Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2016-15041-mainwp-dashboard preview

CVE-2016-15041-mainwp-dashboard

GitHubflame-11/cve-2016-15041-mainwp-dashboard

Vuln lab: MainWP Dashboard <= 3.1.2 Unauthenticated Stored XSS

ctfeducationlabs-practice+3
8 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubzycoder0day/cve-2026-8181

CVE-2026-8181 - Burst Statistics 3.4.0-3.4.1.1 Unauthenticated Authentication Bypass to Admin Account Takeover | Proof of Concept

authenticationctfeducation+4
53 months ago
HackTheBox-Facts preview

HackTheBox-Facts

GitHubsuriyaboon/hackthebox-facts

HTB Facts is a Easy Linux box featuring Camaleon CMS and MinIO. Gain admin access via open registration and a mass assignment vulnerability, then…

cloud-securityctfeducation+7
3 months ago
VulnHub-DC1-Writeup preview

VulnHub-DC1-Writeup

GitHubprapul1/vulnhub-dc1-writeup

VulnHub DC-1 boot-to-root — exploiting CVE-2018-7600 (Drupalgeddon2) for RCE, extracting DB credentials from settings.php, forging admin password…

ctfeducationexploitation+9
12 months ago
Next.js-Middleware-Bypass-CVE-2025-29927- preview

Next.js-Middleware-Bypass-CVE-2025-29927-

GitHubpouriam23/next.js-middleware-bypass-cve-2025-29927-

CTF challenge to learn and practice exploiting the Next.js middleware bypass vulnerability (CVE-2025-29927) by finding a flag in an admin page.

ctfeducationlabs-practice+3
21 year ago
CVE-2026-11518-XSS preview

CVE-2026-11518-XSS

GitHubxmyronn/cve-2026-11518-xss

Proof-of-concept for unauthenticated stored XSS in SourceCodester Inventory System, demonstrating admin session hijacking via crafted registration…

ctfeducationpenetration-testing+3
3 months ago
CVE-2026-6145 preview

CVE-2026-6145

GitHubhann1bl3l3ct3r/cve-2026-6145

User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter

ctfeducationexploitation+3
3 months ago
vuln-chain-lab preview

vuln-chain-lab

GitHubechosecure/vuln-chain-lab

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

ctfeducationlabs-practice+5
15 months ago
vulnerability-in-Remix-React-Router-CVE-2025-31137- preview

vulnerability-in-Remix-React-Router-CVE-2025-31137-

GitHubpouriam23/vulnerability-in-remix-react-router-cve-2025-31137-

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

ctfeducationexploitation+3
11 year ago
cmsms-sqli preview

cmsms-sqli

GitHubtim-karov/cmsms-sqli

Python3 exploit for CVE-2019-9053 (CMS Made Simple <= 2.2.9 SQLi). No deps, time-based blind SQLi → admin creds dump. HTB Writeup owned.

ctfexploitationpassword-cracking+3
7 months ago
CrushFTP-auth-bypass-CVE-2025-31161 preview

CrushFTP-auth-bypass-CVE-2025-31161

GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

authentication-authorizationcommand-and-controlctf+7
11 months ago
CVE-2025-34157 preview

CVE-2025-34157

GitHubeyodav/cve-2025-34157

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

ctfeducationexploitation+3
11 months ago
CVE-2015-1397-Magento-Shoplift preview

CVE-2015-1397-Magento-Shoplift

GitHubwytchwulf/cve-2015-1397-magento-shoplift

Exploit scripts for CVE-2015-1397 in Magento CMS, including a pre-auth exploit to gain admin credentials and a post-auth RCE module for reverse shell…

ctfexploitationpayload-generation+3
2 years ago
audit-xss-cve-2020-7934 preview

audit-xss-cve-2020-7934

GitHubgiardinas-dev/audit-xss-cve-2020-7934

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

ctfeducationexploitation+3
4 years ago
CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE preview

CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50365_csrf_delete_category-phpgurukul-cve

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

ctfeducationexploitation+3
1 year ago
CVE-2026-54415-PoC preview

CVE-2026-54415-PoC

GitHubabdugafforov-bobur/cve-2026-54415-poc

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

authenticationctfeducation+4
22 months ago
CVE-2024-1813-POC preview

CVE-2024-1813-POC

GitHubmobetasec/cve-2024-1813-poc

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

ctfeducationlabs-practice+4
1 month ago
moodle-cve preview

moodle-cve

GitHubhxuu/moodle-cve

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

ctfeducationexploitation+3
31 year ago
Previous12Next