Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
36 results
ettercap preview

ettercap

GitHubettercap/ettercap

Ettercap Project

dns-analysisexploitationinformation-gathering+6
2.8k22h 48m ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubalihzsec/cve-2024-28000

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

educationexploitationlabs-practice+5
1 month ago
CVE-2026-11387 preview

CVE-2026-11387

GitHub1beelze/cve-2026-11387

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

authenticationexploitationpassword-attacks+4
12 months ago
CVE-2026-10580 preview

CVE-2026-10580

GitHub0xgh057r3c0n/cve-2026-10580

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

authentication-authorizationeducationexploitation+4
2 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubshootcannon/cve-2026-5076

ARMember Premium <= 7.3.1 Full Admin Account Takeover

exploitationinformation-gatheringpassword-attacks+3
3 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
3 months ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubjenderal92/cve-2026-8206

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

educationexploitationinformation-gathering+5
33 months ago
CVE-2025-15521 preview

CVE-2025-15521

GitHubnxploited/cve-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

authenticationexploitationinformation-gathering+5
14 months ago
CVE-2025-15030 preview

CVE-2025-15030

GitHubnxploited/cve-2025-15030

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

exploitationpassword-attackspenetration-testing+3
14 months ago
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
4 months ago
CVE-2025-14736 preview

CVE-2025-14736

GitHubhyunchiya/cve-2025-14736

Unauthenticated Privilege Escalation to Administrator via Role Form Field

exploitationpassword-attackspenetration-testing+4
7 months ago
CVE-2025-14998 preview

CVE-2025-14998

GitHubktn1990/cve-2025-14998

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

authenticationexploitationpassword-attacks+3
28 months ago
CVE-2025-4796 preview

CVE-2025-4796

GitHubanothersec/cve-2025-4796

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

exploitationpassword-attackspenetration-testing+3
19 months ago
CVE-2025-12539 preview

CVE-2025-12539

GitHubnxploited/cve-2025-12539

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

educationexploitationinformation-gathering+6
79 months ago
CVE-2023-5359 preview

CVE-2023-5359

GitHubenzocipher/cve-2023-5359

CVE-2023-5359 scanner for W3 Total Cache cleartext storage vulnerability. Detects exposed credentials (API keys, OAuth tokens) in publicly accessible…

educationexploitationinformation-gathering+3
10 months ago
teamcity-idea-cve-2020-35667-poc preview

teamcity-idea-cve-2020-35667-poc

GitHubstefan-500/teamcity-idea-cve-2020-35667-poc

TeamCity IntelliJ IDEA Plugin Credential Interception

exploitationinformation-gatheringpassword-attacks+3
10 months ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubebrasha/cve-2024-28000

LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000

educationexploitationinformation-gathering+5
510 months ago
CVE-2020-35590 preview

CVE-2020-35590

GitHubn4nj0/cve-2020-35590

Brute-force tool for WordPress Plugin Limit Login Attempts Reloaded >=2.13.0 - Login Limit Bypass (CVE-2020-35590)

authenticationexploitationpassword-attacks+3
810 months ago
Previous12Next