Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
CVE-2023-43804 preview

CVE-2023-43804

GitHubdeepanshu-khurana/cve-2023-43804

Containerized three-tier lab reproducing CVE-2023-43804 urllib3 cookie leak via cross-origin redirects, with exploit script and patch verification.

container-securitydefensive-toolseducation+5
3 days ago
linux-entra-sso-PoC preview

linux-entra-sso-PoC

GitHubsqueeze440/linux-entra-sso-poc

PoC — origin validation error enabling Entra ID PRT SSO cookie exfiltration in linux-entra-sso (GHSA-g9vc-5j77-f2cm, CVE-2026-87005, CVSS 5.3).

authenticationexploitationinformation-gathering+5
12 days ago
CVE-2026-52924 preview

CVE-2026-52924

GitHubeliot-code/cve-2026-52924

Technical analysis of CVE-2026-52924, a critical use-after-free in Linux kernel SCTP stale cookie handling, including root cause, attack flow, fix,…

binary-exploitationeducationexploitation+2
16 days ago
CVE-2026-75865 preview

CVE-2026-75865

GitHubghostpels/cve-2026-75865

Unauthenticated arbitrary file upload -> RCE in WPLP Cookie Consent (gdpr-cookie-consent) <= 4.4.1 - technical write-up and PoC

educationexploitationpenetration-testing+3
18 days ago
cve-2026-19900-PoC preview

cve-2026-19900-PoC

GitHubon3sk-0x1/cve-2026-19900-poc

Proof-of-concept exploit for CVE-2026-19900, an authentication bypass and remote code execution vulnerability in LB-LINK X-PRO routers, allowing…

authenticationexploitationiot-security+3
19 days ago
cve-2022-29117-assessment preview

cve-2022-29117-assessment

GitHubcharanmv08/cve-2022-29117-assessment

CVE-2022-29117 (.NET Cookie-Handling DoS) Assessment, Understanding & Questions Framework

curated-resourceseducationvulnerability-analysis+1
23 days ago
CVE-2026-74252 preview

CVE-2026-74252

GitHubtoanln-cov/cve-2026-74252

Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass

exploitationvulnerability-analysisweb-application-exploitation+1
1 month ago
CVE-2026-50522 preview

CVE-2026-50522

GitHub4minx/cve-2026-50522

CVE-2026-50522 PoC

exploitationpayload-generationpenetration-testing+4
421 month ago
CVE-2026-60206-PoC-Exploit preview

CVE-2026-60206-PoC-Exploit

GitHubtc4dy/cve-2026-60206-poc-exploit

👾 CVE-2026-60206 - Oracle WebLogic SAML Auth Bypass Exploit Framework ⚡Bash & Python versions. Features: --detect safe check, --exploit…

authentication-authorizationexploitationexploit-frameworks+8
42 months ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
2 months ago
cve-2026-23550-poc preview

cve-2026-23550-poc

GitHubbaktistr/cve-2026-23550-poc

Bash-based proof-of-concept tester for CVE-2026-23550. Checks WordPress modular connector login endpoints for admin cookie issuance and verifies…

exploitationinformation-gatheringpenetration-testing+3
2 months ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
22 months ago
CVE-2022-24706 preview

CVE-2022-24706

GitHubjunghyeonkum/cve-2022-24706

Proof-of-concept exploit for CVE-2022-24706 targeting Apache CouchDB 3.2.1 and below. Demonstrates remote command execution via Erlang Distribution…

database-securityeducationexploitation+3
2 months ago
CVE-2008-1930 preview

CVE-2008-1930

GitHubheisenbergh4x/cve-2008-1930

CVE-2008-1930 is a critical improper authentication vulnerability affecting the core cookie integrity mechanism in WordPress version 2.5. It allows…

educationexploitationinformation-gathering+5
3 months ago
CVE-2025-10720-PoC preview

CVE-2025-10720-PoC

GitHublorenzocamilli/cve-2025-10720-poc

Proof-of-concept exploit for an authentication bypass vulnerability (CWE-565) in WP Private Content Plus v3.6.2, allowing unauthenticated access to…

authentication-authorizationexploitationpenetration-testing+3
3 months ago
oxasploits preview

oxasploits

GitHuboxasploits/oxasploits

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

binary-exploitationbluetooth-securityexploitation+6
3 months ago
CVE-2026-0257-PoC preview

CVE-2026-0257-PoC

GitHubakashsingh0454/cve-2026-0257-poc

Passive, read-only remote detection tool for CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect. Fingerprints PAN-OS…

information-gatheringnetwork-securitypenetration-testing+3
23 months ago
CVE-2024-34568 preview

CVE-2024-34568

GitHubsanupl/cve-2024-34568

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

exploitationphishingvulnerability-analysis+2
14 months ago
Previous123456Next