Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
113 results
wp2shell-Hestia-Scanner preview

wp2shell-Hestia-Scanner

GitHubbytespulse-oe/wp2shell-hestia-scanner

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

ai-securitydefensive-toolsforensics+7
2
1 month ago
CVE-2023-5561-PoC preview

CVE-2023-5561-PoC

GitHubpog007/cve-2023-5561-poc

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

exploitationinformation-gatheringreconnaissance+2
42 years ago
CVE-2022-40348_Intern-Record-System-Cross-site-Scripting-V1.0-Vulnerability-Unauthenticated preview

CVE-2022-40348_Intern-Record-System-Cross-site-Scripting-V1.0-Vulnerability-Unauthenticated

GitHubh4md153v63n/cve-2022-40348_intern-record-system-cross-site-scripting-v1.0-vulnerability-unauthenticated

CVE-2022-40348: Intern Record System - 'name' and 'email' Cross-site Scripting (Unauthenticated)

exploitationpenetration-testingvulnerability-analysis+2
32 years ago
CVE-2024-2876 preview

CVE-2024-2876

GitHubaerchy/cve-2024-2876

Proof-of-concept exploit for CVE-2024-2876, a critical SQL injection in Email Subscribers by Icegram Express WordPress plugin, allowing…

exploitationpenetration-testingvulnerability-analysis+2
21 year ago
CVE-2026-31283 preview

CVE-2026-31283

GitHubsaykino/cve-2026-31283

Documentation of CVE-2026-31283: an email bombing vulnerability in Totara LMS's forgot password API due to missing rate limiting, allowing…

api-securityeducationemail-security+3
5 months ago
CVE-2026-37073 preview

CVE-2026-37073

GitHubjfs-jfs/cve-2026-37073

Proof-of-concept exploit for CVE-2026-37073: unauthenticated SMTP email abuse via incorrect access control in Veno File Manager 4.4.9.

exploitationmisconfigurationpenetration-testing+2
3 months ago
Reflected-XSS-in-Vvveb-CMS-v1.0.7.2 preview

Reflected-XSS-in-Vvveb-CMS-v1.0.7.2

GitHubhelloandrewpaul/reflected-xss-in-vvveb-cms-v1.0.7.2

CVE-2025-9728: Reflected XSS in Login Form (Email & Password Fields) Vvveb CMS v1.0.7.2

educationpapers-researchphishing+3
1 year ago
CVE-2025-66956 preview

CVE-2025-66956

GitHubthewoodenbench/cve-2025-66956

Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute…

exploitationinformation-gatheringreconnaissance+2
7 months ago
CVE-2025-54321 preview

CVE-2025-54321

GitHubsaykino/cve-2025-54321

Documentation of CVE-2025-54321: an email bombing vulnerability in Ascertia SigningHub's reset password function due to missing rate limiting,…

curated-resourceseducationmisconfiguration+2
10 months ago
CVE-2021-41074 preview

CVE-2021-41074

GitHubdillonkirsch/cve-2021-41074

Proof-of-concept CSRF exploit targeting Qloapps HotelCommerce 1.5.1 that allows unauthorized admin email changes via crafted HTML documents.

exploitationpenetration-testingvulnerability-analysis+2
5 years ago
CVE-2024-4295-Poc preview

CVE-2024-4295-Poc

GitHubcve-2024/cve-2024-4295-poc

Proof-of-concept exploit for CVE-2024-4295, an unauthenticated SQL injection in Email Subscribers by Icegram Express <= 5.7.20 via the hash parameter.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2023-49546 preview

CVE-2023-49546

GitHubgeraldoalcantara/cve-2023-49546

Customer Support System 1.0 - SQL Injection Vulnerability in the "email" Parameter During "save_staff" Operation

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2025-25965 preview

CVE-2025-25965

GitHubsudo-sakib/cve-2025-25965

CVE-2025-25965 is a newly discovered CSRF vulnerability in the Phpgurukul Online Banquet Booking System v1.2, allowing remote attackers to change a…

educationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2024-25412 preview

CVE-2024-25412

GitHubparagbagul111/cve-2024-25412

A cross-site scripting (XSS) vulnerability in Flatpress v1.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2024-54951 preview

CVE-2024-54951

GitHuballevon412/cve-2024-54951

I contacted the monica development team via email on 11/20/2024. I also contacted them via LinkedIn, and other platforms in the weeks that followed.…

exploitationpenetration-testingvulnerability-analysis+2
1 year ago
CVE-2023-48104 preview

CVE-2023-48104

GitHube1tex/cve-2023-48104

Proof-of-concept exploit demonstrating HTML injection in SOGo Web Client before 5.9.1, enabling phishing attacks via malicious forms in email bodies.

exploitationphishingvulnerability-analysis+2
2 years ago
CVE-2024-24139 preview

CVE-2024-24139

GitHubburaksevben/cve-2024-24139

Proof-of-concept exploit demonstrating SQL injection in a login system with email verification, targeting CVE-2024-24139 for security testing and…

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2024-0235-PoC preview

CVE-2024-0235-PoC

GitHubnxploited/cve-2024-0235-poc

The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing…

exploitationinformation-gatheringpenetration-testing+2
1 year ago
Previous1234567Next