Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
62 results
ettercap preview

ettercap

GitHubettercap/ettercap

Ettercap Project

dns-analysisexploitationinformation-gathering+6
2.8k0 days ago
wpprobe preview

wpprobe

GitHubchocapikk/wpprobe

A fast WordPress plugin enumeration tool

api-security-testingcrawlerexploitation+5
9419 days ago
cantina preview
Archived

cantina

GitLabwattocyber/cantina

OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and…

information-gatheringnetwork-mappingpenetration-testing+2
14 days ago
wpscan preview

wpscan

GitHubwpscanteam/wpscan

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

crawlerdynamic-code-analysisinformation-gathering+7
9.8k15 days ago
CVE-2026-64640 preview

CVE-2026-64640

GitHuboscerd/cve-2026-64640

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

api-securitycloud-securitydata-exfiltration+5
28 days ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubhudzaifaharrantisi/cve-2026-8181

CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan…

authenticationexploitationinformation-gathering+4
1 month ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubexdev994/cve-2026-49049

CVE-2026-49049 Helix3 (JoomShaper) Joomla Unauthenticated AJAX RCE Scanner

educationexploitationpayload-generation+4
1 month ago
CVE-2021-43798 preview

CVE-2021-43798

GitHublim-ahmin/cve-2021-43798

Proof-of-concept exploit for Grafana path traversal vulnerability (CVE-2021-43798) allowing unauthorized file read via directory traversal in plugin…

exploitationinformation-gatheringpenetration-testing+3
1 month ago
CVE-2026-5524-PoC preview

CVE-2026-5524-PoC

GitHubcaterscam/cve-2026-5524-poc

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

command-and-controlexploitationinformation-gathering+8
12 months ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubjenderal92/cve-2026-8206

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

educationexploitationinformation-gathering+5
33 months ago
CVE-2026-8732-POC preview

CVE-2026-8732-POC

GitHubp3nt3st3r-star/cve-2026-8732-poc

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

exploitationinformation-gatheringpenetration-testing+4
83 months ago
CVE-2024-8856 preview

CVE-2024-8856

GitHubjenderal92/cve-2024-8856

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

information-gatheringreconnaissancevulnerability-analysis+2
23 months ago
nox-framework preview

nox-framework

GitHubnox-project/nox-framework

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

crawlerdata-exfiltrationdigital-forensics+8
3244 months ago
CVE-2026-34160 preview

CVE-2026-34160

GitHubromain-deperne/cve-2026-34160

Unauthenticated SSRF in Chamilo LMS via PENS plugin (pens.php) — CVSS 7.5

exploitationpenetration-testingreconnaissance+3
4 months ago
CVE-2025-15521 preview

CVE-2025-15521

GitHubnxploited/cve-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

authenticationexploitationinformation-gathering+5
14 months ago
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
4 months ago
CVE-2026-3584 preview

CVE-2026-3584

GitHubyucaerin/cve-2026-3584

CVE-2026-3584

exploitationinformation-gatheringpayload-development+5
5 months ago
Previous1234Next