Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
100 results
CVE-2023-22515 preview

CVE-2023-22515

GitHubdkq-k/cve-2023-22515

Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…

educationexploitationpenetration-testing+3
7 months ago
cve-2023-40000 preview

cve-2023-40000

GitHubiveresk/cve-2023-40000

Proof-of-concept exploit for CVE-2023-40000 targeting WordPress LiteSpeed Cache plugin versions < 5.7.0.1. Supports check and attack modes, with XSS…

exploitationpenetration-testingred-teaming+2
12 years ago
CVE-2022-32199 preview

CVE-2022-32199

GitHubtoxich4/cve-2022-32199

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

exploitationpenetration-testingred-teaming+2
13 years ago
CVE-2024-27956-RCE preview

CVE-2024-27956-RCE

GitHubcve-2024/cve-2024-27956-rce

Proof-of-concept exploit for CVE-2024-27956, a SQL injection in ValvePress Automatic WordPress plugin. Creates admin user and enables remote code…

exploitationpayload-developmentpenetration-testing+3
2 years ago
CrushFTP-auth-bypass-CVE-2025-31161 preview

CrushFTP-auth-bypass-CVE-2025-31161

GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

authentication-authorizationcommand-and-controlctf+7
11 months ago
CVE-2025-8359 preview

CVE-2025-8359

GitHubnxploited/cve-2025-8359

AdForest <= 6.0.9 - Authentication Bypass to Admin

authentication-authorizationexploitationpenetration-testing+2
11 months ago
CVE-2025-67070-Intelbras-CFTV-MFA-Bypass preview

CVE-2025-67070-Intelbras-CFTV-MFA-Bypass

GitHubteteco/cve-2025-67070-intelbras-cftv-mfa-bypass

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

authentication-authorizationexploitationpenetration-testing+3
7 months ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubovergrowncarrot1/cve-2021-22911

Python exploit script for CVE-2021-22911 targeting Rocket.Chat admin password reset via unauthenticated user registration. Automates exploitation…

exploitationpenetration-testingred-teaming+2
3 years ago
CVE-2020-24033 preview

CVE-2020-24033

GitHubm0nsterrr/cve-2020-24033

Proof-of-concept for CVE-2020-24033: Cross-Site Request Forgery on fs.com S3900 24T4S switch allows unauthenticated admin account creation via…

educationexploitationpenetration-testing+3
5 years ago
Zabbix-cve-2022-23131-SSO-bypass preview

Zabbix-cve-2022-23131-SSO-bypass

GitHubdagowda/zabbix-cve-2022-23131-sso-bypass

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2018-15365 preview

CVE-2018-15365

GitHubnixwizard/cve-2018-15365

Proof-of-concept exploit for reflected XSS in Trend Micro Deep Discovery Inspector 3.8, enabling CSRF bypass and admin account takeover via…

exploitationpenetration-testingred-teaming+2
7 years ago
CitrixBleedCVE-2026-8452-2025-5777 preview

CitrixBleedCVE-2026-8452-2025-5777

GitHubmaxprog-svg/citrixbleedcve-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

exploitationinformation-gatheringpenetration-testing+3
3 days ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubkaleth4/cve-2026-21858

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

authenticationexploitationpayload-development+4
4 months ago
CVE-2023-42793_POC preview

CVE-2023-42793_POC

GitHubjohnossawy/cve-2023-42793_poc

Automated exploit script for CVE-2023-42793 targeting TeamCity, enabling token manipulation and admin user creation for penetration testing.

exploitationpenetration-testingred-teaming+2
2 years ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubalhakim88/cve-2026-21858

Automated exploit chain for n8n combining arbitrary file read, admin token forgery, and sandbox bypass to achieve unauthenticated remote code…

exploitationpayload-developmentpenetration-testing+4
7 months ago
CVE-2026-20131-POC preview

CVE-2026-20131-POC

GitHubp3nt3st3r-star/cve-2026-20131-poc

Proof-of-concept exploit for CVE-2026-20131, a pre-authentication RCE in Cisco Catalyst SD-WAN Controller and Manager, enabling admin access and…

exploitationnetwork-securitypenetration-testing+3
5 months ago
CVE-2026-30862 preview

CVE-2026-30862

GitHubdrkim-dev/cve-2026-30862

Proof-of-concept demonstrating stored XSS in Appsmith Table Widget leading to vertical privilege escalation and full admin takeover via XSS-to-CSRF…

exploitationpenetration-testingprivilege-escalation+4
24 months ago
Zabbix-CVE-2024-42327-SQL-Injection-RCE preview

Zabbix-CVE-2024-42327-SQL-Injection-RCE

GitHubbridgeralderson/zabbix-cve-2024-42327-sql-injection-rce

Exploits Zabbix SQL injection (CVE-2024-42327) to extract admin session and execute commands via API, achieving reverse shell.

exploitationpenetration-testingred-teaming+2
481 year ago
Previous123456Next