Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
40 results
CVE-2026-49468-LiteLLM-Auth-Bypass preview

CVE-2026-49468-LiteLLM-Auth-Bypass

GitHubbiitts/cve-2026-49468-litellm-auth-bypass

CVE-2026-49468 — LiteLLM (<1.84.0) unauthenticated auth bypass via Host-header route confusion. PoC + docker lab.

authenticationeducationexploitation+4
5
3 months ago
wp2shell-lab preview

wp2shell-lab

GitHub47cid/wp2shell-lab

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

code-analysisctfeducation+7
152 months ago
CVE-2026-33032 preview

CVE-2026-33032

GitHubkeraattin/cve-2026-33032

One missing function call on the route registration was enough to turn the MCP interface into an unauthenticated RCE gateway.

api-securityexploitationnetwork-security+4
55 months ago
wp2shell-lab preview

wp2shell-lab

GitHubdinosn/wp2shell-lab

Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress…

educationexploitationlabs-practice+3
632 months ago
wp2shell preview

wp2shell

GitHubikow/wp2shell

wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.

educationexploitationlabs-practice+4
102 months ago
wp2shell-detect preview

wp2shell-detect

GitHubown2pwn-fr/wp2shell-detect

Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.

information-gatheringpenetration-testingreconnaissance+3
42 months ago
wp2shell-poc preview

wp2shell-poc

GitHubicex0/wp2shell-poc

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

authenticationcommand-and-controlexploitation+5
7851 month ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubkernelzeroday/cve-2026-29000

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

authentication-authorizationexploitationpayload-generation+5
87 months ago
hardcidr preview

hardcidr

GitHubtrustedsec/hardcidr

Bash script for passive reconnaissance that queries RIRs and BGP route servers to discover target organization netblocks, ASNs, and CIDR ranges…

information-gatheringnetwork-mappingosint+2
3834 years ago
NoiseHound preview

NoiseHound

GitHubwarpedatom/noisehound

Detection-aware BloodHound attack-path scoring - the quietest route to your objective, calibrated across five detection tiers…

adversarial-attackdefensive-toolslateral-movement+4
671 month ago
CVE-2026-85706 preview

CVE-2026-85706

GitHubeqstlab/cve-2026-85706

PoC and Docker lab for CVE-2026-85706, an unauthenticated arbitrary file read in GitLab CE/EE via the commits API route bypass and urlencoded error…

data-exfiltrationexploitationinformation-gathering+5
259 days ago
wordpress-cve-2026-63030 preview

wordpress-cve-2026-63030

GitHubsenanfurkan/wordpress-cve-2026-63030

Pre-auth RCE in WordPress Core via REST API batch route confusion + WP_Query SQLi (CVE-2026-63030 / CVE-2026-60137). Detection PoC.

exploitationpayload-developmentpenetration-testing+2
52 months ago
CVE-2018-20062 preview

CVE-2018-20062

GitHubjasper2018/cve-2018-20062

Verification script and PoC for CVE-2018-20062, the ThinkPHP 5.0.x invokefunction deserialization RCE, confirming route reachability and capturing…

exploitationpenetration-testingvulnerability-analysis+2
27 days ago
CVE-2026-63030-CVE-2026-60137 preview

CVE-2026-63030-CVE-2026-60137

GitHubgiangdurian/cve-2026-63030-cve-2026-60137

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

ctfeducationexploitation+4
2 months ago
CVE-2026-60137_CVE-2026-63030 preview

CVE-2026-60137_CVE-2026-63030

GitHubdungsocool/cve-2026-60137_cve-2026-63030

WordPress unauthenticated RCE exploit combining route confusion and SQL injection. Automated script, lab setup, and detailed vulnerability analysis…

educationexploitationlabs-practice+3
2 months ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubshinthink/cve-2026-63030

WordPress Core Pre-Auth RCE via REST Batch Route Confusion + SQLi (CVE-2026-63030 + CVE-2026-60137)

educationexploitationpayload-development+4
2 months ago
PressVector preview

PressVector

GitHubvulnquest58/pressvector

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

information-gatheringpenetration-testingreconnaissance+3
12 months ago
CVE-2026-63030 preview

CVE-2026-63030

GitHubanggatechi/cve-2026-63030

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

exploitationpenetration-testingpost-exploitation+3
12 months ago
Previous123Next