Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
294 results
WSS preview

WSS

GitHubnu11secur1ty/wss

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

code-analysisinformation-gatheringpassword-attacks+3
3
2 months ago
CVE-2022-1597 preview

CVE-2022-1597

GitHubv35hr4j/cve-2022-1597

The plugin, used as a companion for the Discy and Himer themes, does not sanitise and escape a parameter on its reset password form which makes it…

exploitationpenetration-testingphishing-tools+3
44 years ago
wp2shell-rce preview

wp2shell-rce

GitHubjohnlodan/wp2shell-rce

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

penetration-testingreconnaissancevulnerability-analysis+4
31 month ago
CVE-2026-15964-PoC preview

CVE-2026-15964-PoC

GitHubinstructor-admin/cve-2026-15964-poc

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

authentication-authorizationexploitationinformation-gathering+5
11 month ago
p4wned preview

p4wned

GitHubflyingllama87/p4wned

Perforce security research and tools - CVE-2026-6043

exploitationexploit-frameworksinformation-gathering+6
23 months ago
XSS2Shell-CVE-2026-64638 preview

XSS2Shell-CVE-2026-64638

GitHubmr-leonardogomes/xss2shell-cve-2026-64638

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

exploitationpenetration-testingreconnaissance+3
11 month ago
xss2shell-check preview

xss2shell-check

GitHubsanaullahamanullah/xss2shell-check

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

defensive-toolsinformation-gatheringpenetration-testing+4
11 month ago
meowEye preview

meowEye

GitHubeslam3kl/meoweye

MeowEye is a real-time scanner for identifying multiple web vulnerabilities in live applications.

dynamic-analysis-sandboxingfuzzingpenetration-testing+3
31 year ago
CVE-2025-53072-CVE-2025-62481 preview

CVE-2025-53072-CVE-2025-62481

GitHubrxerium/cve-2025-53072-cve-2025-62481

Detection for CVE-2025-53072 + CVE-2025-62481

reconnaissancevulnerability-scannersweb-security+1
311 months ago
CVE-2026-49049 preview

CVE-2026-49049

GitHubjenderal92/cve-2026-49049

Mass vulnerability scanner for CVE-2026-49049 – Unauthenticated Remote Code Execution in Joomla Helix3 plugin. Multi‑threaded, detects both executed…

exploitationpayload-generationpenetration-testing+4
1 month ago
CVE-2026-41473-CyberPanel-AI-Scanner-Unauth preview

CVE-2026-41473-CyberPanel-AI-Scanner-Unauth

GitHubpenteraio/cve-2026-41473-cyberpanel-ai-scanner-unauth

Nuclei detection template for CVE-2026-41473, an unauthenticated read/write API access flaw in CyberPanel AI Scanner before 2.4.4. Uses two HTTP…

api-securityapi-security-testingvulnerability-analysis+3
2 months ago
CVE-2025-12101-Scanner-PoC preview

CVE-2025-12101-Scanner-PoC

GitHubboneys/cve-2025-12101-scanner-poc

Multi-threaded scanner for CVE-2025-12101, a reflected XSS in Citrix NetScaler, with single/multi-host scanning, dual protocol testing, proxy…

exploitationinformation-gatheringpenetration-testing+3
2 months ago
wp2shell preview

wp2shell

GitHubkulichr/wp2shell

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.

exploitationinformation-gatheringreconnaissance+3
2 months ago
CVE-2022-35499 preview

CVE-2022-35499

GitHubpn-tester/cve-2022-35499

Proof-of-concept exploit for reflected cross-site scripting (XSS) vulnerability in Trimble TM4WEB <=22.2.0, demonstrating injection via arbitrary URL…

exploitationinformation-gatheringpenetration-testing+3
2 months ago
CVE-2006-2842 preview

CVE-2006-2842

GitHubkarthi-the-hacker/cve-2006-2842

CLI scanner for CVE-2006-2842 (PHP include() path truncation) vulnerability. Scans single or multiple URLs to detect this specific web application…

information-gatheringpenetration-testingreconnaissance+3
32 years ago
CVE-2026-17543-PHP-Exposure-Validator preview

CVE-2026-17543-PHP-Exposure-Validator

GitHubpratham220/cve-2026-17543-php-exposure-validator

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

defensive-toolsinformation-gatheringpenetration-testing+5
1 month ago
CVE-2025-37164 preview

CVE-2025-37164

GitHubrxerium/cve-2025-37164

Detection for CVE-2025-37164

exploitationpenetration-testingvulnerability-analysis+3
39 months ago
CVE-2025-66470 preview

CVE-2025-66470

GitHubjmehta10/cve-2025-66470

A fast, simple scanner for detecting CVE-2025-66470 - XSS vulnerability in NiceGUI's ui.interactive_image component.

exploitationinformation-gatheringpenetration-testing+4
29 months ago
Previous1…456…17Next