Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
103 results
CVE-2021-3560-Polkit-Privilege-Esclation preview

CVE-2021-3560-Polkit-Privilege-Esclation

GitHubsecnigma/cve-2021-3560-polkit-privilege-esclation

Automated Bash PoC for CVE-2021-3560 polkit privilege escalation. Exploits dbus timing attack to inject a sudo user and gain root shell on vulnerable…

authenticationexploitationpenetration-testing+2
126
3 years ago
ShimMe preview

ShimMe

GitHubdeepinstinct/shimme

PoC for Windows privilege escalation and code injection using OfficeClickToRun RPC and undocumented shim manipulation to inject DLLs into SYSTEM…

adversarial-attackexploitationpost-exploitation+2
1461 year ago
CVE-2017-5638 preview

CVE-2017-5638

GitHubpayatu/cve-2017-5638

Apache Struts 2.0 RCE vulnerability - Allows an attacker to inject OS commands into a web application through the content-type header

command-and-controlexploitationpenetration-testing+3
89 years ago
dirtypipe preview

dirtypipe

GitHubdrapl0n/dirtypipe

DirtyPipe: Exploit for a new Linux vulnerability known as 'Dirty Pipe(CVE-2022-0847)' allows local users to gain root privileges. The vulnerability…

binary-exploitationexploitationpayload-generation+4
74 years ago
cve-2025-66398 preview

cve-2025-66398

GitHubshowy-headteacher114/cve-2025-66398

Demonstrate exploitation of Signal K Server CVE-2025-66398 allowing unauthenticated attackers to inject backdoor and enable remote code execution.

exploitationpayload-developmentpenetration-testing+3
15 days ago
-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server preview

-CVE-2024-21683-RCE-in-Confluence-Data-Center-and-Server

GitHubr00t7oo2jm/-cve-2024-21683-rce-in-confluence-data-center-and-server

This vulnerability allows an unauthenticated attacker to remotely execute arbitrary code on a vulnerable Confluence server. The vulnerability exists…

exploitationpayload-developmentpenetration-testing+3
22 years ago
CVE-2025-44148 preview

CVE-2025-44148

GitHubbarisbaydur/cve-2025-44148

A reflected cross-site scripting (XSS) vulnerability exists in MailEnable Webmail due to improper user input sanitization in the failure.aspx. This…

exploitationpenetration-testingvulnerability-analysis+2
31 year ago
CVE-2025-63498 preview

CVE-2025-63498

GitHubxryptoh/cve-2025-63498

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

exploitationpenetration-testingvulnerability-analysis+2
210 months ago
CVE-2022-0847-container-escape preview

CVE-2022-0847-container-escape

GitHubjlsakuya/cve-2022-0847-container-escape

A simple exploit that uses dirtypipe to inject shellcode into runC entrypoint to implement container escapes.

container-escapeexploitationpayload-generation+3
23 years ago
Flowise-CVE-2026-58057-exploit preview

Flowise-CVE-2026-58057-exploit

GitHubcerberusmrxi/flowise-cve-2026-58057-exploit

Flowise Windows RCE exploit for CVE-2026-58057. Bypasses environment variable validation via case-sensitive flaw. Uses node_options to inject…

command-and-controlexploitationinformation-gathering+7
12 months ago
BlueDucky preview

BlueDucky

GitHubsergeb250/blueducky

BlueDucky exploits a Bluetooth vulnerability, specifically CVE-2023-45866, which allows an attacker to inject keystrokes into a target device. The…

bluetooth-securityexploitationpayload-generation+3
21 year ago
CVE-2021-45416 preview

CVE-2021-45416

GitHub86x/cve-2021-45416

Reflected Cross-site scripting (XSS) vulnerability in RosarioSIS 8.2.1 allows attackers to inject arbitrary HTML via the search_term parameter in the…

exploitationpenetration-testingvulnerability-analysis+2
24 years ago
CVE-2026-2600-POC preview

CVE-2026-2600-POC

GitHubfolks-iwd/cve-2026-2600-poc

Proof-of-concept exploit for CVE-2026-2600, a stored XSS in ElementsKit Elementor Addons <= 3.7.9, allowing authenticated Contributors to inject…

exploitationpenetration-testingvulnerability-analysis+2
15 months ago
CVE-2026-42167-PoC preview

CVE-2026-42167-PoC

GitHubjimmexploit/cve-2026-42167-poc

Functional SQL injection exploit for CVE-2026-42167 in ProFTPD mod_sql, enabling unauthenticated attackers to inject commands via USER parameter.…

exploitationpenetration-testingred-teaming+2
14 months ago
CVE-2023-46998 preview

CVE-2023-46998

GitHubsoy-oreocato/cve-2023-46998

Proof-of-concept exploit for a stored/reflected Cross-Site Scripting (XSS) vulnerability in Bootbox.js versions 3.2 through 6.0, allowing remote…

exploitationpenetration-testingvulnerability-analysis+2
12 years ago
jsPDF-Object-Injection preview

jsPDF-Object-Injection

GitHubabsholi7ly/jspdf-object-injection

CVE-2026-25755 A critical PDF Object Injection vulnerability in jsPDF allows attackers to inject arbitrary PDF objects through the addJS() function,…

exploitationpayload-developmentvulnerability-analysis+1
17 months ago
CVE-2019-19369 preview

CVE-2019-19369

GitHubthecybergeek/cve-2019-19369

Authenticated remote code execution exploit for FusionPBX versions <= 4.5.10, leveraging the PHP-Editor function to inject a payload and gain a shell…

exploitationpayload-generationpenetration-testing+3
15 years ago
CVE-2023-6000-POC preview

CVE-2023-6000-POC

GitHubronf98/cve-2023-6000-poc

This vulnerability displays an XSS flaw in a WordPress popup plugin, allowing attackers to inject malicious JavaScript through a stored XSS

exploitationpayload-developmentpenetration-testing+3
11 year ago
Previous123456Next