Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
CVE-2021-21389 preview

CVE-2021-21389

GitHubhoangkien1020/cve-2021-21389

BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2.1 it's possible for a…

exploitationpenetration-testingprivilege-escalation+3
19
5 years ago
CVE-2026-11961 preview

CVE-2026-11961

GitHubjohenlastgen-jlg/cve-2026-11961

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

exploitationinformation-gatheringmisconfiguration+5
11 month ago
CVE-2025-14364 preview

CVE-2025-14364

GitHubnxploited/cve-2025-14364

Demo Importer Plus <= 2.0.8 - Missing Authorization to Authenticated (Subscriber+) Site Reset and Privilege Escalation

educationexploitationpenetration-testing+3
4 months ago
CVE-2026-56164-EXP preview

CVE-2026-56164-EXP

GitHubsentinel-aidefense/cve-2026-56164-exp

CVE-2026-56164 EOP Exploit

educationexploitationpenetration-testing+4
121 month ago
CVE-2026-23550 preview

CVE-2026-23550

GitHub1beelze/cve-2026-23550

Root-cause analysis, PoC, and detection guidance for CVE-2026-23550, a critical unauthenticated admin session takeover in the WordPress plugin…

educationexploitationpenetration-testing+3
2 months ago
CVE-2025-28062 preview

CVE-2025-28062

GitHubthvt0ne/cve-2025-28062

proof of concept

educationexploitationpenetration-testing+3
21 year ago
CVE-2025-66849 preview

CVE-2025-66849

GitHubwojtekchwala/cve-2025-66849

Ghost CMS Privilege Escalation PoC

exploitationpayload-developmentpenetration-testing+3
5 months ago
CVE-2025-25062 preview

CVE-2025-25062

GitHubrhburt/cve-2025-25062

Backdrop CMS 1.29.2 - Privilege Escalation via Stored XSS + CSRF

exploitationpenetration-testingprivilege-escalation+2
21 year ago
CVE-2021-31762 preview

CVE-2021-31762

GitHubmesh3l911/cve-2021-31762

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

command-and-controlexploitationpenetration-testing+3
15 years ago
CSRF-via-stored-XSS-for-PrivEsc preview

CSRF-via-stored-XSS-for-PrivEsc

GitHubmexeck88/csrf-via-stored-xss-for-privesc

Chamilo-LMS (v2.0) CVE-2025-26153

educationexploitationpayload-development+4
7 months ago
CVE-2025-55287-POC preview

CVE-2025-55287-POC

GitHubeternalvalhalla/cve-2025-55287-poc

Authenticated stored XSS priv esc PoC. Affects Genealogy versions prior to 4.4.0

exploitationpenetration-testingprivilege-escalation+3
11 year ago
CVE-2024-56116 preview

CVE-2024-56116

GitHubcompliancecontrol/cve-2024-56116

Documentation for CVE-2024-56116: a Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allowing remote attackers to create an…

authentication-authorizationexploitationprivilege-escalation+2
1 year ago
CVE-2024-57429 preview

CVE-2024-57429

GitHubahrixia/cve-2024-57429

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2025-25369 preview

CVE-2025-25369

GitHublkasjkasj/cve-2025-25369

Documented XSS exploit for ZKBio CVSecurity v.6.4.1 with WAF bypass, enabling privilege escalation from Template Editor to administrator via crafted…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2024-45264 preview

CVE-2024-45264

GitHubthehermione/cve-2024-45264

CVE-2024-45264

exploitationpenetration-testingprivilege-escalation+2
2 years ago
CVE-2021-32160 preview

CVE-2021-32160

GitHubmesh3l911/cve-2021-32160

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…

exploitationpayload-developmentpenetration-testing+3
5 years ago
CVE-2021-44217 preview

CVE-2021-44217

GitHubhyperkopite/cve-2021-44217

Proof-of-concept for a stored XSS vulnerability (CVE-2021-44217) in Ericsson CodeChecker's comments component, enabling cookie theft and sensitive…

data-exfiltrationinformation-gatheringprivilege-escalation+3
4 years ago
CVE-2024-57523. preview

CVE-2024-57523.

GitHubhackwidmaddy/cve-2024-57523.

CVE-2024-57523 - CSRF Vulnerability in Users.php - SourceCodester Packers and Movers Management System 1.0

exploitationinformation-gatheringpenetration-testing+3
1 year ago