Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
833 results
CVE-2025-2563 preview

CVE-2025-2563

GitHubnxploited/cve-2025-2563

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

educationexploitationpayload-development+5
4 months ago
CVE-2025-14364 preview

CVE-2025-14364

GitHubnxploited/cve-2025-14364

Demo Importer Plus <= 2.0.8 - Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation

educationexploitationpenetration-testing+3
4 months ago
CVE-2026-1492 preview

CVE-2026-1492

GitHubnxploited/cve-2026-1492

User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

educationexploitationpenetration-testing+4
4 months ago
NextJS-RCE-Root-Takeover preview

NextJS-RCE-Root-Takeover

GitHubimad457/nextjs-rce-root-takeover

Pentest Report: Next.js 16.0.6 RCE (CVE-2025-66478)

educationexploitationlabs-practice+4
26 months ago
HTB-Pterodactyl-Writeup preview

HTB-Pterodactyl-Writeup

GitHubv0idw1re/htb-pterodactyl-writeup

HackTheBox — Pterodactyl (Medium/Linux) walkthrough. CVE-2025-49132 LFI → pearcmd RCE → bcrypt crack → SSH. Privesc via CVE-2025-6018 (PAM…

ctfeducationexploitation+9
4 months ago
Optimum preview

Optimum

GitHubr3fr4kt/optimum

Writeup of the Optimum machine from Hack The Box. This walkthrough covers the exploitation of Rejetto HttpFileServer 2.3 (CVE-2014-6287) to gain…

educationexploitationinformation-gathering+7
5 months ago
CVE-2026-6356 preview

CVE-2026-6356

GitHubpenguinsecq/cve-2026-6356

Exploit PoC of CVE-2026-6356

educationexploitationpenetration-testing+3
4 months ago
Explosive-As-Hell-MCS-Qualifer-Web-500 preview

Explosive-As-Hell-MCS-Qualifer-Web-500

GitHubabdullahmaqbool22/explosive-as-hell-mcs-qualifer-web-500

[First-Blood-XO] React Server Component endpoint vulnerable to CVE-2025-55182 (RCE) → enumerated SUID binaries → /usr/bin/perl had SUID set → used…

binary-exploitationctfeducation+7
4 months ago
Web-Penetration-Test preview

Web-Penetration-Test

GitHubsalimelh94/web-penetration-test

Exploiting WordPress vulnerabilities (CVE-2025-34077), authentication bypass via cookie injection, and privilege escalation to root. Part of my…

authenticationctfeducation+6
4 months ago
HTB-Pterodactyl-Writeup preview

HTB-Pterodactyl-Writeup

GitHubkarimelsheikh1/htb-pterodactyl-writeup

HTB Season 10 - Pterodactyl machine writeup. Medium Linux box covering CVE-2025-49132 (Pterodactyl Panel RCE) and CVE-2025-6018/6019 (udisks2…

ctfeducationexploitation+7
4 months ago
CVE-2025-4322 preview

CVE-2025-4322

GitHubyucaerin/cve-2025-4322

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

authenticationeducationexploitation+5
11 year ago
SimpleCTF-THM-Walkthrough preview

SimpleCTF-THM-Walkthrough

GitHubpaulameg/simplectf-thm-walkthrough

First CTF successfully completed! This repo documents my walkthrough of TryHackMe's Simple CTF. It covers network reconnaissance (Nmap), web…

ctfeducationpassword-cracking+5
13 months ago
CVE-2025-4631 preview

CVE-2025-4631

GitHubnxploited/cve-2025-4631

Profitori 2.0.6.0 - 2.1.1.3 - Missing Authorization to Unauthenticated Privilege Escalation

ctfeducationexploitation+4
11 year ago
pentesting-obioba preview

pentesting-obioba

GitHubfacundomfernandez/pentesting-obioba

Pentesting caja negra: Shellshock (CVE-2014-6271) + Log4Shell (CVE-2021-44228). Escalada a root. Informe ejecutivo y técnico

educationexploitationexploit-frameworks+7
3 months ago
CVE-2024-54363-Exploit preview

CVE-2024-54363-Exploit

GitHubnxploited/cve-2024-54363-exploit

Incorrect Privilege Assignment vulnerability in nssTheme Wp NssUser Register allows Privilege Escalation.This issue affects Wp NssUser Register: from…

educationexploitationpenetration-testing+3
11 year ago
CSRF-via-stored-XSS-for-PrivEsc preview

CSRF-via-stored-XSS-for-PrivEsc

GitHubmexeck88/csrf-via-stored-xss-for-privesc

Chamilo-LMS (v2.0) CVE-2025-26153

educationexploitationpayload-development+4
6 months ago
Audit-BlackBox-Web-to-Root preview

Audit-BlackBox-Web-to-Root

GitHubfbm31/audit-blackbox-web-to-root

Audit de sécurité Black Box d'un serveur Drupal 7. Démonstration d'une Kill Chain complète : Injection SQL (CVE-2014-3704) ➔ RCE ➔ Reverse Shell ➔…

command-and-controleducationexploitation+8
7 months ago
Vulnerable-Lab-Exploitation preview

Vulnerable-Lab-Exploitation

GitHubhackhermind-pixel/vulnerable-lab-exploitation

A hands-on project demonstrating the setup of virtual security lab, network reconnaissance, and exploitation of CVE-2012-1823.

educationexploitationinformation-gathering+8
17 months ago
Previous1…44454647Next