Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
116 results
CVE-2017-12635 preview

CVE-2017-12635

GitHubassalielmehdi/cve-2017-12635

Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation

database-securityeducationexploitation+4
10
6 years ago
CVE-2025-49706-SharePoint-Spoofing-Vulnerability-Under-Active-Exploitation preview

CVE-2025-49706-SharePoint-Spoofing-Vulnerability-Under-Active-Exploitation

GitHubadityabhatt3010/cve-2025-49706-sharepoint-spoofing-vulnerability-under-active-exploitation

A deep dive into CVE-2025-49706 — the SharePoint spoofing flaw now exploited in the wild for stealthy web shell deployment and privilege escalation.

educationexploitationincident-response+6
171 year ago
CVE-2022-21661 preview

CVE-2022-21661

GitHubguestzz/cve-2022-21661

Exploit for CVE-2022-21661 targeting Elementor WordPress plugin, enabling SQL injection-based privilege escalation and data extraction.

exploitationpenetration-testingvulnerability-analysis+2
74 years ago
CVE-2025-11749 preview

CVE-2025-11749

GitHubnxploited/cve-2025-11749

AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation

exploitationinformation-gatheringpenetration-testing+4
811 months ago
CVE-2026-81294 preview

CVE-2026-81294

GitHubabraxas/cve-2026-81294

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified…

authenticationexploitationlabs-practice+5
35 days ago
CVE-2026-12793 preview

CVE-2026-12793

GitHubabraxas/cve-2026-12793

Proof-of-concept exploit for CVE-2026-12793, an unauthenticated privilege escalation in WordPress JetFormBuilder up to 3.6.2 that creates…

educationexploitationlabs-practice+5
17 days ago
CVE-2026-13355 preview

CVE-2026-13355

GitHubmurrez/cve-2026-13355

Python PoC scanner and exploit for CVE-2026-13355, an unauthenticated admin privilege escalation in Meta Box AIO WordPress plugins, with FOFA mass…

exploitationinformation-gatheringpenetration-testing+6
14 days ago
CVE-2026-12793 preview

CVE-2026-12793

GitHubrootxn/cve-2026-12793

Python PoC for CVE-2026-12793 in JetFormBuilder <= 3.6.2: unauthenticated privilege escalation leading to plugin upload and remote code execution,…

exploitationpayload-generationpenetration-testing+5
19 days ago
CVE-2026-60137-and-CVE-2026-63030 preview

CVE-2026-60137-and-CVE-2026-63030

GitHubivanesk315/cve-2026-60137-and-cve-2026-63030

Docker-based WordPress lab reproducing CVE-2026-60137 and CVE-2026-63030 pre-auth RCE, with a Python PoC exploit for SQLi, privilege escalation, and…

educationexploitationlabs-practice+6
26 days ago
CVE-2026-80467 preview

CVE-2026-80467

GitHubsangsenimanwartefak/cve-2026-80467

Python detection tool that fingerprints ACF Extended forms on WordPress and checks for publicly exposed role fields indicating CVE-2026-80467…

educationpenetration-testingprivilege-escalation+4
18 days ago
CVE-2026-5118 preview

CVE-2026-5118

GitHubsangsenimanwartefak/cve-2026-5118

Detection tooling for CVE-2026-5118, an unauthenticated privilege escalation in Divi Form Builder <= 5.1.2, identifying affected WordPress…

defensive-toolseducationinformation-gathering+5
13 days ago
CVE-2026-9055 preview

CVE-2026-9055

GitHubexecution-py/cve-2026-9055

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

configuration-auditingcurated-resourceseducation+3
1 month ago
CVE-2022-24637 preview

CVE-2022-24637

GitHubprinceaikinsbaidoo/cve-2022-24637

Defensive notes on CVE-2022-24637 in Open Web Analytics before 1.7.4, covering unauthenticated information disclosure, privilege escalation impact,…

defensive-toolseducationinformation-gathering+3
26 days ago
cve-2021-43858 preview

cve-2021-43858

GitHub0rx1/cve-2021-43858

Exploit for MinIO privilege escalation vulnerability CVE-2021-43858, allowing unauthorized access to cloud storage. Written in Go, run with 'go run…

cloud-securityexploitationpenetration-testing+2
34 years ago
CVE-2026-4282-Scanner preview

CVE-2026-4282-Scanner

GitHubhex0user/cve-2026-4282-scanner

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

authenticationdefensive-toolsinformation-gathering+4
31 month ago
CVE-2026-0920- preview

CVE-2026-0920-

GitHubnxploited/cve-2026-0920-

LA-Studio Element Kit for Elementor <= 1.5.6.3 - Unauthenticated Privilege Escalation via Backdoor to Administrative User Creation via lakit_bkrole…

educationexploitationprivilege-escalation+3
35 months ago
CVE-2026-5118 preview

CVE-2026-5118

GitHub1beelze/cve-2026-5118

Automated exploit and mass scanner for CVE-2026-5118, an unauthenticated privilege escalation in WordPress Divi Form Builder <=5.1.2, enabling admin…

authenticationexploitationpayload-generation+6
2 months ago
CVE-2026-40487 preview

CVE-2026-40487

GitHubastaruf/cve-2026-40487

Proof-of-concept exploit for CVE-2026-40487, demonstrating arbitrary file upload via MIME spoofing leading to stored XSS and account takeover in…

exploitationpayload-developmentpenetration-testing+3
35 months ago
Previous1234567Next