Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1166 results
cve-2026-15748 preview

cve-2026-15748

GitHubyora1928/cve-2026-15748

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

crawlerexploitationinformation-gathering+4
2
2 days ago
CVE-2024-8856 preview

CVE-2024-8856

GitHubjenderal92/cve-2024-8856

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

information-gatheringreconnaissancevulnerability-analysis+2
22 months ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsinformation-gatheringpenetration-testing+4
4 days ago
CVE-2023-40000 preview

CVE-2023-40000

GitHubrxerium/cve-2023-40000

LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges

exploitationinformation-gatheringpenetration-testing+3
710 months ago
CVE-2026-8794 preview

CVE-2026-8794

GitHubh4zaz/cve-2026-8794

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

authenticationinformation-gatheringpenetration-testing+4
5 days ago
CVE-2023-22047---Oracle-PeopleSoft-LFI preview

CVE-2023-22047---Oracle-PeopleSoft-LFI

GitHub0xterror/cve-2023-22047---oracle-peoplesoft-lfi

CVE-2023-22047 is a critical unauthenticated Local File Inclusion (LFI) vulnerability in Oracle PeopleSoft Enterprise PeopleTools. This exploit…

exploitationinformation-gatheringpenetration-testing+3
5 days ago
Livewire2025CVE preview

Livewire2025CVE

GitHube4zyy/livewire2025cve

Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into vuln.txt, safe sites into…

information-gatheringvulnerability-analysisvulnerability-scanners+2
37 months ago
One-Liner-Collections preview

One-Liner-Collections

GitHubcybertix-pvt-ltd/one-liner-collections

This Repositories contains list of One Liners with Descriptions and Installation requirements

curated-resourcesinformation-gatheringpenetration-testing+5
5091 year ago
Wordpresscan preview
Archived

Wordpresscan

GitHubswisskyrepo/wordpresscan

WPScan rewritten in Python + some WPSeku ideas

information-gatheringpassword-attacksreconnaissance+3
6525 years ago
laf preview
Archived

laf

GitHubtakeshixx/laf

Login Area Finder: scans host/s for login panels

information-gatheringpenetration-testingreconnaissance+2
1411 years ago
arachni-ui-web preview
Archived

arachni-ui-web

GitHubarachni/arachni-ui-web

Arachni's Web User Interface.

information-gatheringpenetration-testingvulnerability-scanners+2
2334 years ago
nse-exchange preview
Archived

nse-exchange

GitHubdiverto/nse-exchange

Nmap scripts to detect exchange 0-day (CVE-2022-41082) vulnerability

exploitationinformation-gatheringpenetration-testing+3
823 years ago
heartbleed preview
Archived

heartbleed

GitHubxlucas/heartbleed

A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability

exploitationinformation-gatheringpenetration-testing+2
111 years ago
ssl-heartbleed.nse preview
Archived

ssl-heartbleed.nse

GitHubtakeshixx/ssl-heartbleed.nse

Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160

exploitationinformation-gatheringnetwork-security+3
12 years ago
CVE-2020-26733 preview
Archived

CVE-2020-26733

GitHubswzhouu/cve-2020-26733

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 Cross Site Scripting (XSS) Vulnerability

exploitationinformation-gatheringpenetration-testing+2
13 years ago
CVE-2020-26732 preview
Archived

CVE-2020-26732

GitHubswzhouu/cve-2020-26732

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session

information-gatheringmisconfigurationpenetration-testing+2
13 years ago
scan-log4shell preview
Archived

scan-log4shell

GitHubsuniastar/scan-log4shell

A scanning suite to find servers affected by the log4shell flaw (CVE-2021-44228) with example to test it

exploitationinformation-gatheringpenetration-testing+2
4 years ago
CVE-2022-0236 preview
Archived

CVE-2022-0236

GitHubqurbat/cve-2022-0236

Proof of concept for unauthenticated sensitive data disclosure affecting the wp-import-export WordPress plugin (CVE-2022-0236)

exploitationinformation-gatheringpenetration-testing+2
34 years ago
Previous1…62636465Next