Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
CVE-2024-9796 preview

CVE-2024-9796

GitHubbwithe/cve-2024-9796

CVE-2024-9796 WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection. Poc.

educationexploitationpassword-cracking+2
4
1 year ago
CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction preview

CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction

GitHubdhananjayasj/cve-2024-1698-notificationx-wordpress-plugin-sql-injection-to-admin-credential-extraction

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

exploitationinformation-gatheringpassword-cracking+3
3 months ago
SSI-CVE-2022-21661 preview

SSI-CVE-2022-21661

GitHubwellingtonespindula/ssi-cve-2022-21661

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

educationexploitationlabs-practice+3
62 years ago
CVE-2025-4396 preview

CVE-2025-4396

GitHubnefhara/cve-2025-4396

This repository contains a practical research and validation toolkit for CVE-2025-4396, an unauthenticated Time-Based Blind SQL Injection affecting…

educationexploitationpassword-cracking+3
5 months ago
WP-Contest-Gallery-28.1.4-Exploit preview

WP-Contest-Gallery-28.1.4-Exploit

GitHubcerberusmrxi/wp-contest-gallery-28.1.4-exploit

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

exploitationpassword-crackingpayload-development+4
11 month ago
CVE-2025-4396 preview

CVE-2025-4396

GitHubsup3rdav3/cve-2025-4396

CVE-2025-4396 - WordPress Relevanssi Time-Based Blind SQL Injection

ctfeducationexploitation+5
3 months ago
CVE-2025-2011 preview

CVE-2025-2011

GitHubx3rx3ssec/cve-2025-2011

Exploit for CVE-2025-2011

exploitationpassword-crackingpenetration-testing+2
19 months ago
wp2shell preview

wp2shell

GitHub0xsha/wp2shell

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

command-and-controleducationexploitation+7
1041 month ago
wpCrack preview

wpCrack

GitHubm4dm0e/wpcrack

wordpress hash cracker .

authenticationinformation-gatheringpassword-cracking+2
644 years ago
wp2shell preview

wp2shell

GitHubiqbalx7/wp2shell

unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

api-securityexploitationpassword-cracking+4
1 month ago
CVE-2022-0169 preview

CVE-2022-0169

GitHubx3rx3ssec/cve-2022-0169

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

educationexploitationinformation-gathering+3
31 year ago
wp2shell preview

wp2shell

GitHubekomssavior/wp2shell

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)

exploitationinformation-gatheringpassword-cracking+5
81 month ago