Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
89 results
CVE-2026-13001 preview

CVE-2026-13001

GitHubbyt3l0rd/cve-2026-13001

Exploit for CVE-2026-13001, an unauthenticated arbitrary file upload in Podlove Podcast Publisher WordPress plugin, enabling remote code execution…

exploitationpayload-developmentpenetration-testing+4
1 day ago
yLog4j preview

yLog4j

GitHuby-security/ylog4j

PortSwigger Burp Plugin for the Log4j (CVE-2021-44228)

api-security-testingexploitationpenetration-testing+2
24 years ago
CVE-2026-0740 preview

CVE-2026-0740

GitHubxshadow-here/cve-2026-0740

Automated mass exploiter for CVE-2026-0740, an unauthenticated arbitrary file upload in Ninja Forms File Uploads plugin, enabling remote code…

exploitationpayload-generationpenetration-testing+3
34 months ago
Mass-CVE-2026-23550-Exploit preview

Mass-CVE-2026-23550-Exploit

GitHubdzmind2312/mass-cve-2026-23550-exploit

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

exploitationinformation-gatheringpenetration-testing+3
26 months ago
CYBERDUDEBIVASH-Modular-DS-CVE-2026-23550-Detector preview

CYBERDUDEBIVASH-Modular-DS-CVE-2026-23550-Detector

GitHubcyberdudebivash/cyberdudebivash-modular-ds-cve-2026-23550-detector

authorized CYBERDUDEBIVASH ECOSYSTEM tool for detecting CVE-2026-23550 in WordPress Modular DS plugin

information-gatheringthreat-intelligencevulnerability-scanners+1
17 months ago
Ashwesker-CVE-2026-21962 preview

Ashwesker-CVE-2026-21962

GitHubboroeurnprach/ashwesker-cve-2026-21962

Exploit PoC and Nuclei template for CVE-2026-21962, a critical unauthenticated remote code execution in Oracle HTTP Server and WebLogic Proxy…

exploitationpayload-developmentpenetration-testing+3
57 months ago
CVE-2026-3228 preview

CVE-2026-3228

GitHubnull200ok/cve-2026-3228

Scans and exploits CVE-2026-3228, a stored XSS in NextScripts WordPress plugin, with pre-auth detection, authenticated checks, and payload injection…

exploitationpayload-developmentpenetration-testing+3
25 months ago
Exploit-CVE-2026-1357 preview

Exploit-CVE-2026-1357

GitHubitsismarcos/exploit-cve-2026-1357

Exploit for CVE-2026-1357 in WordPress WPVivid plugin, enabling remote code execution via crafted AES-encrypted payloads and directory traversal to…

exploitationpayload-developmentpenetration-testing+2
16 months ago
CVE-2026-1306 preview

CVE-2026-1306

GitHubmurrez/cve-2026-1306

Multi-target PoC runner for CVE-2026-1306 in WordPress midi-Synth plugin: fetches nonce, sends export AJAX request to upload files, and verifies…

exploitationpayload-generationpenetration-testing+3
4 months ago
CVE-2026-11961 preview

CVE-2026-11961

GitHubjohenlastgen-jlg/cve-2026-11961

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

exploitationinformation-gatheringmisconfiguration+5
128 days ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubjenderal92/cve-2026-49049

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed…

exploitationpayload-generationpenetration-testing+4
11 month ago
super-secret-finder preview

super-secret-finder

GitHubrandomrobbiebf/super-secret-finder

Burp Plugin for Secret Matching

api-securityinformation-gatheringpenetration-testing+3
63 years ago
AMFDSer-ngng preview

AMFDSer-ngng

GitHubnccgroup/amfdser-ngng

A Burp Extender plugin, that will take deserialized AMF objects and encode them in XML using the Xtream library

api-security-testingdynamic-analysis-sandboxingpenetration-testing+3
2711 years ago
trivy-plugin-kubectl preview

trivy-plugin-kubectl

GitHubaquasecurity/trivy-plugin-kubectl

A Trivy plugin that scans the images of a kubernetes resource

cloud-securitycontainer-securitydevsecops+1
252 years ago
CVE-2026-3584 preview

CVE-2026-3584

GitHubyucaerin/cve-2026-3584

CVE-2026-3584

exploitationinformation-gatheringpayload-development+5
5 months ago
trivy-plugin-aqua preview

trivy-plugin-aqua

GitHubaquasecurity/trivy-plugin-aqua

Plugin for integrating Trivy with Aqua Security platform to scan IaC, pipelines, and dependencies for vulnerabilities and misconfigurations.

cloud-infrastructure-securityconfiguration-auditingdevsecops+2
1411 days ago
CVE-2026-4106 preview

CVE-2026-4106

GitHubef3tr/cve-2026-4106

WordPress HTMega Unauthenticated PII Disclosure Exploit (CVE-2026-4106)

educationexploitationinformation-gathering+6
14 months ago
CVE-2026-2942 preview

CVE-2026-2942

GitHubxxconi/cve-2026-2942

Automated scanner for unauthenticated arbitrary file upload and remote code execution in ProSolution WP Client (CVE-2026-2942). Supports…

educationexploitationpayload-development+3
3 months ago
Previous12345Next