Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
72 results
CVE-2026-96451 preview

CVE-2026-96451

GitHubnxploited/cve-2026-96451

WordPress Ultimate Member plugin <= 2.13.1 - Privilege Escalation vulnerability

exploitationpassword-attackspenetration-testing+5
1 day ago
wapiti preview

wapiti

GitHubwapiti-scanner/wapiti

Web vulnerability scanner written in Python3

api-security-testingconfiguration-auditingcrawler+11
1.9k1 day ago
Nettacker preview

Nettacker

GitHubowasp/nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

api-securityapi-security-testingdynamic-code-analysis+14
5.6k3 days ago
fscan preview

fscan

GitHubshadow1ng/fscan

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

educationexploitationlateral-movement+9
14.6k4 days ago
Netgrave preview

Netgrave

GitHubxewdy444/netgrave

A tool for retrieving login credentials from Netwave IP cameras using a memory dump vulnerability (CVE-2018-17240)

educationexploitationinformation-gathering+5
78 days ago
hexstrike-ai preview

hexstrike-ai

GitHub0x4m4/hexstrike-ai

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

binary-analysiscloud-securityctf+9
12.4k2 months ago
CVE-2026-60137 preview

CVE-2026-60137

GitHubadarshthakur14777-cyber/cve-2026-60137

wpsqli full SQLi extractor + dumper for CVE-2026-60137

database-securityexploitationinformation-gathering+5
2 months ago
CVE-2024-51482 preview

CVE-2024-51482

GitHubc0gnit00/cve-2024-51482

CVE-2025-51482 POC, Dump Credentials From zm.Users

educationexploitationinformation-gathering+4
2 months ago
solrradar preview

solrradar

GitHubshinthink/solrradar

☄️ Mass reconnaissance & exploitation framework for Apache Solr CVE-2026-44825 — Velocity template injection to RCE

command-and-controlexploitationinformation-gathering+7
53 months ago
CVE-2026-11387 preview

CVE-2026-11387

GitHub1beelze/cve-2026-11387

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

authenticationexploitationpassword-attacks+4
13 months ago
WSS preview

WSS

GitHubnu11secur1ty/wss

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

code-analysisinformation-gatheringpassword-attacks+3
33 months ago
CVE-2026-12416-CVE-2026-12417 preview

CVE-2026-12416-CVE-2026-12417

GitHubnxploited/cve-2026-12416-cve-2026-12417

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

authenticationexploitationpassword-attacks+3
33 months ago
CVE-2025-52488 preview

CVE-2025-52488

GitHubsh4den/cve-2025-52488

This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes…

exploitationinformation-gatheringpassword-attacks+3
23 months ago
CVE-2026-31278 preview

CVE-2026-31278

GitHubmda1r/cve-2026-31278

CVE write-up for Active Directory credential exposure vulnerability in Suprema BioStar 2

exploitationnetwork-securitypapers-research+3
3 months ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
4 months ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
4 months ago
wp-def preview

wp-def

GitHubjenderal92/wp-def

Wordpress Default Password

misconfigurationpassword-attacksvulnerability-analysis+1
24 months ago
Wordpress-Default-Password preview

Wordpress-Default-Password

GitHubjenderal92/wordpress-default-password

python 2.7

password-attackspenetration-testingweb-security+1
4 months ago
Previous1234Next