Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
478 results
CVE-2023-22515 preview

CVE-2023-22515

GitHubdkq-k/cve-2023-22515

Detailed analysis and proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Atlassian Confluence Data Center…

educationexploitationpenetration-testing+3
7 months ago
CVE-2017-20192-formidable-forms preview

CVE-2017-20192-formidable-forms

GitHubflame-11/cve-2017-20192-formidable-forms

Reproducible Docker lab for CVE-2017-20192 (Formidable Forms < 2.05.03 stored XSS) with automated PoC script for unauthenticated exploitation and…

educationexploitationlabs-practice+3
8 months ago
Exploit-CSRF-on-SCOPIA-XT-Desktop-version-8.3.915.4 preview

Exploit-CSRF-on-SCOPIA-XT-Desktop-version-8.3.915.4

GitHubv1n1v131r4/exploit-csrf-on-scopia-xt-desktop-version-8.3.915.4

Proof of concept demonstrating Cross-Site Request Forgery (CSRF) on Avaya SCOPIA XT Desktop, allowing admin password change without anti-CSRF token.

exploitationpenetration-testingvulnerability-analysis+2
15 years ago
cve-2023-40000 preview

cve-2023-40000

GitHubiveresk/cve-2023-40000

Proof-of-concept exploit for CVE-2023-40000 targeting WordPress LiteSpeed Cache plugin versions < 5.7.0.1. Supports check and attack modes, with XSS…

exploitationpenetration-testingred-teaming+2
12 years ago
CVE-2025-60880 preview

CVE-2025-60880

GitHubshenal01/cve-2025-60880

Proof-of-concept for a stored XSS vulnerability in Bagisto admin panel, demonstrating SVG upload with malicious JavaScript and providing mitigation…

educationexploitationvulnerability-analysis+2
10 months ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubhossainshadat/cve-2025-63420

Proof-of-concept for CVE-2025-63420: stored HTML injection in CrushFTP Admin Panel Reports. Includes reproduction steps, CVSS scoring, and payload…

educationexploitationpenetration-testing+3
9 months ago
CVE-Newgen-Software-Advisories preview

CVE-Newgen-Software-Advisories

GitHubcbx216/cve-newgen-software-advisories

Advisory for CVE-2025-65742 — Newgen OmniDocs LDAP Admin BFLA

educationexploitationinformation-gathering+3
7 months ago
CVE-2023-38829-NETIS-WF2409E preview

CVE-2023-38829-NETIS-WF2409E

GitHubadhikara13/cve-2023-38829-netis-wf2409e

Proof-of-concept demonstrating command injection in NETIS WF2409E router's ping and traceroute functions, allowing arbitrary command execution via…

command-and-controleducationexploitation+3
13 years ago
CVE-2025-63420 preview

CVE-2025-63420

GitHubmmakingdom/cve-2025-63420

CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created Folder"), enabling persistent…

educationexploitationpenetration-testing+2
19 months ago
analyze-Exploit-CVE-2023-22518-Confluence preview

analyze-Exploit-CVE-2023-22518-Confluence

GitHubd3ckkno0b/analyze-exploit-cve-2023-22518-confluence

CVE-2023-22518 exploit analysis for Atlassian Confluence Server covering setup, JAR diffing, root cause, and unauthorized restore to regain admin…

code-analysisdebuggerseducation+4
11 year ago
Explotacion-CVE-2023-32315-Openfire preview

Explotacion-CVE-2023-32315-Openfire

GitHubpulentoski/explotacion-cve-2023-32315-openfire

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

authenticationexploitationpayload-generation+3
1 month ago
zabbix-cve-2022-23131 preview

zabbix-cve-2022-23131

GitHubfa1c0n35/zabbix-cve-2022-23131

Exploit for Zabbix SAML SSO bypass (CVE-2022-23131) enabling unauthorized admin access by forging session cookies.

authentication-authorizationexploitationpenetration-testing+2
14 years ago
CVE-2022-32199 preview

CVE-2022-32199

GitHubtoxich4/cve-2022-32199

Python exploit for CVE-2022-32199, enabling authenticated admin users to delete arbitrary files on ScriptCase <= 9.9.008 via directory traversal.

exploitationpenetration-testingred-teaming+2
13 years ago
CVE-2020-2733 preview

CVE-2020-2733

GitHubanmolksachan/cve-2020-2733

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

encryption-decryption-toolsexploitationinformation-gathering+5
12 years ago
CVE-2020-6287_SAP-NetWeaver-bypass-auth preview

CVE-2020-6287_SAP-NetWeaver-bypass-auth

GitHubdylvie/cve-2020-6287_sap-netweaver-bypass-auth

Automated exploit for CVE-2020-6287 targeting SAP NetWeaver AS JAVA authentication bypass. Creates admin users via LM Configuration Wizard.…

exploitationpenetration-testingreconnaissance+2
11 year ago
CVE-2024-0566 preview

CVE-2024-0566

GitHubxbz0n/cve-2024-0566

Proof-of-concept exploit for CVE-2024-0566, a post-authenticated time-based SQL injection in Smart Manager 8.27.0 WordPress plugin. Demonstrates…

exploitationpenetration-testingvulnerability-analysis+2
12 years ago
Exploit_CVE-2021-24762 preview

Exploit_CVE-2021-24762

GitHubc4cnm/exploit_cve-2021-24762

This repo shows an exploit to CVE-2021-24762. This is an Blind SQLi exploit that, on default config, greps the admin password.

exploitationpassword-crackingpenetration-testing+2
110 months ago
CVE-2024-0399 preview

CVE-2024-0399

GitHubxbz0n/cve-2024-0399

Proof-of-concept exploit for CVE-2024-0399, a post-authenticated time-based SQL injection in WooCommerce Customers Manager 29.4, targeting…

database-securityexploitationpenetration-testing+3
12 years ago
Previous1…91011…27Next