Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
488 results
PoCs preview

PoCs

GitHubvictorbonato/pocs

Proof-of-concept exploits for CVE-2026-56197 demonstrating remote code execution in Windows Admin Center, implemented in Python for vulnerability…

exploitationvulnerability-analysisweb-application-exploitation
316 days ago
halo-cors-csrf-CVE-2026-67921 preview

halo-cors-csrf-CVE-2026-67921

GitHubunpredictable21/halo-cors-csrf-cve-2026-67921

Proof-of-concept demonstrating a combined CORS misconfiguration and CSRF protection bypass in Halo CMS, enabling cross-site request forgery attacks…

exploitationvulnerability-analysisweb-application-exploitation+1
23 days ago
CVE-2022-24112-POC preview

CVE-2022-24112-POC

GitHubkavishkagihan/cve-2022-24112-poc

Apache APISIX 2.12.1 Remote Code Execution by IP restriction bypass and using default admin AIP token

api-security-testingexploitationmisconfiguration+3
24 years ago
Apache-APISIX-CVE-2022-24112 preview

Apache-APISIX-CVE-2022-24112

GitHubm4xsec/apache-apisix-cve-2022-24112

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit

api-securityapi-security-testingexploitation+3
154 years ago
CVE-2026-70376 preview

CVE-2026-70376

GitHubilhomjonr/cve-2026-70376

Advisory and Python PoC for Pluck CMS CSRF: fail-open Referer check plus double-extension upload enables webshell deployment and remote code…

educationexploitationpenetration-testing+3
21 days ago
e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout preview

e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

GitHubhunt-benito/e-is-for-exploit-cve-2026-17543-php-pgsql-sql-injection-backslash-breakout

PoC exploit for CVE-2026-17543: SQL injection in PHP ext/pgsql via backslash breakout, with data exfiltration and admin privilege-escalation payloads…

database-securityeducationexploitation+4
127 days ago
CVE-2024-31114 preview

CVE-2024-31114

GitHubnxploited/cve-2024-31114

Shortcode Addons <= 3.2.5 - Authenticated (Admin+) Arbitrary File Upload

exploitationpayload-generationpenetration-testing+3
1 year ago
watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py preview

watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py

GitHubwatchtowrlabs/watchtowr-vs-cpanel-whm-authbypass-to-rce.py

Detection artifact generator that verifies cPanel/WHM authentication bypass (CVE-2026-41940) and demonstrates RCE via CRLF injection, targeting WHM…

exploitationinformation-gatheringpenetration-testing+3
4314 months ago
proxylogscan preview

proxylogscan

GitHubdwisiswant0/proxylogscan

A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as…

exploitationinformation-gatheringpenetration-testing+3
1654 years ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubjweny/cve-2022-23131

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

exploitationpenetration-testingred-teaming+2
954 years ago
CVE-2023-28121 preview

CVE-2023-28121

GitHubgbrsh/cve-2023-28121

WooCommerce Payments: Unauthorized Admin Access Exploit

educationexploitationpenetration-testing+2
413 years ago
CVE-2023-3460 preview

CVE-2023-3460

GitHubgbrsh/cve-2023-3460

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in Ultimate Member WordPress plugin versions below 2.6.7. Intended for…

educationexploitationpenetration-testing+2
353 years ago
ProxyLogon preview

ProxyLogon

GitHubrickgeex/proxylogon

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

authenticationeducationexploitation+3
335 years ago
CVE-2024-3656 preview

CVE-2024-3656

GitHubh4x0r-dz/cve-2024-3656

Keycloak admin API allows low privilege users to use administrative functions

authentication-authorizationexploitationmisconfiguration+3
311 year ago
confluence-hack preview

confluence-hack

GitHubaiex-3/confluence-hack

Exploit for CVE-2023-22515 in Atlassian Confluence that creates a new admin user and deploys a web-based shell plugin for command execution on the…

educationexploitationpenetration-testing+3
522 years ago
CVE-2024-6670 preview

CVE-2024-6670

GitHubsinsinology/cve-2024-6670

Proof-of-concept exploit for Progress WhatsUp Gold SQL injection authentication bypass (CVE-2024-6670). Includes root cause analysis and automated…

authentication-authorizationexploitationpenetration-testing+2
352 years ago
CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE preview

CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE

GitHubzerozenxlabs/cve-2026-20127---cisco-sd-wan-preauth-rce

Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

exploitationpost-exploitationprivilege-escalation+2
306 months ago
RCity-CVE-2024-27198 preview

RCity-CVE-2024-27198

GitHubstuub/rcity-cve-2024-27198

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

authentication-authorizationeducationexploitation+4
352 years ago
Previous12…28Next