Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
111 results
CVE-2025-29927-check preview

CVE-2025-29927-check

GitHubc0dejump/cve-2025-29927-check

script to check cve "CVE-2025-29927" while waiting to add it to HExHTTP

exploitationinformation-gatheringpenetration-testing+2
31 year ago
dirty-pipe-poc preview

dirty-pipe-poc

GitHub0xeremus/dirty-pipe-poc

POC Exploit to add user to Sudo for CVE-2022-0847 Dirty Pipe Vulnerability

binary-exploitationexploitationpenetration-testing+2
23 years ago
Fragnesia preview

Fragnesia

GitHub1neptune/fragnesia

Add go CVE-2026-46300 (Fragnesia) local privilege escalation exploit

exploitationpenetration-testingprivilege-escalation+1
13 months ago
CVE-2022-32114 preview

CVE-2022-32114

GitHubbypazs/cve-2022-32114

An unrestricted file upload vulnerability in the Add New Assets function of Strapi v4.1.12 allows attackers to execute arbitrary code via a crafted…

exploitationpenetration-testingvulnerability-analysis+2
14 years ago
DirtyFrag preview

DirtyFrag

GitHub1neptune/dirtyfrag

Add go CVE-2026-43284 / CVE-2026-43500 (dirtyfrag) local privilege escalation exploit

container-escapeexploitationprivilege-escalation+1
13 months ago
Mass-CVE-2023-28121-kdoec preview

Mass-CVE-2023-28121-kdoec

GitHubrio128128/mass-cve-2023-28121-kdoec

CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ]

exploitationpenetration-testingprivilege-escalation+2
13 years ago
CVE-2021-31762 preview

CVE-2021-31762

GitHubmesh3l911/cve-2021-31762

Exploiting a Cross-site request forgery (CSRF) attack to creat a new privileged user through the Webmin's add users feature

command-and-controlexploitationpenetration-testing+3
15 years ago
CVE-2020-11651 preview

CVE-2020-11651

GitHubdrew-alleman/cve-2020-11651

A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd…

authenticationcommand-and-controlexploitation+3
11 year ago
CVE-2021-1675-CVE-2021-34527 preview

CVE-2021-1675-CVE-2021-34527

GitHubwhoami-chmod777/cve-2021-1675-cve-2021-34527

PowerShell exploit for PrintNightmare (CVE-2021-1675) performing local privilege escalation via Print Spooler, with custom DLL payload injection to…

binary-exploitationexploitationpayload-development+2
12 years ago
CVE-2021-34527 preview

CVE-2021-34527

GitHubcyb3rpeace/cve-2021-34527

PowerShell local privilege escalation exploit for PrintNightmare (CVE-2021-34527) targeting Windows Print Spooler. Embeds custom DLL payload to add…

binary-exploitationexploitationpayload-generation+4
14 years ago
CVE-2014-3704 preview

CVE-2014-3704

GitHubjoaomorenorf/cve-2014-3704

This code is taken from "Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)" and was converted to Python 3 to suit the exercise in…

educationexploitationlabs-practice+2
11 year ago
CVE-2020-23586 preview

CVE-2020-23586

GitHubhuzaifahussain98/cve-2020-23586

CSRF allows to Add Network Traffic Control Type Rule

exploitationmisconfigurationpenetration-testing+3
13 years ago
CVE-2020-6287-Sap-Add-User preview

CVE-2020-6287-Sap-Add-User

GitHubynsmroztas/cve-2020-6287-sap-add-user

sap netweaver portal add user administrator

exploitationinformation-gatheringpenetration-testing+2
16 years ago
CVE-2017-12542 preview

CVE-2017-12542

GitHubvijayshankar22/cve-2017-12542

This script checks if an HP iLO server is vulnerable and can add an admin user

authenticationexploitationpenetration-testing+2
11 months ago
CVE-2023-26982 preview

CVE-2023-26982

GitHubbypazs/cve-2023-26982

Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket…

exploitationpenetration-testingvulnerability-analysis+2
3 years ago
CVE-2021-32160 preview

CVE-2021-32160

GitHubmesh3l911/cve-2021-32160

Exploiting a Reflected Cross-Site Scripting (XSS) attack to create a privileged user through the Webmin's add users feature then getting a reverse…

exploitationpayload-developmentpenetration-testing+3
5 years ago
MAL-005 preview

MAL-005

GitHubmbadanoiu/mal-005

MAL-005: Zip Slip in Add Carbon Applications in WSO2 ESB

exploitationpenetration-testingvulnerability-analysis+1
2 years ago
CVE-2021-29441 preview

CVE-2021-29441

GitHubazhao1981/cve-2021-29441

Exploit for CVE-2021-29441 targeting Alibaba Nacos to add unauthorized accounts, enabling authentication bypass and unauthorized access.

authenticationexploitationpenetration-testing+2
1 year ago
Previous1234567Next