-2026-48611-phpbb

Python proof-of-concept exploit that bypasses authentication in phpBB 3.3.16 and below by forging session cookies to gain admin access.

authenticationexploitationpassword-attacks+4
3 months ago
CVE-2026-96451 preview

CVE-2026-96451

GitHubnxploited/cve-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

exploitationpassword-attackspenetration-testing+5
4 days ago
OMEN preview

OMEN

GitHubrub-syssec/omen

Markov model-based password guesser in C that enumerates candidates by probability, generating most likely passwords first for hash cracking via…

cryptographyhash-analysispapers-research+3
3357 years ago
CVE-2026-14281 preview

CVE-2026-14281

GitHublangz337/cve-2026-14281

Mass scanner and single-target exploit for CVE-2026-14281, an unauthenticated privilege escalation in the WordPress Automation Web Platform plugin…

exploitationpassword-attackspenetration-testing+6
112 days ago
CVE-2026-15989 preview

CVE-2026-15989

GitHubantid00t/cve-2026-15989

Python PoC scanner for CVE-2026-15989, exploiting unauthenticated role injection in WordPress Super Forms to create admin accounts and verify access.

exploitationpassword-attackspenetration-testing+6
15 days ago
CVE-2026-61500 preview

CVE-2026-61500

GitHubaramosf/cve-2026-61500

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

cryptographyeducationexploitation+7
12 days ago
EmbedXPL-Forge preview

EmbedXPL-Forge

GitHubmrhenrike/embedxpl-forge

Embedded Device Security Assessment Framework — 700 modules, 350 CVEs, 55 vendors, APT Group Engine. Covers routers, IP cameras, GPON ONTs, ISP CPEs,…

embedded-systems-securityexploitationexploit-frameworks+9
4911 days ago
WordList preview

WordList

GitHubrix4uni/wordlist

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

dns-subdomain-enumerationfuzzinginformation-gathering+6
1553 months ago
By-Poloss..-..CVE-2026-19125 preview

By-Poloss..-..CVE-2026-19125

GitHubpolosss/by-poloss..-..cve-2026-19125

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

authenticationexploitationpassword-attacks+5
15 days ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubfl0ydsec/cve-2026-63030

Python mass exploit and detector for the WordPress Core pre-auth RCE chain CVE-2026-63030 and CVE-2026-60137, chaining SQL injection into remote code…

exploitationpassword-attackspayload-development+7
14 days ago
ntlmscout preview

ntlmscout

GitHubboydhacks/ntlmscout

Unauthenticated NTLM endpoint reconnaissance tool that decodes Type-2 challenges across HTTP, SMB, MSSQL, SMTP, IMAP, POP3, NNTP, LDAP, and RDP to…

authenticationdns-analysisinformation-gathering+8
5619 days ago
CVE-2026-93453 preview

CVE-2026-93453

GitHubfaceless0x7/cve-2026-93453

Python PoC for CVE-2026-93453, a SOGo password reset link poisoning flaw via attacker-controlled Origin header that enables reset token interception…

authenticationexploitationpassword-attacks+5
220 days ago
ResetSpy preview

ResetSpy

GitHubmlcsec/resetspy

Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal

authenticationdefensive-toolsidentity-management+6
5723 days ago
sshamble preview

sshamble

GitHubrunzeroinc/sshamble

Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

authenticationdefensive-toolsinformation-gathering+6
1.2k27 days ago
Previous12…32Next