Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
104 results
LSTAR-EN preview

LSTAR-EN

GitHubmoscowchill/lstar-en

LSTAR - CobaltStrike Translated to EN

command-and-controlexploitationids-ips-evasion+9
233 years ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubghostpels/cve-2026-18366

Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

exploitationinformation-gatheringprivilege-escalation+2
14 days ago
WP-GDPR-Compliance-Plugin-Exploit preview

WP-GDPR-Compliance-Plugin-Exploit

GitHubaeroot/wp-gdpr-compliance-plugin-exploit

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…

exploitationpayload-generationpenetration-testing+3
47 years ago
DuplicateDump preview

DuplicateDump

GitHubhagrid29/duplicatedump

Dumping LSASS with a duplicated handle from custom LSA plugin

post-exploitationprivilege-escalationred-teaming
2074 years ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubarch1m3d/cve-2024-28000

PoC for the CVE-2024 Litespeed Cache Privilege Escalation

educationexploitationpenetration-testing+3
71 year ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubez4rd1x1/cve-2026-8181

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

authentication-authorizationctfeducation+5
3 months ago
CVE-2026-49060-Lab preview

CVE-2026-49060-Lab

GitHubrootdirective-sec/cve-2026-49060-lab

Docker-based lab for reproducing CVE-2026-49060, an unauthenticated privilege escalation in the Hippoo Mobile App for WooCommerce WordPress plugin.…

educationlabs-practicepenetration-testing+3
2 months ago
staekka preview

staekka

GitHubj-0-t/staekka

Stækka Metasploit - Extenting Metasploit

anti-botexploit-frameworksforensics+7
549 years ago
MASS-CVE-2024-27956 preview

MASS-CVE-2024-27956

GitHubitzheartzz/mass-cve-2024-27956

Proof-of-concept exploit for CVE-2024-27956 SQL injection in ValvePress Automatic plugin. Creates admin users in WordPress to achieve remote code…

exploitationpayload-developmentpenetration-testing+3
32 years ago
CVE-2026-13152 preview

CVE-2026-13152

GitHubminhhk68/cve-2026-13152

CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).

educationexploitationpenetration-testing+4
11 month ago
CVE-2020-14321 preview

CVE-2020-14321

GitHublanzt/cve-2020-14321

Authenticated exploit for Moodle 3.9 that escalates teacher privileges to manager role and achieves remote code execution via malicious plugin upload.

exploitationpayload-generationpenetration-testing+3
214 years ago
CVE-2026-18366 preview

CVE-2026-18366

GitHubnxploited/cve-2026-18366

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

exploitationinformation-gatheringpost-exploitation+3
18 days ago
CVE-2026-8732-POC preview

CVE-2026-8732-POC

GitHubp3nt3st3r-star/cve-2026-8732-poc

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

exploitationinformation-gatheringpenetration-testing+4
83 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHub0xterror/cve-2026-8181

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

authentication-authorizationexploitationpenetration-testing+4
15 days ago
Burp-SessionAuthTool preview
Archived

Burp-SessionAuthTool

GitHubthomaspatzke/burp-sessionauthtool

Burp plugin which supports in finding privilege escalation vulnerabilities

authentication-authorizationpenetration-testingprivilege-escalation+3
424 years ago
CVE-2026-11961 preview

CVE-2026-11961

GitHubjohenlastgen-jlg/cve-2026-11961

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

exploitationinformation-gatheringmisconfiguration+5
128 days ago
CVE-2026-3584 preview

CVE-2026-3584

GitHubyucaerin/cve-2026-3584

CVE-2026-3584

exploitationinformation-gatheringpayload-development+5
5 months ago
CVE-2025-12539 preview

CVE-2025-12539

GitHubnxploited/cve-2025-12539

TNC Toolbox: Web Performance <= 1.4.2 - Unauthenticated Sensitive Information Exposure to Privilege Escalation/cPanel Account Takeover

educationexploitationinformation-gathering+6
79 months ago
Previous123456Next