Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
478 results
CVE-2025-69212-for-myself preview

CVE-2025-69212-for-myself

GitHubliaomilk/cve-2025-69212-for-myself

just record for myself

exploitationpayload-generationpenetration-testing+2
15 days ago
CVE-2020-1956 preview

CVE-2020-1956

GitHubb510/cve-2020-1956

CVE-2020-1956

exploitationinformation-gatheringpenetration-testing+2
5 years ago
CVE-2019-16097 preview

CVE-2019-16097

GitHubeviladan0s/cve-2019-16097

Proof-of-concept exploit for CVE-2019-16097 in Harbor, enabling attacker admin account creation and malicious image upload. For authorized security…

exploitationpenetration-testingred-teaming+2
236 years ago
CVE-2025-2304-exploit preview

CVE-2025-2304-exploit

GitHubjeanback1/cve-2025-2304-exploit

Python exploit script for CVE-2025-2304, a mass assignment privilege escalation in Camaleon CMS. Automates CSRF token parsing and role parameter…

educationexploitationlabs-practice+5
4 months ago
WP-GDPR-Compliance-Plugin-Exploit preview

WP-GDPR-Compliance-Plugin-Exploit

GitHubaeroot/wp-gdpr-compliance-plugin-exploit

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…

exploitationpayload-generationpenetration-testing+3
47 years ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
3 months ago
CVE-2024-57429 preview

CVE-2024-57429

GitHubahrixia/cve-2024-57429

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2019-13633 preview

CVE-2019-13633

GitHubsecurity-avs/cve-2019-13633

Proof of concept for a blind/persistent XSS vulnerability in Blinger.io helpdesk, demonstrating remote code execution in admin panels via crafted…

information-gatheringpenetration-testingphishing+3
5 years ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubhughink/cve-2022-40684

PoC and exploit for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager management interfaces, enabling…

authentication-authorizationexploitationpenetration-testing+3
113 years ago
CVE-2020-14295 preview

CVE-2020-14295

GitHub0z09e/cve-2020-14295

Authenticated SQL injection to command execution on Cacti 1.2.12

exploitationpenetration-testingvulnerability-analysis+1
25 years ago
CVE-2023-0099-exploit preview

CVE-2023-0099-exploit

GitHubamirzargham/cve-2023-0099-exploit

simple urls < 115 - Reflected XSS

exploitationpayload-generationpenetration-testing+3
62 years ago
Vehicle-Service-Management-System-Multiple-Privilege-Escalation-Leads-to-CRUD-Operations preview

Vehicle-Service-Management-System-Multiple-Privilege-Escalation-Leads-to-CRUD-Operations

GitHubsanupl/vehicle-service-management-system-multiple-privilege-escalation-leads-to-crud-operations

CVE-2021-46075 - A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users can access…

exploitationmisconfigurationpenetration-testing+3
3 months ago
Mailcow-CVE-2022-31138 preview

Mailcow-CVE-2022-31138

GitHubly1g3/mailcow-cve-2022-31138

Proof-of-concept exploit for Mailcow CVE-2022-31138 enabling RCE via perl code injection in Sync Job regex fields, with privilege escalation to…

exploitationpayload-developmentpenetration-testing+3
24 years ago
xpl-ModernWMS-CVE-2024-57698 preview

xpl-ModernWMS-CVE-2024-57698

GitHubrodolfomarianocy/xpl-modernwms-cve-2024-57698

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

exploitationinformation-gatheringmisconfiguration+3
1 year ago
Mailcow-CVE-2022-31245 preview

Mailcow-CVE-2022-31245

GitHubly1g3/mailcow-cve-2022-31245

CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow

command-and-controlexploitationpenetration-testing+3
124 years ago
CVE-2024-21338-x64-build- preview

CVE-2024-21338-x64-build-

GitHubzombie-kaiser/cve-2024-21338-x64-build-

Local Privilege Escalation from Admin to Kernel vulnerability on Windows 10 and Windows 11 operating systems with HVCI enabled.

binary-exploitationexploitationprivilege-escalation+1
72 years ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubmmakingdom/cve-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

educationexploitationpenetration-testing+2
19 months ago
CrushFTP_CVE-2025-54309 preview

CrushFTP_CVE-2025-54309

GitHubchin-tech/crushftp_cve-2025-54309

Python exploit for CrushFTP CVE-2025-54309 XML race condition vulnerability. Creates admin user via concurrent requests with configurable payload…

exploitationpayload-developmentpenetration-testing+3
11 months ago
Previous12…27Next