Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
165 results
CVE-2014-3704 preview

CVE-2014-3704

GitHubjoaomorenorf/cve-2014-3704

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

educationexploitationlabs-practice+2
1
1 year ago
CVE-2025-66947 preview

CVE-2025-66947

GitHubkabir0104k/cve-2025-66947

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

database-securityeducationpenetration-testing+2
18 months ago
vulnerability-in-Remix-React-Router-CVE-2025-31137- preview

vulnerability-in-Remix-React-Router-CVE-2025-31137-

GitHubpouriam23/vulnerability-in-remix-react-router-cve-2025-31137-

CTF challenge replicating CVE-2025-31137 in Remix/React Router Express. Learn to exploit a server-side vulnerability to find the admin flag.

ctfeducationexploitation+3
11 year ago
CrushFTP-auth-bypass-CVE-2025-31161 preview

CrushFTP-auth-bypass-CVE-2025-31161

GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

authentication-authorizationcommand-and-controlctf+7
11 months ago
CrushFTP-AS2-Bypass-Research-CVE-2025-54309 preview

CrushFTP-AS2-Bypass-Research-CVE-2025-54309

GitHubsmileyface101/crushftp-as2-bypass-research-cve-2025-54309

Research on CrushFTP AS2 authentication bypass allowing unauthenticated admin access. Includes PoC scripts, detection rules, and technical analysis…

authenticationdefensive-toolseducation+6
9 months ago
CVE-2019-9053-POC preview

CVE-2019-9053-POC

GitHubcaelumisme/cve-2019-9053-poc

Python 3 exploit for CVE-2019-9053, an unauthenticated time-based blind SQL injection in CMS Made Simple < 2.2.10, extracting admin credentials and…

educationexploitationpassword-cracking+3
10 months ago
CVE-2020-29607-POC preview

CVE-2020-29607-POC

GitHubcaelumisme/cve-2020-29607-poc

Python 3 exploit for Pluck CMS 4.7.13 file upload restriction bypass, enabling authenticated admin to upload a PHP webshell and achieve remote code…

educationexploitationpayload-generation+3
10 months ago
CVE-2025-34157 preview

CVE-2025-34157

GitHubeyodav/cve-2025-34157

A stored XSS in the project delete flow allows execution of attacker-controlled JavaScript in an administrator’s browser when the admin attempts to…

ctfeducationexploitation+3
11 months ago
CVE-2025-57520-Stored-XSS-in-Decap-CMS-3.8.3- preview

CVE-2025-57520-Stored-XSS-in-Decap-CMS-3.8.3-

GitHubonurcangnc/cve-2025-57520-stored-xss-in-decap-cms-3.8.3-

A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the **admin…

educationexploitationpenetration-testing+3
11 months ago
xuxueli__xxl-job_CVE-2020-29204_2-2-0 preview

xuxueli__xxl-job_CVE-2020-29204_2-2-0

GitHubshoucheng3/xuxueli__xxl-job_cve-2020-29204_2-2-0

Exploit for CVE-2020-29204 targeting XXL-JOB distributed task scheduling framework, demonstrating remote code execution via unauthenticated access to…

educationexploitationmisconfiguration+3
1 year ago
CVE-2020-25273 preview

CVE-2020-25273

GitHubjonathanrey87/cve-2020-25273

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

authenticationeducationexploitation+3
5 years ago
CVE-2025-52357 preview

CVE-2025-52357

GitHubwrathfuldiety/cve-2025-52357

Proof of Concept and Security Advisory for XSS vulnerability in the FD602GW-DX-R410 fiber router’s admin console (firmware V2.2.14). Includes…

educationexploitationpenetration-testing+3
1 year ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubrizqimaulanaa/cve-2023-3460

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in the Ultimate Member WordPress plugin. Intended for educational…

educationexploitationpenetration-testing+2
3 years ago
CVE-2023-29983 preview

CVE-2023-29983

GitHubzprototype/cve-2023-29983

Proof-of-concept for CVE-2023-29983: stored cross-site scripting via unsanitized token parameter in cmaps auditlog, enabling admin cookie theft.

educationexploitationpenetration-testing+3
3 years ago
CVE-2024-34832 preview

CVE-2024-34832

GitHubjulio-cfa/cve-2024-34832

Proof-of-concept exploit for CVE-2024-34832: directory traversal in CubeCart admin panel leading to remote code execution via crafted `_g` parameter…

code-analysiseducationexploitation+3
2 years ago
Magento-eCommerce-RCE-CVE-2015-1397 preview

Magento-eCommerce-RCE-CVE-2015-1397

GitHub0xdtc/magento-ecommerce-rce-cve-2015-1397

Bash exploit for CVE-2015-1397 (Magento Shoplift) that injects crafted SQL payloads to create an admin user on vulnerable Magento stores.

educationexploitationpenetration-testing+2
1 year ago
CVE-2023-32315 preview

CVE-2023-32315

GitHubasepsaepdin/cve-2023-32315

Python exploit for CVE-2023-32315, a path traversal in Openfire's admin console, allowing unauthenticated access to restricted pages. Includes Docker…

educationexploitationpenetration-testing+2
1 year ago
CVE-2024-44871 preview

CVE-2024-44871

GitHubvances25/cve-2024-44871

Python exploit for MoziloCMS <= 3.0.1 that uploads a PHP web shell via authenticated admin access, renames the file, and executes system commands on…

educationexploitationpayload-generation+2
1 year ago
Previous1…456…10Next