Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
478 results
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
1
1 day ago
CVE-2025-0324-axis-vapix-privesc preview

CVE-2025-0324-axis-vapix-privesc

GitHubkemrec/cve-2025-0324-axis-vapix-privesc

Root-cause analysis and safety-gated verification tool for CVE-2025-0324, a privilege-escalation flaw in AXIS OS VAPIX allowing any authenticated…

binary-analysisexploitationfirmware-analysis+4
2 days ago
CitrixBleedCVE-2026-8452-2025-5777 preview

CitrixBleedCVE-2026-8452-2025-5777

GitHubmaxprog-svg/citrixbleedcve-2026-8452-2025-5777

CitrixBleed Exploit Tool - CVE-2025-5777 & CVE-2026-8452. Unauthenticated remote memory read from Citrix NetScaler ADC & Gateway. Steal admin session…

exploitationinformation-gatheringpenetration-testing+3
3 days ago
htb-labs-connected preview

htb-labs-connected

GitHubdiegorivas1/htb-labs-connected

Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege escalation to root via…

ctfeducationexploitation+7
5 days ago
CVE-2026-17532-lab preview

CVE-2026-17532-lab

GitHubkalhoralireza/cve-2026-17532-lab

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

educationexploitationlabs-practice+3
8 days ago
CVE-2020-1472 preview

CVE-2020-1472

GitHubckq7703/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that exploits a cryptographic flaw in Netlogon to escalate privileges to domain admin in Active Directory…

exploitationexploit-frameworkspenetration-testing+2
8 days ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubyasirr10/cve-2026-29000

Exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt allowing attackers to forge admin tokens using only the public key.

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2026-39324 preview

CVE-2026-39324

GitHubsm1ee/cve-2026-39324

Proof-of-concept exploit for Rack::Cookie authentication bypass (CVE-2026-39324), demonstrating session forgery via fallback coder to gain admin…

authentication-authorizationexploitationpenetration-testing+2
4 months ago
CVE-2025-57457 preview

CVE-2025-57457

GitHubrestdone/cve-2025-57457

Proof-of-concept for OS command injection in Curo UC300 IP phone admin panel, demonstrating arbitrary command execution via the IP Addr parameter.

command-and-controlexploitationpenetration-testing+2
10 months ago
CVE-2026-30081 preview

CVE-2026-30081

GitHubrakeshelamaran98/cve-2026-30081

Documentation of CVE-2026-30081, a high-severity cleartext transmission vulnerability in Quantum Networks QN-I-470 router firmware 6.1.1.B1, allowing…

exploitationinformation-gatheringnetwork-security+2
5 months ago
CVE-2026-20131-POC preview

CVE-2026-20131-POC

GitHubp3nt3st3r-star/cve-2026-20131-poc

Proof-of-concept exploit for CVE-2026-20131, a pre-authentication RCE in Cisco Catalyst SD-WAN Controller and Manager, enabling admin access and…

exploitationnetwork-securitypenetration-testing+3
5 months ago
CVE-2024-34102 preview

CVE-2024-34102

GitHubmksundaram69/cve-2024-34102

Proof-of-concept exploit for CVE-2024-34102, a critical XML entity injection in Magento, enabling exfiltration of sensitive files and unauthorized…

data-exfiltrationeducationexploitation+2
1 year ago
CVE-2026-29000---pac4j-jwt-Authentication-Bypass-PoC preview

CVE-2026-29000---pac4j-jwt-Authentication-Bypass-PoC

GitHubmanbahadurthapa1248/cve-2026-29000---pac4j-jwt-authentication-bypass-poc

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt. Forges JWT tokens to gain admin access to protected endpoints.

authentication-authorizationexploitationpenetration-testing+2
15 months ago
CVE-2026-36959 preview

CVE-2026-36959

GitHubkirubel-cve/cve-2026-36959

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

authenticationexploitationpenetration-testing+2
4 months ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubkaleth4/cve-2026-21858

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

authenticationexploitationpayload-development+4
4 months ago
CVE-2025-10352-POC preview

CVE-2025-10352-POC

GitHubivansmc/cve-2025-10352-poc

Exploit for CVE-2025-10352. Admin account creation on Melis Platform Framework

exploitationpenetration-testingred-teaming+2
110 months ago
CVE-2026-21994 preview

CVE-2026-21994

GitHubg0w6y/cve-2026-21994

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

authenticationcloud-securityexploitation+3
5 months ago
CVE-2026-30862 preview

CVE-2026-30862

GitHubdrkim-dev/cve-2026-30862

Proof-of-concept demonstrating stored XSS in Appsmith Table Widget leading to vertical privilege escalation and full admin takeover via XSS-to-CSRF…

exploitationpenetration-testingprivilege-escalation+4
24 months ago
Previous12…27Next