Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
206 results
cve-2025-29927-nextjs preview

cve-2025-29927-nextjs

GitHubgitgudkrish/cve-2025-29927-nextjs

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

authenticationeducationpenetration-testing+3
3 months ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubmmakingdom/cve-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

educationexploitationpenetration-testing+2
19 months ago
CVE-2025-66947 preview

CVE-2025-66947

GitHubkabir0104k/cve-2025-66947

Proof-of-concept for time-based blind SQL injection in a PHP admin panel. Demonstrates exploitation via unsanitized GET parameter, with mitigation…

database-securityeducationpenetration-testing+2
18 months ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubhossainshadat/cve-2025-63420

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

educationexploitationpenetration-testing+3
9 months ago
xuxueli__xxl-job_CVE-2020-29204_2-2-0 preview

xuxueli__xxl-job_CVE-2020-29204_2-2-0

GitHubshoucheng3/xuxueli__xxl-job_cve-2020-29204_2-2-0

Exploit for CVE-2020-29204 targeting XXL-JOB distributed task scheduling framework, demonstrating remote code execution via unauthenticated access to…

educationexploitationmisconfiguration+3
1 year ago
CVE-2024-34832 preview

CVE-2024-34832

GitHubjulio-cfa/cve-2024-34832

Proof-of-concept exploit for CVE-2024-34832: directory traversal in CubeCart admin panel leading to remote code execution via crafted `_g` parameter…

code-analysiseducationexploitation+3
2 years ago
CVE-2025-67315 preview

CVE-2025-67315

GitHubr-pradyun/cve-2025-67315

CSRF vulnerability PoC and remediation guide for employee deactivation in an admin panel. Includes CVSS scoring, attack reproduction steps, and…

ctfeducationexploitation+3
7 months ago
CVE-2026-54415-PoC preview

CVE-2026-54415-PoC

GitHubabdugafforov-bobur/cve-2026-54415-poc

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

authenticationctfeducation+4
21 month ago
Gallery-Plugin-SQL-Injection preview

Gallery-Plugin-SQL-Injection

GitHubcapture0x/gallery-plugin-sql-injection

Exploit for SQL injection in WordPress Video Gallery plugin (version 2.3.6) via orderby parameter, enabling unauthenticated database extraction.

educationexploitationpenetration-testing+3
2 years ago
TotalCMS-Arbitrary_File-Upload--XSS_Steal_Cookies---TotalDepot preview

TotalCMS-Arbitrary_File-Upload--XSS_Steal_Cookies---TotalDepot

GitHubsromanhu/totalcms-arbitrary_file-upload--xss_steal_cookies---totaldepot

TotalCMS is affected by Arbitrary File Upload - XSS vulnerability which allows Cross-Site Scriting (XSS) Stored and also stealing session cookies

data-exfiltrationeducationexploitation+3
2 years ago
CVE-2026-55579 preview

CVE-2026-55579

GitHubch4120n/cve-2026-55579

Python exploit for CVE-2026-55579, an unauthenticated RCE in Pheditor via hardcoded default credentials. Executes commands and uploads files through…

educationexploitationlabs-practice+6
11 month ago
mellivora preview

mellivora

GitHubnakiami/mellivora

PHP-based CTF engine for hosting capture-the-flag competitions with arbitrary challenges, scoreboards, hints, team management, and admin console.…

ctfeducationlabs-practice+3
4512 years ago
Cryptolocker preview

Cryptolocker

GitHubajayrandhawa/cryptolocker

Open-source ransomware simulator with AES-256 file encryption, system lockdown, and multi-threaded encryption. Includes a web admin interface for key…

educationencryption-decryption-toolsmalware-analysis
1431 month ago
wireshark-rdp preview

wireshark-rdp

GitHubawakecoding/wireshark-rdp

Curated RDP Wireshark captures illustrating Kerberos, NTLM, smartcard, NLA, Restricted Admin, Credential Guard, RD Gateway, and clipboard redirection…

authenticationcurated-resourceseducation+3
2221 year ago
ForceAdmin preview

ForceAdmin

GitHubcatzsec/forceadmin

⚡ Create infinite UAC prompts forcing a user to run as admin ⚡

educationpayload-generationprivilege-escalation+1
2463 years ago
CVE-2018-9995-rs preview

CVE-2018-9995-rs

GitHub0xdamian/cve-2018-9995-rs

Rust proof-of-concept that exploits an authentication bypass in DVR/NVR devices to dump admin credentials via vulnerable login endpoints.

educationexploitationinformation-gathering+3
979 months ago
camjacking preview

camjacking

GitHubcappricio-securities/camjacking

Simulates camera permission phishing attacks for security awareness training, featuring realistic templates, an admin dashboard, and real-time alerts…

educationimpersonation-toolsinformation-gathering+5
645 months ago
confluence-hack preview

confluence-hack

GitHubaiex-3/confluence-hack

Exploit for CVE-2023-22515 in Atlassian Confluence that creates a new admin user and deploys a web-based shell plugin for command execution on the…

educationexploitationpenetration-testing+3
522 years ago
Previous12…12Next