Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
34 results
CVE-2025-58434-AND-59528-POC preview

CVE-2025-58434-AND-59528-POC

GitHubkartik2005221/cve-2025-58434-and-59528-poc

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

authenticationeducationexploitation+5
18
5 months ago
CVE-2026-80099 preview

CVE-2026-80099

GitHubwayang1337/cve-2026-80099

Newfold plugins (wp-module-data <= 2.9.7) Unauthenticated

exploitationinformation-gatheringpassword-attacks+7
120 days ago
fortipwn preview

fortipwn

GitHubxtwip/fortipwn

Forti CVE-2022-40684 enumeration script built in Rust

authentication-authorizationexploitationpenetration-testing+2
43 years ago
MetabaseRCE_CVE-2023-38646 preview

MetabaseRCE_CVE-2023-38646

GitHubshisones/metabaserce_cve-2023-38646

Proof-of-concept exploit for Metabase pre-auth RCE (CVE-2023-38646) that retrieves setup token and executes arbitrary commands via base64-encoded…

exploitationpenetration-testingred-teaming+3
2 years ago
cve-2023-46747 preview

cve-2023-46747

GitHubvidura2/cve-2023-46747

Exploit script for CVE-2023-46747 (F5 BIG-IP TMUI RCE) enabling unauthenticated user creation, token retrieval, and remote command execution on…

exploitationpenetration-testingred-teaming+3
21 year ago
CVE-2026-25253 preview

CVE-2026-25253

GitHubyym8538/cve-2026-25253

Proof-of-concept exploit for CVE-2026-25253 in OpenClaw: a crafted gatewayUrl exfiltrates the Control UI gateway token, enabling unauthorized gateway…

authenticationdata-exfiltrationexploitation+6
11 month ago
CVE-2025-69516 preview

CVE-2025-69516

GitHubsniss/cve-2025-69516

Automated Python exploit for CVE-2025-69516, an SSTI vulnerability in Tactical RMM, enabling remote code execution with a session token.

educationexploitationpenetration-testing+3
6 months ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubhhesenjan/cve-2023-42793

Python exploit for CVE-2023-42793 that achieves remote code execution on TeamCity Linux servers by encoding a payload in a URL and sending it to the…

exploitationpenetration-testingremote-access-tool+2
12 years ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1186 years ago
openvpn preview

openvpn

GitHubopenvpn/openvpn

Secure tunneling daemon implementing VPN protocols with TLS encryption, certificate authentication, and routing/firewall configuration for private…

authentication-authorizationcryptographynetwork-security+2
14.6k4 days ago
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE preview

CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE

GitHubjakabakos/cve-2023-27524-apache-superset-auth-bypass-and-rce

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

authentication-authorizationcommand-and-controldatabase-security+5
283 years ago
dlink-dir610-exploits preview

dlink-dir610-exploits

GitHubrenatoalencar/dlink-dir610-exploits

Exploits for CVE-2020-9376 and CVE-2020-9377

authentication-authorizationexploitationremote-access-tool+2
46 years ago
CVE-2026-15013 preview

CVE-2026-15013

GitHubzer0dayf/cve-2026-15013

Exploit for CVE-2026-15013: unauthenticated SAML auth bypass via algorithm confusion. Forges SAML responses to gain admin access and deploy…

authentication-authorizationpayload-generationpenetration-testing+6
12 months ago
CVE-2025-58434_CVE-2025-59528 preview

CVE-2025-58434_CVE-2025-59528

GitHubhonney336/cve-2025-58434_cve-2025-59528

CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

authenticationexploitationpenetration-testing+3
5 months ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubdezso-dfield/cve-2023-27350

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

authentication-authorizationcommand-and-controlexploitation+4
9 months ago
CVE-2018-10933_ssh preview

CVE-2018-10933_ssh

GitHublikekabin/cve-2018-10933_ssh

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

authentication-authorizationexploitationpenetration-testing+3
7 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubomnigodz/cve-2022-1388

This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)

authentication-authorizationexploitationpenetration-testing+2
4 years ago
remote-control preview

remote-control

GitHubkatsana/remote-control

Grant remote access to user account without sharing credentials

authentication-authorizationidentity-access-managementremote-access-tool+2
91 year ago
Previous12Next