Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
86 results
CVE-2025-63498 preview

CVE-2025-63498

GitHubxryptoh/cve-2025-63498

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

exploitationpenetration-testingvulnerability-analysis+2
2
10 months ago
cve-2022-23131 preview

cve-2022-23131

GitHubwr0x00/cve-2022-23131

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Generates a signed session cookie to gain unauthorized admin access.

authenticationexploitationpenetration-testing+2
13 years ago
FallingSkies-CVE-2023-35885 preview

FallingSkies-CVE-2023-35885

GitHubdatackmy/fallingskies-cve-2023-35885

Python exploit for CVE-2023-35885 targeting CloudPanel v2.0.0–v2.3.0. Injects a webshell via a crafted serialized cookie to achieve remote code…

educationexploitationpayload-generation+3
553 years ago
CVE-2025-2825 preview

CVE-2025-2825

GitHubwooooong/cve-2025-2825

Exploit script for CrushFTP authentication bypass (CVE-2025-2825) using crafted Authorization header and CrushAuth cookie to gain unauthorized access.

authentication-authorizationexploitationpenetration-testing+2
11 year ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
22 months ago
CVE-2026-0257-PoC preview

CVE-2026-0257-PoC

GitHubakashsingh0454/cve-2026-0257-poc

Passive, read-only remote detection tool for CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect. Fingerprints PAN-OS…

information-gatheringnetwork-securitypenetration-testing+3
23 months ago
grafana-CVE-2018-15727 preview

grafana-CVE-2018-15727

GitHubu238/grafana-cve-2018-15727

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

authenticationexploitationpenetration-testing+2
228 years ago
CVE-2026-7222-XSS preview

CVE-2026-7222-XSS

GitHubxmyronn/cve-2026-7222-xss

Proof-of-concept exploit for stored XSS (CWE-79) in a PHP coaching management system, demonstrating session hijacking and privilege escalation from…

educationexploitationpenetration-testing+3
4 months ago
POC-CVE-2014-0166 preview

POC-CVE-2014-0166

GitHubettack/poc-cve-2014-0166

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

exploitationpassword-attackspenetration-testing+2
512 years ago
laravel_cookie_killer preview

laravel_cookie_killer

GitHubsynacktiv/laravel_cookie_killer

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

encryption-decryption-toolsexploitationpayload-development+4
283 years ago
CVE-2025-45250 preview

CVE-2025-45250

GitHubxp3s/cve-2025-45250

CVE-2025-45250 POC

exploitationinformation-gatheringpenetration-testing+2
1 year ago
Zabbix-cve-2022-23131-SSO-bypass preview

Zabbix-cve-2022-23131-SSO-bypass

GitHubdagowda/zabbix-cve-2022-23131-sso-bypass

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2025-26244 preview

CVE-2025-26244

GitHubjarm222/cve-2025-26244

The graph functionality of DeimosC2 v1.1.0-Beta is vulnerable to Stored Cross-Site Scripting (XSS), allowing the theft of session cookie and…

command-and-controlexploitationpayload-development+4
1 year ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
2 months ago
CVE-2017-9822 preview

CVE-2017-9822

GitHubtranphuc2005/cve-2017-9822

Detailed analysis and proof-of-concept exploit for CVE-2017-9822, an XXE/insecure deserialization vulnerability in DotNetNuke CMS leading to remote…

binary-exploitationexploitationpayload-development+3
1 year ago
CVE-2025-10720-PoC preview

CVE-2025-10720-PoC

GitHublorenzocamilli/cve-2025-10720-poc

Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to…

authentication-authorizationexploitationpenetration-testing+3
3 months ago
Web-Penetration-Test preview

Web-Penetration-Test

GitHubsalimelh94/web-penetration-test

Exploiting WordPress vulnerabilities (CVE-2025-34077), authentication bypass via cookie injection, and privilege escalation to root. Part of my…

authenticationctfeducation+6
5 months ago
chromecookiestealer preview

chromecookiestealer

GitHubmagisterquis/chromecookiestealer

Steal/Inject Chrome cookies over the DevTools (--remote-debugging-port) protocol.

data-exfiltrationinformation-gatheringpenetration-testing+1
1153 years ago
Previous12345Next