Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1576 results
XSS2Shell preview

XSS2Shell

GitHubg0d150ne/xss2shell

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

command-and-controlexploitationinformation-gathering+6
10 days ago
CVE-2017-7921-EXP preview

CVE-2017-7921-EXP

GitHubblacksheepstudio/cve-2017-7921-exp

Python exploit for CVE-2017-7921 in Hikvision IP cameras, performing unauthenticated user enumeration, snapshot capture, and configuration file…

authenticationexploitationinformation-gathering+3
3 years ago
CVE-2026-8794 preview

CVE-2026-8794

GitHubh4zaz/cve-2026-8794

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

authenticationinformation-gatheringpenetration-testing+4
5 days ago
CVE-2023-22047---Oracle-PeopleSoft-LFI preview

CVE-2023-22047---Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047---oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

exploitationinformation-gatheringpenetration-testing+3
5 days ago
One-Liner-Collections preview

One-Liner-Collections

GitHubcybertix-pvt-ltd/one-liner-collections

This Repositories contains list of One Liners with Descriptions and Installation requirements

curated-resourcesinformation-gatheringpenetration-testing+5
5091 year ago
CVE-2026-56292-AcyMailing-SQLi preview

CVE-2026-56292-AcyMailing-SQLi

GitHubnullwhisper/cve-2026-56292-acymailing-sqli

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

exploitationinformation-gatheringpenetration-testing+3
7 days ago
CVE-2026-19478-PoC preview

CVE-2026-19478-PoC

GitHubdavkharrr/cve-2026-19478-poc

Proof-of-concept exploit for unauthenticated remote code injection in GitLab's GraphQL API, using crafted queries to modify or delete public projects…

api-securityexploitationinformation-gathering+3
13 days ago
WordpressPingbackPortScanner preview
Archived

WordpressPingbackPortScanner

GitHubfirefart/wordpresspingbackportscanner

WordpressPingbackPortScanner

information-gatheringnetwork-mappingpenetration-testing+3
1657 years ago
HQLmap preview
Archived

HQLmap

GitHubpaulsec/hqlmap

(Deprecated) HQLmap, Automatic tool to exploit HQL injections

database-securityinformation-gatheringpenetration-testing+2
2286 years ago
CVE-2023-31445-Unprivileged-Information-Disclosure preview
Archived

CVE-2023-31445-Unprivileged-Information-Disclosure

GitHubdodge-mptc/cve-2023-31445-unprivileged-information-disclosure

Repository contains description for CVE-2023-31445

information-gatheringosintpenetration-testing+3
13 years ago
CVE-2024-55099-Online-Nurse-Hiring-System-v1.0-SQL-Injection-Vulnerability- preview
Archived

CVE-2024-55099-Online-Nurse-Hiring-System-v1.0-SQL-Injection-Vulnerability-

GitHubugurkarakoc1/cve-2024-55099-online-nurse-hiring-system-v1.0-sql-injection-vulnerability-
exploitationinformation-gatheringpenetration-testing+2
11 year ago
cve-2022-1609-exploit preview
Archived

cve-2022-1609-exploit

GitHubitworksig/cve-2022-1609-exploit

Exploit for CVE-2022-1609 WordPress Weblizar Backdoor.

exploitationinformation-gatheringpenetration-testing+2
13 years ago
cve-2025-6907 preview
Archived

cve-2025-6907

GitHubbytereaper77/cve-2025-6907

a standalone C-based SQL Injection exploit targeting the CVE‑2025‑6907 vulnerability in the CODE_PROJECT service.

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2025-6082 preview
Archived

CVE-2025-6082

GitHubbytereaper77/cve-2025-6082

Proof‑of‑Concept exploits the Full Path Disclosure bug in the “Birth Chart Compatibility” WordPress plugin (<=v2.0)

exploitationinformation-gatheringpenetration-testing+3
11 year ago
CVE-2025-5964- preview
Archived

CVE-2025-5964-

GitHubbytereaper77/cve-2025-5964-

C PoC language for emulating path traversal vulnerability (CVE-2025-5964) in M-Files25.6.14925.0

exploitationinformation-gatheringpenetration-testing+3
21 year ago
CVE-2025-11077 preview
Archived

CVE-2025-11077

GitHubbytereaper77/cve-2025-11077

Exploit blind SQL Injection in (Online Learning Management System)

exploitationinformation-gatheringpenetration-testing+2
210 months ago
CVE-2021-32789 preview
Archived

CVE-2021-32789

GitHuband0x00/cve-2021-32789

💣 Wordpress WooCommerce users dump exploit.

exploitationinformation-gatheringpenetration-testing+2
13 years ago
Serein preview
Archived

Serein

GitHubw01fh4cker/serein

【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day…

crawlerexploitationinformation-gathering+6
1.3k3 years ago
Previous1…868788Next