Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
103 results
AntiWeb_testing-Suite preview

AntiWeb_testing-Suite

GitHubmdudek-ics/antiweb_testing-suite

Suite de herramientas que sacan partido del CVE-2017-9097 (+RCE)

exploitationpassword-crackingreconnaissance+2
2
8 years ago
wp2shell preview

wp2shell

GitHubiqbalx7/wp2shell

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

api-securityexploitationpassword-cracking+4
2 months ago
CVE-2025-44203 preview

CVE-2025-44203

GitHubivant7d3/cve-2025-44203

Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

exploitationinformation-gatheringpassword-cracking+2
3 months ago
WP-Contest-Gallery-28.1.4-Exploit preview

WP-Contest-Gallery-28.1.4-Exploit

GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

exploitationpassword-crackingpayload-development+4
12 months ago
CVE-2024-55555 preview

CVE-2024-55555

GitHubyucaerin/cve-2024-55555

Laravel Crypto Killer Mass Scanner (CVE-2024-55555)

encryption-decryption-toolsexploitationpassword-cracking+3
21 year ago
CVE-2023-6063-PoC preview

CVE-2023-6063-PoC

GitHubincommatose/cve-2023-6063-poc

A Proof on Concept for CVE-2023-6063, a time-based blind SQL injection vulnerability in WP Fastest Cache ≤1.2.2.

educationexploitationpassword-cracking+3
21 year ago
CVE-2022-0169 preview

CVE-2022-0169

GitHubx3rx3ssec/cve-2022-0169

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

educationexploitationinformation-gathering+3
31 year ago
CMS-Made-Simple-2.2.9-CVE-2019-9053 preview

CMS-Made-Simple-2.2.9-CVE-2019-9053

GitHubazrenom/cms-made-simple-2.2.9-cve-2019-9053

Exploit for CVE-2019-9053, an unauthenticated SQL injection in CMS Made Simple 2.2.9, that extracts admin credentials and optionally cracks the…

exploitationpassword-crackingpenetration-testing+2
32 years ago
Make-and-Break preview

Make-and-Break

GitHubrayferrufino/make-and-break

Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine

educationexploitationexploit-frameworks+6
17 years ago
CVE-2025-68999-POC preview

CVE-2025-68999-POC

GitHubfolks-iwd/cve-2025-68999-poc

PoC exploit for CVE-2025-68999 - Second-Order SQL Injection in Happy Addons for Elementor <= 3.20.4

educationexploitationpassword-cracking+3
11 month ago
onetwoseven-writeup preview

onetwoseven-writeup

GitHubdopaminauta/onetwoseven-writeup

HTB OneTwoSeven full walkthrough: deterministic creds, chroot symlink escape, rewrite-rule bypass RCE, CVE-2024-1086 to root

ctfeducationexploitation+7
12 months ago
CVE-2021-43798 preview

CVE-2021-43798

GitHubokymi-x/cve-2021-43798

Python toolkit for authorized testing of CVE-2021-43798 Grafana path traversal, with arbitrary file read PoC, secret decryption, and user hash export…

encryption-decryption-toolsexploitationinformation-gathering+3
14 months ago
cms-made-simple-python3 preview

cms-made-simple-python3

GitHubjagdeepsinghceh/cms-made-simple-python3

Python3-converted exploit and research notes for CMS Made Simple (CVE-2019-9053) — Unauthenticated SQL Injection vulnerability. Includes original…

educationexploitationpassword-cracking+3
210 months ago
CVE-2024-21754-Forti-RCE preview

CVE-2024-21754-Forti-RCE

GitHubcybersecuritist/cve-2024-21754-forti-rce

Exploit for CVE-2024-21754 targeting insufficient password hashing in FortiOS and FortiProxy, enabling privileged attackers to decrypt backup files…

exploitationnetwork-securitypassword-cracking+2
22 years ago
CVE-2022-35513 preview

CVE-2022-35513

GitHubp1ckzi/cve-2022-35513

CVE-2022-35513 | blink1-pass-decrypt

cryptographyencryption-decryption-toolsexploitation+3
24 years ago
shirocrack preview

shirocrack

GitHuban00brektn/shirocrack

Simple hash cracker for Apache Shiro hashes written in Golang. Useful for exploiting CVE-2024-4956.

exploitationhash-analysispassword-cracking+2
22 years ago
CVE-2019-9053-exploit preview

CVE-2019-9053-exploit

GitHubjeanback1/cve-2019-9053-exploit

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

exploitationinformation-gatheringpassword-cracking+3
4 months ago
CVE-2019-9053 preview

CVE-2019-9053

GitHubitzr1g/cve-2019-9053

Python exploit for CVE-2019-9053 targeting CMS Made Simple with SQL injection detection and password hash cracking via wordlist, featuring argparse…

educationexploitationpassword-cracking+3
5 months ago
Previous123456Next