Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
95 results
wpUsersScan preview

wpUsersScan

GitHubteambugsbunny/wpusersscan

Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -

information-gatheringosintreconnaissance+2
9 years ago
CVE-2025-2539 preview

CVE-2025-2539

GitHubyucaerin/cve-2025-2539

CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read

exploitationinformation-gatheringpassword-attacks+3
1 year ago
woocommerce_scanner preview

woocommerce_scanner

GitHubtdawg506/woocommerce_scanner

A Python script designed to scan a list of WordPress sites to identify those with WooCommerce installed and check if they are vulnerable to…

information-gatheringreconnaissancevulnerability-scanners+1
0 years ago
CVE-2024-5522-PoC preview

CVE-2024-5522-PoC

GitHubkryptonproject/cve-2024-5522-poc

Unauthenticated SQL injection exploit for CVE-2024-5522 targeting WordPress HTML5 Video Player plugin. Includes automated target discovery via search…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
TryHack3M-Bricks-Heist preview

TryHack3M-Bricks-Heist

GitHubh0w1tzxr/tryhack3m-bricks-heist

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

ctfeducationexploitation+6
8 months ago
CVE-2025-6758 preview

CVE-2025-6758

GitHubnxploited/cve-2025-6758

Real Spaces - WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator

exploitationpenetration-testingprivilege-escalation+3
10 months ago
CVE-2024-34444-Exploit-Poc preview

CVE-2024-34444-Exploit-Poc

GitHubdzmind2312/cve-2024-34444-exploit-poc

Multi-threaded mass scanner for CVE-2024-34444 (Missing Authorization) in Slider Revolution WordPress plugin. Automates nonce extraction, version…

exploitationinformation-gatheringpenetration-testing+3
7 months ago
CVE-2017-5487 preview

CVE-2017-5487

GitHubdream434/cve-2017-5487

Exploit for CVE-2017-5487 to enumerate WordPress user accounts via the REST API, extracting sensitive information from vulnerable 4.7 installations.

information-gatheringosintreconnaissance+2
1 year ago
CVE-2022-3590-WordPress-Vulnerability-Scanner preview

CVE-2022-3590-WordPress-Vulnerability-Scanner

GitHubhuynhvanphuc/cve-2022-3590-wordpress-vulnerability-scanner

Python script to detect unauthenticated blind SSRF (CVE-2022-3590) in WordPress pingback feature. Supports single URL and batch scanning with…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubsupraaa-1337/cve-2025-3102

Detects the version of the SureTriggers WordPress plugin from exposed asset URLs and compares it to determine if it's vulnerable (<= 1.0.78).

exploitationinformation-gatheringreconnaissance+2
1 year ago
CVE-2025-6082 preview
Archived

CVE-2025-6082

GitHubbytereaper77/cve-2025-6082

Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)

exploitationinformation-gatheringpenetration-testing+3
11 year ago
PenBox preview

PenBox

GitHubx3omdax/penbox

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

exploitationfuzzinginformation-gathering+8
5369 years ago
CVE-2024-3495-Poc preview

CVE-2024-3495-Poc

GitHubtruonghuuphuc/cve-2024-3495-poc

CVE-2024-3495 Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection

exploitationinformation-gatheringpenetration-testing+3
92 years ago
xss2shell preview

xss2shell

GitHub0xlipon/xss2shell

🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

defensive-toolspayload-generationpenetration-testing+6
31 month ago
CVE-2026-8732-PoC preview

CVE-2026-8732-PoC

GitHubfientix/cve-2026-8732-poc

CVE-2026-8732 | WP Maps Pro <= 6.1.0 Unauth Admin Creation

exploitationpenetration-testingreconnaissance+3
8 days ago
CVE-2021-38314 preview

CVE-2021-38314

GitHubakhilkoradiya/cve-2021-38314

CVE-2021-38314 Python Exploit

exploitationinformation-gatheringpenetration-testing+3
44 years ago
CVE-2026-13714 preview

CVE-2026-13714

GitHubnxploited/cve-2026-13714

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

exploitationpenetration-testingreconnaissance+2
1 month ago
Jquery-File-Tree-1.6.6-Path-Traversal preview

Jquery-File-Tree-1.6.6-Path-Traversal

GitHubnickguitar/jquery-file-tree-1.6.6-path-traversal

Jquery File Tree 1.6.6 Path Traversal exploit (CVE-2017-1000170)

information-gatheringpenetration-testingreconnaissance+2
45 years ago
Previous123456Next