Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
27 results
connectwise-screenconnect_auth-bypass-add-user-poc preview

connectwise-screenconnect_auth-bypass-add-user-poc

GitHubwatchtowrlabs/connectwise-screenconnect_auth-bypass-add-user-poc

Proof-of-concept exploit for authentication bypass in ConnectWise ScreenConnect, enabling addition of administrative user as first step to Remote…

authentication-authorizationexploitationprivilege-escalation+3
752 years ago
CVE-2025-47227_CVE-2025-47228 preview

CVE-2025-47227_CVE-2025-47228

GitHubsynacktiv/cve-2025-47227_cve-2025-47228

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

authentication-authorizationcommand-and-controlexploitation+3
111 year ago
mobileiron-exploit preview

mobileiron-exploit

GitHubsynacktiv/mobileiron-exploit

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

authenticationauthentication-authorizationexploitation+3
92 years ago
nexus-os preview

nexus-os

GitLabnexaiceo/nexus-os

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

ai-securityauthentication-authorizationcloud-security+8
4 months ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubgotr00t0day/cve-2022-1388

A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit…

authentication-authorizationexploitationpenetration-testing+3
52 years ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubdezso-dfield/cve-2023-27350

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

authentication-authorizationcommand-and-controlexploitation+4
9 months ago
CVE-2022-46169_unauth_remote_code_execution preview

CVE-2022-46169_unauth_remote_code_execution

GitHubsvchost9913/cve-2022-46169_unauth_remote_code_execution

Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0

authentication-authorizationcommand-and-controlexploitation+3
3 years ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubsoledad208/cve-2018-10933

CVE-2018-10933 very simple POC

authentication-authorizationexploitationpayload-generation+3
1267 years ago
Gogs_RCE preview

Gogs_RCE

GitHubjas502n/gogs_rce

Exploit for Gogs RCE (CVE-2018-18925) leveraging session forgery and Git hook injection to achieve arbitrary command execution with root privileges.

authentication-authorizationexploitationpayload-development+4
166 years ago
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE preview

CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE

GitHubjakabakos/cve-2023-27524-apache-superset-auth-bypass-and-rce

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

authentication-authorizationcommand-and-controldatabase-security+5
283 years ago
CVE-2026-0073-PoC-Exploit preview

CVE-2026-0073-PoC-Exploit

GitHubtc4dy/cve-2026-0073-poc-exploit

Zero-click authentication bypass exploit for Android ADB Wireless Debugging (CVE-2026-0073). Provides interactive shell, command execution, and…

android-securityauthentication-authorizationeducation+6
159 days ago
palo-alto-panos-cve-2024-0012 preview

palo-alto-panos-cve-2024-0012

GitHubwatchtowrlabs/palo-alto-panos-cve-2024-0012

Exploit for CVE-2024-0012 and CVE-2024-9474 targeting authentication bypass and authenticated command injection in Palo Alto PAN-OS management web…

authentication-authorizationcommand-and-controlexploitation+3
241 year ago
CVE-2019-10915 preview

CVE-2019-10915

GitHubjiansiting/cve-2019-10915

Proof-of-concept exploit for CVE-2019-10915 targeting an authentication bypass in Siemens TIA Administrator, enabling remote command execution via…

authentication-authorizationexploitationfirmware-analysis+3
47 years ago
fortios-auth-bypass-exploit-CVE-2024-55591 preview

fortios-auth-bypass-exploit-CVE-2024-55591

GitHubsysirq/fortios-auth-bypass-exploit-cve-2024-55591

Python exploit for CVE-2024-55591, bypassing FortiOS authentication to execute remote commands on vulnerable FortiGate and FortiProxy devices.

authentication-authorizationcommand-and-controlexploitation+3
31 year ago
CVE-2025-32432 preview

CVE-2025-32432

GitHubheltonpojo/cve-2025-32432

Pre-auth RCE exploit for Craft CMS in Go. Grabs session/CSRF token, poisons PHP session, triggers deserialization for command execution or reverse…

authentication-authorizationexploitationinformation-gathering+3
2 months ago
cve-2026-39987 preview

cve-2026-39987

GitHubmatesz44/cve-2026-39987

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

authentication-authorizationexploitationpenetration-testing+2
1 month ago
CVE-2026-34048 preview

CVE-2026-34048

GitHub0xmrma/cve-2026-34048

Admin-only terminal bootstrap routes checked only for login state, which let a normal team member drive Coolify's realtime terminal backend and…

authentication-authorizationcloud-securitycommand-and-control+6
2 months ago
CVE-2026-39987 preview

CVE-2026-39987

GitHubvanhari/cve-2026-39987

Proof-of-concept exploit for an authentication bypass in marimo's terminal WebSocket endpoint, enabling unauthenticated command execution in versions…

authentication-authorizationctfexploitation+3
2 months ago
Previous12Next