Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
CVE-2026-43914-PoC preview

CVE-2026-43914-PoC

GitHubboreas37/cve-2026-43914-poc

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

exploitationpassword-attackspenetration-testing+2
2
1 day ago
CVE-2026-71205-PoC preview

CVE-2026-71205-PoC

GitHubnel-droid/cve-2026-71205-poc

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

authenticationexploitationpassword-attacks+4
9 days ago
wp2shell preview

wp2shell

GitHub0xwhoknows/wp2shell

Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes,…

exploitationpassword-attackspenetration-testing+4
11 month ago
CVE-2026-63030 preview

CVE-2026-63030

GitHub4minx/cve-2026-63030

CVE-2026-63030 (wp2shell) POC.

exploitationpassword-attackspenetration-testing+2
91 month ago
CVE-2025-44203 preview

CVE-2025-44203

GitHubivant7d3/cve-2025-44203

Exploit for CVE-2025-44203 targeting a race condition in HotelDruid 3.0.0/3.0.7 that leaks admin credentials and causes denial of service. Includes a…

exploitationinformation-gatheringpassword-cracking+2
1 month ago
CVE-2026-11387 preview

CVE-2026-11387

GitHub1beelze/cve-2026-11387

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

authenticationexploitationpassword-attacks+4
11 month ago
CVE-2026-12416-CVE-2026-12417 preview

CVE-2026-12416-CVE-2026-12417

GitHubnxploited/cve-2026-12416-cve-2026-12417

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

authenticationexploitationpassword-attacks+3
22 months ago
By-Poloss..-..CVE-2026-11551-PoC preview

By-Poloss..-..CVE-2026-11551-PoC

GitHubpolosss/by-poloss..-..cve-2026-11551-poc

Unauthenticated Privilege Escalation via Account Takeover

exploitationpassword-attackspenetration-testing+3
12 months ago
TomcatScanPro preview

TomcatScanPro

GitHublizhianyuguangming/tomcatscanpro

tomcat自动化漏洞扫描利用工具,支持批量弱口令检测、后台部署war包getshell、CVE-2017-12615 文件上传、CVE-2020-1938/CNVD-2020-10487 文件包含

exploitationpassword-attackspayload-generation+3
2942 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
2 months ago
Zimbra-Valid-Login-Checker preview

Zimbra-Valid-Login-Checker

GitHubjenderal92/zimbra-valid-login-checker

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

authenticationpassword-attackspenetration-testing+2
12 months ago
CVE-2025-25198-PoC preview

CVE-2025-25198-PoC

GitHubgroppoxx/cve-2025-25198-poc

PoC for CVE-2025-25198: automated Host header poisoning test for Mailcow - HTTPS listener, automatic cookie/CSRF handling, captures first reset link.

exploitationpassword-attackspenetration-testing+3
203 months ago
CVE-2025-58434-PoC preview

CVE-2025-58434-PoC

GitHubvincent-vbg/cve-2025-58434-poc

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

authenticationexploitationpassword-attacks+3
3 months ago
CVE-2025-15030 preview

CVE-2025-15030

GitHubnxploited/cve-2025-15030

User Profile Builder < 3.15.2 - Unauthenticated Arbitrary Password Reset

exploitationpassword-attackspenetration-testing+3
14 months ago
CVE-2025-10658 preview

CVE-2025-10658

GitHubjfriedli/cve-2025-10658

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

authenticationexploitationpassword-attacks+3
15 months ago
CVE-2025-60787 preview

CVE-2025-60787

GitHubagent-skywalker/cve-2025-60787

Proof-of-concept exploit for CVE-2025-60787, an OS command injection in motionEye v0.43.1b4, enabling remote code execution via crafted…

command-and-controlexploitationpassword-attacks+5
5 months ago
RocketChat-NoSQLi-Chain-CVE-2021-22911 preview

RocketChat-NoSQLi-Chain-CVE-2021-22911

GitHubtenebrae93/rocketchat-nosqli-chain-cve-2021-22911

Automated exploit for Rocket.Chat NoSQL injection (CVE-2021-22911) that leaks password reset tokens and performs unauthenticated account takeover.

exploitationpassword-attackspenetration-testing+3
6 months ago
CVE-2025-70829 preview

CVE-2025-70829

GitHubxiaoxiaoranxxx/cve-2025-70829

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

authenticationdatabase-securityexploitation+3
46 months ago
Previous123456Next