Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
29 results
CVE-2026-13001 preview

CVE-2026-13001

GitHubshinthink/cve-2026-13001

Podlove Podcast Publisher Unauthenticated File Upload RCE via is_image() vs extract_file_extension() Mismatch | CVSS 9.8

educationexploitationpayload-development+3
1 month ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubaleewyy/cve-2025-49132

Minimal proof-of-concept exploit for CVE-2025-49132 in Pterodactyl panels; reads PHP files to extract database credentials and enable unauthorized…

database-securityexploitationinformation-gathering+3
2 months ago
CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction preview

CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction

GitHubdhananjayasj/cve-2024-1698-notificationx-wordpress-plugin-sql-injection-to-admin-credential-extraction

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

exploitationinformation-gatheringpassword-cracking+3
2 months ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
2 months ago
CVE-2026-8732 preview

CVE-2026-8732

GitHubzycoder0day/cve-2026-8732

Automated 8-phase exploit for CVE-2026-8732, an unauthenticated privilege escalation in WP Maps Pro ≤ 6.1.0. Uses multiprocessing and asyncio to scan…

exploitationpenetration-testingprivilege-escalation+3
32 months ago
htb-facts preview

htb-facts

GitHubmattiapertusati/htb-facts

HackTheBox — Facts (Easy/Linux) | CVE-2025-2304 + AWS S3 + SSH Key + Facter PrivEsc

cloud-securityctfeducation+7
4 months ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubmverschu/cve-2017-7921

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

authenticationexploitationinformation-gathering+5
6 months ago
cve-2024-56800-poc preview

cve-2024-56800-poc

GitHubcyhe50/cve-2024-56800-poc
crawlerexploitationpenetration-testing+3
9 months ago
grafanaExp preview

grafanaExp

GitHuba-d-team/grafanaexp

A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt…

encryption-decryption-toolsexploitationinformation-gathering+3
27010 months ago
CVE-2025-57819_FreePBX preview

CVE-2025-57819_FreePBX

GitHuborange0mint/cve-2025-57819_freepbx

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

educationexploitationinformation-gathering+4
211 months ago
CVE-2025-24799 preview

CVE-2025-24799

GitHubrosemary1337/cve-2025-24799

Exploits GLPI CVE-2025-24799 via unauthenticated time-based blind SQL injection to extract usernames and password hashes from glpi_users for…

exploitationpenetration-testingvulnerability-analysis+2
11 months ago
CVE-2024-7954 preview

CVE-2024-7954

GitHubr0otk3r/cve-2024-7954
educationexploitationpenetration-testing+3
1 year ago
CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053- preview

CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-

GitHubhf3cyber/cms-made-simple-2.2.9-unauthenticated-sql-injection-exploit-cve-2019-9053-

This exploit targets an unauthenticated SQL injection vulnerability in CMS Made Simple <= 2.2.9 (CVE-2019-9053). It uses a time-based blind SQL…

exploitationinformation-gatheringpassword-cracking+3
1 year ago
CVE-2024-42009 preview

CVE-2024-42009

GitHubbhanunamikaze/cve-2024-42009

This Proof of Concept (PoC) demonstrates an exploit for CVE-2024-42009, leveraging a cross-site scripting (XSS) vulnerability to extract emails from…

data-exfiltrationeducationexploitation+5
11 year ago
CVE-2024-44541 preview

CVE-2024-44541

GitHubpointedsec/cve-2024-44541

This repository details a SQL Injection vulnerability in Inventio Lite v4's, including exploitation steps and a Python script to automate the attack.…

educationexploitationpassword-cracking+3
1 year ago
CVE-2024-44000 preview

CVE-2024-44000

GitHubgeniuszly/cve-2024-44000

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies

exploitationinformation-gatheringpenetration-testing+2
51 year ago
CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit preview

CVE-2021-36396-Moodle-Time-Based-SQLi-Exploit

GitHubt0x1cx/cve-2021-36396-moodle-time-based-sqli-exploit

This script demonstrates a time-based blind SQL injection on Moodle platforms, exploiting response delays to extract data.

database-securityeducationexploitation+3
222 years ago
wp-mail-masta-exploit preview

wp-mail-masta-exploit

GitHubhackhoven/wp-mail-masta-exploit

Exploit script for WordPress Plugin Mail Masta 1.0 - CVE-2016-10956

educationexploitationpenetration-testing+2
22 years ago
Previous12Next