Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
165 results
CVE-2026-6145 preview

CVE-2026-6145

GitHubhann1bl3l3ct3r/cve-2026-6145

User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter

ctfeducationexploitation+3
3 months ago
CVE-2026-2587-Exploit-POC preview

CVE-2026-2587-Exploit-POC

GitHubbhanunamikaze/cve-2026-2587-exploit-poc

CVE-2026-2587 PoC validator for Eclipse GlassFish EL Injection RCE in the admin console gadget.jsf handler. Safe authenticated vulnerability scanner…

code-analysisdynamic-analysis-sandboxingeducation+6
1
CVE-2025-2563 preview

CVE-2025-2563

GitHubnxploited/cve-2025-2563

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is…

educationexploitationpayload-development+5
14 months ago
test-cve-2025-29927 preview

test-cve-2025-29927

GitHubyugo-eliatrope/test-cve-2025-29927

Demo app to exploit CVE-2025-29927: NextJS middleware bypass via proxy-injected headers for unauthorized /admin access. Includes vulnerable app and…

educationexploitationpenetration-testing+2
11 year ago
cve-2025-29927-nextjs preview

cve-2025-29927-nextjs

GitHubgitgudkrish/cve-2025-29927-nextjs

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

authenticationeducationpenetration-testing+3
3 months ago
vuln-chain-lab preview

vuln-chain-lab

GitHubechosecure/vuln-chain-lab

PoC Docker lab: chaining file upload bypass + stored XSS to create admin accounts. Educational resource for pen testers.

ctfeducationlabs-practice+5
15 months ago
Exploit-CVE-2023-22518 preview

Exploit-CVE-2023-22518

GitHublilly-dox/exploit-cve-2023-22518

Exploit for CVE-2023-22518 in Atlassian Confluence. Provides a detailed walkthrough of the vulnerability, including environment setup, root cause…

educationexploitationlabs-practice+3
12 years ago
cve-2023-22515-1 preview

cve-2023-22515-1

GitHubdkq-k/cve-2023-22515-1

Technical analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence allowing…

educationexploitationpenetration-testing+3
7 months ago
CVE-2023-22515 preview

CVE-2023-22515

GitHubtranphuc2005/cve-2023-22515

Step-by-step exploit walkthrough for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Server and Data Center,…

educationexploitationpenetration-testing+2
0 years ago
CVE-2023-22515 preview

CVE-2023-22515

GitHubdkq-k/cve-2023-22515

Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…

educationexploitationpenetration-testing+3
7 months ago
CVE-2017-20192-formidable-forms preview

CVE-2017-20192-formidable-forms

GitHubflame-11/cve-2017-20192-formidable-forms

Reproducible Docker lab for CVE-2017-20192 (Formidable Forms < 2.05.03 stored XSS) with automated PoC script for unauthenticated exploitation and…

educationexploitationlabs-practice+3
8 months ago
CVE-2025-60880 preview

CVE-2025-60880

GitHubshenal01/cve-2025-60880

Proof-of-concept for a stored XSS vulnerability in Bagisto admin panel, demonstrating SVG upload with malicious JavaScript and providing mitigation…

educationexploitationvulnerability-analysis+2
10 months ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubhossainshadat/cve-2025-63420

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

educationexploitationpenetration-testing+3
9 months ago
CVE-Newgen-Software-Advisories preview

CVE-Newgen-Software-Advisories

GitHubcbx216/cve-newgen-software-advisories

Advisory for CVE-2025-65742 — Newgen OmniDocs LDAP Admin BFLA

educationexploitationinformation-gathering+3
7 months ago
CVE-2023-38829-NETIS-WF2409E preview

CVE-2023-38829-NETIS-WF2409E

GitHubadhikara13/cve-2023-38829-netis-wf2409e

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

command-and-controleducationexploitation+3
13 years ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubmmakingdom/cve-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

educationexploitationpenetration-testing+2
19 months ago
analyze-Exploit-CVE-2023-22518-Confluence preview

analyze-Exploit-CVE-2023-22518-Confluence

GitHubd3ckkno0b/analyze-exploit-cve-2023-22518-confluence

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

code-analysisdebuggerseducation+4
11 year ago
CVE-2025-54309__Enhanced_exploit preview

CVE-2025-54309__Enhanced_exploit

GitHubwhisperer1290/cve-2025-54309__enhanced_exploit

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

authentication-authorizationeducationexploitation+4
10 years ago
Previous1…345…10Next
3 months ago