Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Exploits — Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for penetration testing and research. | Kitploit
Tools/GitHubGitHub/kmkz/exploits
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationFuzzingCommand and ControlLearning & EducationPayload DevelopmentContainer Escape
GitHubkmkz/exploits

Exploits

Original CVEs, exploit PoCs, and security advisories with detailed vulnerability chains, privilege escalation, and container escape techniques for penetration testing and research.

2166816 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

Exploits

Original CVEs, exploit PoCs and security advisories
by @kmkz · boffsec-services.com · @kmkz_security


2026

FileTargetTypeCVSSv3
CVE-2026-22191-SicuroWeb-ATI-chain.txtSicuroWeb / Beghelli Sicuro24Advisory (3-CVE chain)9.3
CVE-2026-22191-POC.pySicuroWeb / Beghelli Sicuro24PoC (mitmproxy)9.3
CVE-2026-22192-22199_Voltronic-Power_Preauth_root_RCE.txtVoltronic Power SNMP Web Pro 1.1Advisory (2-CVE chain)10.0
KeyCloak-49220-secret-dump-ato.shKeycloak <= 26.5.6PoC (client secret dump + ATO)8.1
CVE-2026-58455DockwatchLab + PoC9.8

CVE-2026-22191 - Template Injection (CWE-79, CWE-1336)
CVE-2026-41468 - AngularJS Sandbox Escape (CWE-94, CWE-1104)
CVE-2026-41469 - Missing CSP / persistence (CWE-693)
-> Chain: Template Injection -> sandbox escape -> no-CSP persistence -> MITM delivery -> persistent client-side RCE (SicuroWeb / Beghelli Sicuro24)

CVE-2026-22192 - Client-side auth bypass via localStorage (CWE-306, CWE-284)
CVE-2026-22199 - Pre-auth path traversal /etc/shadow disclosure (CWE-22)
-> Chain: auth bypass + path traversal -> hash crack -> SSH root RCE (Voltronic Power SNMP Web Pro 1.1) Published April 22, 2026 - 120-day coordinated disclosure via VulnCheck - no vendor patch available
-> Full write-up

Issue #49220 - No CVE - Keycloak Admin REST API: client secrets returned in plaintext to view-clients holders (CWE-522, CWE-284)
-> Chain: admin token (assumed breach) -> client secret dump -> client_credentials grant -> manage-users scope -> full user PII dump + persistent ATO via password reset
-> Secret persists until manually rotated - admin token expiry does not close the window
-> Affected: all versions <= 26.5.6 / Fixed: 26.5.7+ (No CVE - 06/01/2026)

CVE-2026-58455 - Execution After Redirect chained with OS Command Injection (CWE-698, CWE-78)
-> Chain: missing exit() after authentication redirect -> unauthenticated session state -> composePath command injection -> container RCE -> host compromise through the mounted Docker socket
-> Affected: Dockwatch <= 0.6.567
-> Fix PR #135 closed without merge; no patched release available as of 2026-07-21
-> Lab, PoC and reproduction notes


2025

FileTargetTypeCVSSv3
CVE-2025-43300-POC.py-PoC-

2020

FileTargetTypeCVSSv3
CVE-2020-0796_scan.shWindows SMBv3 (SMBGhost)Scanner-

2019

FileTargetTypeCVSSv3
CVE-2019-14251-TEMENOS-T24.txt

PUBLISURE - exploit chain: access control bypass (pre-auth) -> SQLi -> unrestricted file upload RCE -> local admin
Published September 5th, 2019


2018

FileTargetTypeCVSSv3
CVE-2018-10682 / CVE-2018-10683

CVE-2018-10682/10683 - WildFly unauthenticated RCE via anonymous access + .war auto-deployment
Published May 3rd, 2018 - with @Piosky1


2017

FileTargetTypeCVSSv3
CVE-2017-5671.txt

2016

CVE-2016-1000300 - GRR booking system, file extension-only filter bypass -> RCE + privilege escalation
Published January 7th, 2016


2014

FileTargetTypeCVSSv3
FireEye-Malware-Analysis-System-6.4.1-Multiple-Vulns.txtFireEye MAS 6.4.1Multiple vulnerabilities-

Legacy

Older PoCs and research without a precise publication date.


Tools

FileLanguageDescription
Full-payload-delivery-chain.ps1PowerShellFull payload delivery chain (AMSI bypass + dropper)
RedisCredentialCollector.plPerl

Repository structure

root@kitploit:~
Exploits/
2026/
CVE-2026-22191-SicuroWeb-ATI-chain.txt
CVE-2026-22191-POC.py
CVE-2026-22192-22199_Voltronic-Power_Preauth_root_RCE.txt
2025/
2020/
2019/
2018/
2017/
2016/
2014/
Legacy/
Tools/
README.md

Related repositories

  • kmkz/Pentesting - Pentesting tricks and cheat sheets
  • kmkz/Assembly-language - x86/ARM sources for exploit dev
  • kmkz/Sources - Offensive security source code

For professional engagements: boffsec-services.com

Download Tool
TEMENOS T24
Advisory
-
PUBLISURE-EXPLOIT-CHAIN-ADVISORY.txtPublisure Hybrid Mail 2.1.23-vuln chain7.2
WildFly 10.1.2
Unauthenticated RCE
10.0
CVE-2018-8495.htmlWindows Shell URI handler (Edge/IE 11)1-click RCE-
-
Advisory
-
CVE-2017-5671-Credits.pdf-Credits-
FileTargetTypeCVSSv3
CVE-2016-1000300.txtGRR <= 3.0.0-RC1Authenticated RCE via file upload bypass9.9
CVE-2016-6175.txt-Advisory-
cowroot_stable.cLinux kernel (Dirty COW - CVE-2016-5195)LPE-
FileTargetLanguage
BigAnt_Server2.52-RCE.pyBigAnt Server 2.52Python
CodegateCTF_web500.plCodegate CTF Web 500Perl
ForgeZoneCMS_Exploit.plForgeZone CMSPerl
FreeFloatFTP.pyFreeFloat FTP ServerPython
FTPfuzz.pyFTP (generic fuzzer)Python
SciteBoF_poc.plSciTE editorPerl
make_3.81_pointer_dereferencing_poc.plGNU Make 3.81Perl
Redis monitor-based credential harvester