Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
49 results
CVE-2025-48932-Invision-Community-SQLi-Exploit preview

CVE-2025-48932-Invision-Community-SQLi-Exploit

GitHubcerberusmrxi/cve-2025-48932-invision-community-sqli-exploit

Automated exploit for CVE-2025-48932, an unauthenticated blind SQLi in Invision Community <= 4.7.20, with database enumeration, credential dumping,…

data-exfiltrationexploitationinformation-gathering+6
1
22 days ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
2 months ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
3 months ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
2 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubshootcannon/cve-2026-5076

ARMember Premium <= 7.3.1 Full Admin Account Takeover

exploitationinformation-gatheringpassword-attacks+3
2 months ago
CVE-2026-27886-PoC-Account-Takeover preview

CVE-2026-27886-PoC-Account-Takeover

GitHubthesw0rd/cve-2026-27886-poc-account-takeover

Automated PoC exploit for CVE-2026-27886 in Strapi CMS. Performs email enumeration, password reset token exfiltration, and full admin account…

exploitationinformation-gatheringpassword-attacks+4
22 months ago
cve-2023-42820 preview

cve-2023-42820

GitHubstartr4ck/cve-2023-42820

Exploit for JumpServer CVE-2023-42820 that resets admin password and chains with CVE-2023-42819 to achieve remote code execution on affected versions.

exploitationpassword-attackspenetration-testing+3
22 years ago
CVE-2025-57819_FreePBX preview

CVE-2025-57819_FreePBX

GitHuborange0mint/cve-2025-57819_freepbx

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

educationexploitationinformation-gathering+4
211 months ago
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
25 years ago
CVE-2025-1738 preview

CVE-2025-1738

GitHubn0n4m3x41/cve-2025-1738

Proof-of-concept exploit for CVE-2025-1738 demonstrating cleartext admin password exposure in Trivision NC227WF cameras via unauthenticated local…

educationexploitationhardware-iot-security+3
4 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubxshadow-here/cve-2026-8181

Exploit tool for CVE-2026-8181 targeting Burst Statistics WordPress plugin. Automates authentication bypass, user enumeration, admin account…

authenticationexploitationinformation-gathering+6
13 months ago
CVE-2023-6329 preview

CVE-2023-6329

GitHubitzvenom/cve-2023-6329

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

authenticationeducationexploitation+4
15 months ago
CVE-2021-27651 preview

CVE-2021-27651

GitHuborangmuda/cve-2021-27651

Exploit for CVE-2021-27651: bypasses Pega Infinity password reset flow to reset any user's password, enabling admin login and subsequent remote code…

authenticationcode-analysisexploitation+3
14 years ago
CVE-2024-28000 preview

CVE-2024-28000

GitHubssssuperx/cve-2024-28000

Scans and exploits LiteSpeed Cache privilege escalation (CVE-2024-28000) by identifying vulnerable versions, leaking hashes via debug logs, and…

exploitationpassword-attacksprivilege-escalation+3
11 year ago
CVE-2024-29868 preview

CVE-2024-29868

GitHubdevisions/cve-2024-29868

Proof-of-concept exploit for CVE-2024-29868, demonstrating weak PRNG-based recovery token cracking to achieve admin account takeover in Apache…

cryptographyexploitationpassword-attacks+3
12 years ago
CVE-2023-6875 preview

CVE-2023-6875

GitHubhatlesswizard/cve-2023-6875

Go-based exploit for CVE-2023-6875 that intercepts admin password reset emails, logs in, and uploads a web shell to the target server.

exploitationpassword-attackspayload-generation+3
12 years ago
CVE-2020-2733 preview

CVE-2020-2733

GitHubanmolksachan/cve-2020-2733

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

encryption-decryption-toolsexploitationinformation-gathering+5
12 years ago
cve-2019-17240 preview

cve-2019-17240

GitHubspyx/cve-2019-17240

Go-based brute-force tool exploiting Bludit bruteforce mitigation bypass (CVE-2019-17240) for automated password cracking against admin login pages.

exploitationpassword-attackspenetration-testing+2
15 years ago
Previous123Next