Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
CVE-2025-3102 preview

CVE-2025-3102

GitHubdennisec/cve-2025-3102

Exploit script for CVE-2025-3102 targeting SureTriggers WordPress plugin (≤ v1.0.78). Detects vulnerable versions, exploits via REST API, and creates…

educationexploitationpassword-attacks+3
1 year ago
routeros-CVE-2018-14847-bytheway preview

routeros-CVE-2018-14847-bytheway

GitHubbabyshen/routeros-cve-2018-14847-bytheway

By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:

embedded-systems-securityexploitationiot-security+3
43 years ago
CVE-2025-52488 preview

CVE-2025-52488

GitHubsh4den/cve-2025-52488

This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes…

exploitationinformation-gatheringpassword-attacks+3
22 months ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubduy-31/cve-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior…

exploitationpassword-attackspenetration-testing+2
32 years ago
CVE-2025-15521 preview

CVE-2025-15521

GitHubnxploited/cve-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

authenticationexploitationinformation-gathering+5
14 months ago
CVE-2026-31282 preview

CVE-2026-31282

GitHubsaykino/cve-2026-31282

Proof-of-concept for CVE-2026-31282: Totara LMS login page access control bypass enabling unauthenticated brute-force credential attacks. Includes…

authenticationeducationmisconfiguration+3
4 months ago
CVE-2023-22074 preview

CVE-2023-22074

GitHubemad-almousa/cve-2023-22074

Proof-of-concept exploit for CVE-2023-22074, an Oracle Database Sharding component vulnerability enabling password hash exposure in versions 19c,…

database-securityexploitationinformation-gathering+2
2 years ago
Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache preview

Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache

GitHubspyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache

Targets versions ≤2.7.5 vulnerable to CVE-2023-5359

exploitationinformation-gatheringpassword-attacks+3
1 year ago
wapiti preview

wapiti

GitHubwapiti-scanner/wapiti

Web vulnerability scanner written in Python3

api-security-testingconfiguration-auditingcrawler+11
1.9k18 days ago
pwn_jenkins preview

pwn_jenkins

GitHubgquere/pwn_jenkins

Notes about attacking Jenkins servers

exploitationinformation-gatheringpassword-attacks+6
2.1k2 years ago
pixiewps preview

pixiewps

GitHubwiire-a/pixiewps

An offline Wi-Fi Protected Setup brute-force utility

educationexploitationpassword-attacks+2
1.7k4 months ago
django-defender preview

django-defender

GitHubjazzband/django-defender

A simple super fast django reusable app that blocks people from brute forcing login attempts

authenticationdefensive-toolspassword-attacks+1
1.1k7 months ago
CVE-2025-12539 preview

CVE-2025-12539

GitHubnxploited/cve-2025-12539

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

educationexploitationinformation-gathering+6
79 months ago
CVE-2019-17240 preview

CVE-2019-17240

GitHubpingport80/cve-2019-17240

This is the exploit of CVE-2019-17240.

authenticationexploitationids-ips-evasion+2
35 years ago
CVE-2026-24418 preview

CVE-2026-24418

GitHubbridgeralderson/cve-2026-24418

OpenSTAManager v2.9.8 and earlier contain a critical Error-Based SQL Injection vulnerability in the bulk operations handler for the Scadenzario…

database-securityeducationexploitation+5
22 months ago
CVE-2026-10580 preview

CVE-2026-10580

GitHub0xgh057r3c0n/cve-2026-10580

PoC exploit for CVE-2026-10580 - Authentication Bypass in Hippoo Mobile App for WooCommerce <= 1.9.4 leading to Admin Account Takeover

authentication-authorizationeducationexploitation+4
2 months ago
CVE-2025-15030 preview

CVE-2025-15030

GitHubnxploited/cve-2025-15030

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

exploitationpassword-attackspenetration-testing+3
14 months ago
CVE-2025-4094-POC preview

CVE-2025-4094-POC

GitHubpocpioneer/cve-2025-4094-poc

WordPress Plugin Digits < 8.4.6.1 - OTP Auth Bypass via Bruteforce (CVE-2025-4094)

authentication-authorizationexploitationpassword-attacks+3
21 year ago
Previous12Next