Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1170 results
CVE-2026-19598 preview

CVE-2026-19598

GitHubsag-asab/cve-2026-19598

Custom Content Types and Fields plugin for WordPress

authentication-authorizationexploitationvulnerability-analysis+2
1
12 days ago
lab-cve-2025-3515 preview

lab-cve-2025-3515

GitHubimbios/lab-cve-2025-3515

CVE-2025-3515 WordPress lab for Drag and Drop Multiple File Upload for CF7: Dockerized PoC & Nuclei testing

educationexploitationlabs-practice+2
10 years ago
nginx-ultimate-bad-bot-blocker preview

nginx-ultimate-bad-bot-blocker

GitHubmitchellkrogza/nginx-ultimate-bad-bot-blocker

Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS,…

anti-botdefensive-toolsnetwork-security+1
4.8k15h 31m ago
wp2shell-poc preview

wp2shell-poc

GitHubcolere-sys/wp2shell-poc

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

ctfeducationexploit-frameworks+5
31 month ago
Wp2shell-ioc-scanner preview

Wp2shell-ioc-scanner

GitHubmichael-kanda/wp2shell-ioc-scanner

Detects shadow-administrator accounts in WordPress via configurable indicators and heuristics, then removes selected accounts through guarded, logged…

defensive-toolsidentity-access-managementincident-response+4
1 month ago
CVE-2025-11262-Lab preview

CVE-2025-11262-Lab

GitHubrootdirective-sec/cve-2025-11262-lab

Docker lab for reproducing CVE-2025-11262, an unauthenticated stored blind XSS in Link Whisper Free WordPress plugin. Includes vulnerable and patched…

ctfeducationlabs-practice+3
2 months ago
CVE-2024-43160 preview

CVE-2024-43160

GitHubktn1990/cve-2024-43160

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is…

exploitationpayload-generationpenetration-testing+3
21 year ago
CVE-2026-8181-Lab preview

CVE-2026-8181-Lab

GitHubrootdirective-sec/cve-2026-8181-lab

Docker lab demonstrating CVE-2026-8181 authentication bypass in Burst Statistics WordPress plugin. Compares vulnerable and patched versions with a…

authenticationctfeducation+5
3 months ago
CVE-2025-6783 preview

CVE-2025-6783

GitHubjfriedli/cve-2025-6783

Proof-of-concept exploit for CVE-2025-6783 demonstrating SQL injection via crafted HTTP headers and JSON payload against WordPress GoZen Forms REST…

api-security-testingexploitationpenetration-testing+2
5 months ago
wordpress-rce-vapt-cve-2020-25213 preview

wordpress-rce-vapt-cve-2020-25213

GitHubcmadhushanka/wordpress-rce-vapt-cve-2020-25213

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware…

educationexploitationlabs-practice+6
3 months ago
CVE-2019-8942 preview

CVE-2019-8942

GitHubtuannq2299/cve-2019-8942

Detailed technical analysis and proof-of-concept exploit for WordPress RCE vulnerabilities CVE-2019-8942 and CVE-2019-8943, demonstrating LFI-to-RCE…

ctfeducationexploitation+3
14 years ago
CVE-2025-4380 preview

CVE-2025-4380

GitHubr0otk3r/cve-2025-4380

Python exploit for CVE-2025-4380, a Local File Inclusion vulnerability in the Ads Pro WordPress plugin. Supports single and mass target scanning with…

educationexploitationinformation-gathering+3
1 year ago
poc-cve-xss-uploading-svg preview

poc-cve-xss-uploading-svg

GitHub0xn4d/poc-cve-xss-uploading-svg

Proof-of-concept for CVE-2023-4460: authenticated reflected and stored XSS in WordPress plugin Uploading SVG, WEBP and ICO files, triggered via…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2022-4539 preview

CVE-2022-4539

GitHubabdurahmon3236/cve-2022-4539

Exploit for CVE-2022-4539 that spoofs X-Forwarded-For headers to bypass WordPress WAF IP-based login and logging restrictions. Includes scalable…

fingerprint-spoofingids-ips-evasionimpersonation-tools+3
2 years ago
mitigation-cve-2019-9787 preview

mitigation-cve-2019-9787

GitHubkuangting4231/mitigation-cve-2019-9787

PoC and mitigation for CVE-2019-9787 (WordPress XSS/CSRF/RCE). Demonstrates sanitization fixes, HttpOnly cookies, and hash-based CSRF defense with…

ctfeducationexploitation+3
4 years ago
Wordell preview

Wordell

GitHubk3ystr0k3r/wordell

Wordell is a powerful WordPress enumeration script designed to make your WordPress security assessments more efficient and comprehensive. It enables…

information-gatheringosintpenetration-testing+3
43 years ago
argus-wp-watcher preview

argus-wp-watcher

GitHubrodhnin/argus-wp-watcher

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

ai-securitycrawlereducation+5
184 months ago
CVE-2026-0920 preview

CVE-2026-0920

GitHubjohn-doe-code-a11/cve-2026-0920

Explanation and payload of the recent vulnerability in the LA-Studio Element WordPress plugin.

exploitationpayload-developmentpenetration-testing+2
77 months ago
Previous1…456…65Next