Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Penetration_Testing_POC — 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms | Kitploit
Tools/GitHubGitHub/mr-xn/penetration_testing_poc
Privilege EscalationIoT SecurityVulnerability AnalysisExploitationWeb Application ExploitationFuzzingPenetration TestingLearning & EducationCurated Resources

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
GitHubmr-xn/penetration_testing_poc

Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

View RepositoryWebsite
7.4k2.0k991 day agoReviewed by Kitploit

Penetration_Testing_POC

A collection of POCs, scripts, tools, articles, and other tips and tricks used in penetration testing, serving as notes. Contributions are welcome.

Please be aware of whether all tools contain backdoors or other abnormal behavior. It is recommended to operate in a virtual environment.

  • Penetration_Testing_POC
  • Please make good use of search [Ctrl+F] to find
  • IOT Device&Mobile Phone
  • Web APP
  • Privilege Escalation Assistance Related
  • PC
  • tools - Small Tool Collection
  • Articles/Books/Tutorials Related
  • Notes

Please make good use of search [Ctrl+F] to find

IOT Device&Mobile Phone

  • Tianyi Skyworth awifi router has multiple unauthorized access vulnerabilities
  • Huawei WS331a product management page has a CSRF vulnerability
  • CVE-2019-16313 Fengwang Hulian enterprise router v4.31 password disclosure vulnerability
  • D-Link router RCE vulnerability
  • CVE-2019-13051 - Pi-Hole router-side ad-blocking software command injection & privilege escalation
  • D-Link DIR-859 - RCE UnAutenticated (CVE-2019-17621)
  • Huawei HG255 Directory Traversal|Local backup file
  • D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit) CVE-2019-20215 (Metasploit)%20CVE-2019-20215.rb)
  • From Interfaces.d to RCE: Mozilla WebThings IoT Gateway Vulnerability Discovery
  • Xiaomi series router remote command execution vulnerability (CVE-2019-18370, CVE-2019-18371)
  • Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload - firmware can be replaced without authentication)
  • cve-2020-8634&cve-2020-8635|Wing FTP Server 6.2.3 privilege escalation vulnerability discovery, analysis, and reproduction process|Wing FTP Server 6.2.5 privilege escalation
  • CVE-2020-9374-TP LINK TL-WR849N - RCE
  • CVE-2020-12753-LG smartphone arbitrary code execution vulnerability
  • CVE-2020-12695-UPnP security vulnerability
  • 79 Netgear routers remotely taken over via 0day
  • dlink-dir610-exploits-Exploits for CVE-2020-9376 and CVE-2020-9377
  • wacker: A set of scripts that can assist in performing online dictionary attacks against WPA3 access points
  • CVE-2020-24581 D-Link DSL-2888A remote command execution vulnerability analysis-Original address
  • CNVD-2021-14536_Ruijie RG-UAC Unified Internet Behavior Management Audit System account password information disclosure vulnerability
  • CNVD-2021-14544: Hikvision streaming media management server arbitrary file read
  • CNVD-2020-25078: D-link sensitive information leakage, account passwords can be directly obtained to view surveillance
  • ios-gamed-0day
  • ios-nehelper-wifi-info-0day
  • ios-nehelper-enum-apps-0day
  • iOS 15.0.1 RCE PoC
  • DarkSword-RCE: Apple iOS remote code execution vulnerability exploit|darksword-kexploit: Apple iOS kernel exploit|DarkSword: Apple iOS exploit
  • CVE-2021-36260: Hikvision product command injection vulnerability
  • CVE-2021-33044, CVE-2021-33045 Dahua camera POC|Related analysis|Login bypass Chrome extension
  • CVE-2021-36260: Hikvision command injection vulnerability|Another CVE-2021-36260 exploit script
  • CVE-2021-41653: TP-Link TL-WR840N V5(EU) - RCE%20-%20RCE%20-%20CVE-2021-41653.pdf)
  • DirtyPipe-Android: Dirty Pipe root exploit for Android
  • CVE-2022-30075: Tp-Link Archer AX50 Authenticated RCE
  • NotQuite0day: D-Link 1960 related vulnerabilities
  • HuaYuReportRCE: Huayu Digital Report component GetShell
  • IOT_Vul: IOT related vulnerability collection
  • CameraHack: Batch scan and exploit common vulnerabilities in Hikvision, Dahua, and other cameras
  • CVE-2022-32832: Apple macOS APFS kernel arbitrary code execution vulnerability
  • HookWechatRecall: Intercept WeChat message recall Demo via frida tool
  • IOT_vuln: IOT related vulnerability repository
  • hikvision_CVE-2017-7921_auth_bypass_config_decryptor: Decrypt Hikvision configuration files affected by CVE-2017-7921
Download Tool