Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
165 results
CVE-2021-44228 preview

CVE-2021-44228

GitHubiamnewbiez/cve-2021-44228

Deliberately vulnerable Apache Solr application (CVE-2021-44228) for practicing Log4Shell exploitation via User-Agent, POST, and admin endpoints.…

educationexploitationlabs-practice+2
8 months ago
CVE-2020-24033 preview

CVE-2020-24033

GitHubm0nsterrr/cve-2020-24033

Proof-of-concept for CVE-2020-24033: Cross-Site Request Forgery on fs.com S3900 24T4S switch allows unauthenticated admin account creation via…

educationexploitationpenetration-testing+3
5 years ago
Duplicate-of-CVE-2023-26982 preview

Duplicate-of-CVE-2023-26982

GitHubbypazs/duplicate-of-cve-2023-26982

Trudesk version 1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the tickets `Create/Modify Ticket Tags` on…

educationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2019-9053 preview

CVE-2019-9053

GitHubso1icitx/cve-2019-9053

Unauthenticated SQL injection exploit for CVE-2019-9053 in CMS Made Simple <= 2.2.9. Extracts admin creds with time-based SQLi.

educationexploitationpassword-cracking+3
1 year ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubdennisec/cve-2025-3102

Exploit script for CVE-2025-3102 targeting SureTriggers WordPress plugin (≤ v1.0.78). Detects vulnerable versions, exploits via REST API, and creates…

educationexploitationpassword-attacks+3
1 year ago
CVE-2023-27524-POC preview

CVE-2023-27524-POC

GitHubmaanvader/cve-2023-27524-poc

A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.

authentication-authorizationeducationexploitation+3
3 years ago
CVE-2024-10924-Wordpress-Docker preview

CVE-2024-10924-Wordpress-Docker

GitHubhunt3r850/cve-2024-10924-wordpress-docker

Dockerized exploit environment for CVE-2024-10924, an authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1)…

authenticationeducationexploitation+4
1 year ago
CVE-2024-9698 preview

CVE-2024-9698

GitHubnxploited/cve-2024-9698

Crafthemes Demo Import <= 3.3 - Authenticated ( Admin+) Arbitrary File Upload in process_uploaded_files

educationexploitationpayload-development+3
1 year ago
phpipam_1.4.4 preview

phpipam_1.4.4

GitHubhadrian3689/phpipam_1.4.4

Exploit script for CVE-2022-23046 SQL injection in phpIPAM 1.4.4. Allows authenticated admin users to extract database info, read files, and write to…

educationexploitationpenetration-testing+2
3 years ago
audit-xss-cve-2020-7934 preview

audit-xss-cve-2020-7934

GitHubgiardinas-dev/audit-xss-cve-2020-7934

Docker-based XSS exploit for CVE-2020-7934 targeting Liferay portal. Demonstrates stored cross-site scripting via user profile fields to steal admin…

ctfeducationexploitation+3
4 years ago
CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE preview

CVE-2025-50365_CSRF_DELETE_CATEGORY-phpgurukul-CVE

GitHub1h3ll/cve-2025-50365_csrf_delete_category-phpgurukul-cve

PoC for CVE-2025-50365: a CSRF flaw in PHPGurukul Maid Hiring Management System allowing deletion of hiring categories via a crafted admin request.

ctfeducationexploitation+3
1 year ago
CVE-2026-17532-lab preview

CVE-2026-17532-lab

GitHubkalhoralireza/cve-2026-17532-lab

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

educationexploitationlabs-practice+3
8 days ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubmksundaram69/cve-2024-34102

Proof-of-concept exploit for CVE-2024-34102, a critical XML entity injection in Magento, enabling exfiltration of sensitive files and unauthorized…

data-exfiltrationeducationexploitation+2
1 year ago
CVE-2024-42327 preview

CVE-2024-42327

GitHubcompr00t/cve-2024-42327

Proof-of-concept exploit for CVE-2024-42327, an SQL injection vulnerability in Zabbix frontend API allowing non-admin users to execute arbitrary SQL…

educationexploitationpenetration-testing+2
181 year ago
CVE-2025-2304 preview

CVE-2025-2304

GitHubalien0ne/cve-2025-2304

Authenticated privilege escalation in Camaleon CMS v2.9.0 via improper parameter handling in the updated_ajax endpoint.

educationexploitationpassword-attacks+4
197 months ago
CitrixBleed-2-CVE-2025-5777-PoC- preview

CitrixBleed-2-CVE-2025-5777-PoC-

GitHubmingshenhk/citrixbleed-2-cve-2025-5777-poc-

详细讲解CitrixBleed 2 — CVE-2025-5777(越界泄漏)PoC 和检测套件

defensive-toolseducationexploitation+7
171 year ago
CVE-2023-24249-Exploit preview

CVE-2023-24249-Exploit

GitHubiduzzel/cve-2023-24249-exploit

Exploit script for CVE-2023-24249 - a vulnerability allowing remote code execution via file upload and command injection.

educationexploitationpayload-generation+4
92 years ago
CVE-2023-32315 preview

CVE-2023-32315

GitHubap0dexme0/cve-2023-32315

Perform With Massive Openfire Unauthenticated Users

educationexploitationpenetration-testing+2
63 years ago
Previous1…567…10Next