Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
Fortigate-SSL-VPN-Exploit-Kit preview

Fortigate-SSL-VPN-Exploit-Kit

GitHubabraxas/fortigate-ssl-vpn-exploit-kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

command-and-controldata-exfiltrationexploitation+7
127 days ago
cve-2022-42475-poc preview

cve-2022-42475-poc

GitHubull0a/cve-2022-42475-poc

Proof of Concept (PoC) for research and controlled laboratory validation of CVE-2022-42475, a critical heap-based buffer overflow vulnerability…

exploitationpenetration-testingred-teaming+3
11 month ago
FUCK-CDN preview

FUCK-CDN

GitHub0xshe/fuck-cdn

Automated CDN origin-IP discovery skill for Claude Code that runs 40+ prioritized OSINT methods, cross-validates candidates via SSL and HTTP…

dns-analysisdns-subdomain-enumerationinformation-gathering+9
1012 months ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
92 months ago
ezXSS preview

ezXSS

GitHubssl/ezxss

Blind XSS detection and exploitation platform with persistent sessions, reverse proxy, and automated information gathering for penetration testers…

information-gatheringpayload-generationpenetration-testing+2
2.3k2 months ago
Multi-threaded-mass-exploiter-CVE-2018-13379-POC preview

Multi-threaded-mass-exploiter-CVE-2018-13379-POC

GitHubinstructor-admin/multi-threaded-mass-exploiter-cve-2018-13379-poc

CVE-2018-13379 mass exploiter for Fortinet FortiOS SSL VPN. Extracts credentials instantly, saves to CSV + PostgreSQL. Multi-threaded, no bullshit…

exploitationinformation-gatheringpassword-attacks+4
14 months ago
CVE-2022-42475-POC preview

CVE-2022-42475-POC

GitHubarthurhendrich/cve-2022-42475-poc

Exploit for CVE-2022-42475, a pre-auth RCE in FortiOS SSL VPN. Supports validation, benign verification, and full exploitation with connect-back…

exploitationpayload-developmentpenetration-testing+4
7 months ago
NachoVPN preview

NachoVPN

GitHubamberwolfcyber/nachovpn

A delicious, but malicious SSL-VPN server 🌮

adversarial-attackexploitationnetwork-security+5
2687 months ago
CVE-2025-1910-WatchGuard-Privilege-Escalation preview

CVE-2025-1910-WatchGuard-Privilege-Escalation

GitHublutrasecurity/cve-2025-1910-watchguard-privilege-escalation

Proof-of-Concept for exploiting CVE-2025-1910, a local privilege escalation within Watchguard's Mobile VPN with SSL client.

command-and-controlexploitationlateral-movement+6
8 months ago
CVE-2024-21762 preview

CVE-2024-21762

GitHub0x13-bytezer0/cve-2024-21762

Detects and exploits CVE-2024-21762 pre-authentication RCE in FortiGate SSL VPN, featuring baseline validation, automatic exploitation, ROP…

exploitationpayload-generationpenetration-testing+4
8 months ago
sslsplit preview

sslsplit

GitHubdroe/sslsplit

Transparent man-in-the-middle proxy that terminates SSL/TLS connections, forges certificates on-the-fly, and logs decrypted traffic for network…

encryption-decryption-toolsforensicsids-ips-evasion+5
1.9k11 months ago
CVE-2025-36041 preview
Archived

CVE-2025-36041

GitHubbytereaper77/cve-2025-36041

Exploit (C) of the CVE-2025-36041 vulnerability in IBM MQ

exploitationnetwork-securitypenetration-testing+3
21 year ago
CVE-2024-21762_FortiNet_PoC preview

CVE-2024-21762_FortiNet_PoC

GitHubabrewer251/cve-2024-21762_fortinet_poc

Proof-of-concept scanner targeting CVE-2024-21762 in FortiOS SSL VPN’s /remote/hostcheck_validate endpoint with reverse shell payload delivery.

exploitationpayload-generationpenetration-testing+3
41 year ago
cve-2024-21762-poc preview

cve-2024-21762-poc

GitHubcrackercat/cve-2024-21762-poc

CVE-2024-21762 是 Fortinet 公司的 FortiOS 和 FortiProxy 产品中的一个严重漏洞,存在于其 SSL VPN 组件中。

exploitationpenetration-testingred-teaming+2
1 year ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubk4nfr3/cve-2024-9474

Python exploit script for CVE-2024-9474 targeting PAN-OS SSL VPN, enabling remote code execution and reverse shell deployment for penetration testing.

exploitationpayload-generationpenetration-testing+3
101 year ago
CVE-2024-0012-POC preview

CVE-2024-0012-POC

GitHubsachinart/cve-2024-0012-poc

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

authentication-authorizationexploitationpenetration-testing+3
211 year ago
CVE-2024-23113 preview

CVE-2024-23113

GitHubp33d/cve-2024-23113

Python script to detect CVE-2024-23113, a format string vulnerability in FortiGate FGFM service on TCP/541, using SSL connection and crafted payload…

exploitationnetwork-securitypenetration-testing+3
111 year ago
CVE-2024-27956-RCE-File-Package preview

CVE-2024-27956-RCE-File-Package

GitHubw3bw/cve-2024-27956-rce-file-package

Exploit scripts and scanner for CVE-2024-27956, a WordPress plugin vulnerability, including a modified exploit with SSL verification bypass.

exploitationpayload-generationpenetration-testing+3
2 years ago
Previous12Next