Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
478 results
CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE preview

CVE-2026-20127---Cisco-SD-WAN-Preauth-RCE

GitHubzerozenxlabs/cve-2026-20127---cisco-sd-wan-preauth-rce

Proof-of-concept exploit for CVE-2026-20127, a pre-auth RCE in Cisco SD-WAN Manager/Controller enabling admin access and network configuration…

exploitationpost-exploitationprivilege-escalation+2
30
6 months ago
RCity-CVE-2024-27198 preview

RCity-CVE-2024-27198

GitHubstuub/rcity-cve-2024-27198

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

authentication-authorizationeducationexploitation+4
352 years ago
CVE-2019-16097 preview

CVE-2019-16097

GitHubeviladan0s/cve-2019-16097

Proof-of-concept exploit for CVE-2019-16097 in Harbor, enabling attacker admin account creation and malicious image upload. For authorized security…

exploitationpenetration-testingred-teaming+2
236 years ago
Moodle-CVE-2019-3810 preview

Moodle-CVE-2019-3810

GitHubfarisv/moodle-cve-2019-3810

Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)

educationexploitationpenetration-testing+3
175 years ago
CVE-2021-26121 preview

CVE-2021-26121

GitHubsourceincite/cve-2021-26121

Proof-of-concept exploit for CVE-2021-26121: Server-Side Template Injection in CS-Cart <=4.12.x allowing shop admin to achieve remote code execution…

code-analysiseducationexploitation+3
125 years ago
CVE-2026-26980-Ghost-CMS-Api preview

CVE-2026-26980-Ghost-CMS-Api

GitHubgagaltotal/cve-2026-26980-ghost-cms-api

Go-based PoC for Ghost CMS Content API SQL injection (CVE-2026-26980). Verifies vulnerability, extracts admin credentials and API secrets, and…

exploitationinformation-gatheringpenetration-testing+2
112 months ago
CVE-2020-23839 preview

CVE-2020-23839

GitHubboku7/cve-2020-23839

Public PoC Disclosure for CVE-2020-23839 - GetSimple CMS v3.3.16 suffers from a Reflected XSS on the Admin Login Portal

exploitationpayload-developmentpenetration-testing+3
115 years ago
Mailcow-CVE-2022-31245 preview

Mailcow-CVE-2022-31245

GitHubly1g3/mailcow-cve-2022-31245

CVE-2022-31245: RCE and domain admin privilege escalation for Mailcow

command-and-controlexploitationpenetration-testing+3
124 years ago
CVE-2021-36394 preview

CVE-2021-36394

GitHubdinhbaouit/cve-2021-36394

Proof-of-concept exploit for CVE-2021-36394 in Moodle, enabling admin password takeover and remote code execution via custom PHP functions.

exploitationpassword-attackspenetration-testing+3
135 years ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubhughink/cve-2022-40684

PoC and exploit for CVE-2022-40684, an authentication bypass in Fortinet FortiOS, FortiProxy, and FortiSwitchManager management interfaces, enabling…

authentication-authorizationexploitationpenetration-testing+3
113 years ago
FreePBX-CVE-2025-57819-RCE preview

FreePBX-CVE-2025-57819-RCE

GitHub0xehab/freepbx-cve-2025-57819-rce

Unauthenticated SQL injection and arbitrary file upload exploit chain for FreePBX 16, achieving remote code execution via admin creation and webshell…

exploitationpenetration-testingred-teaming+2
132 months ago
CVE-2023-46818 preview

CVE-2023-46818

GitHubhunntr/cve-2023-46818

An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if…

code-analysisexploitationpenetration-testing+2
161 year ago
sophucked preview

sophucked

GitHubdarrenmartyn/sophucked

Proof-of-concept exploit for CVE-2020-25223 (Sophos UTM web admin pre-auth RCE) that delivers a reverse shell. Includes post-exploitation notes and…

exploitationpenetration-testingred-teaming+3
114 years ago
0-click-RCE-Exploit-for-CVE-2024-10924 preview

0-click-RCE-Exploit-for-CVE-2024-10924

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-10924

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

authenticationexploitationpayload-development+4
147 months ago
CVE-2023-22515-POC preview

CVE-2023-22515-POC

GitHubj3seer/cve-2023-22515-poc

Proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Confluence Server and Data Center, enabling…

exploitationinformation-gatheringpenetration-testing+3
82 years ago
Mass-CVE-2023-28121 preview

Mass-CVE-2023-28121

GitHubim-hanzou/mass-cve-2023-28121

CVE-2023-28121 - WooCommerce Payments < 5.6.2 - Unauthenticated Privilege Escalation [ Mass Add Admin User ]

exploitationpenetration-testingprivilege-escalation+2
113 years ago
CVE-2022-1421 preview

CVE-2022-1421

GitHubnb1b3k/cve-2022-1421

Proof-of-concept exploit for CVE-2022-1421, a CSRF vulnerability in Discy WordPress theme allowing admin settings modification via crafted AJAX…

educationexploitationpenetration-testing+2
73 years ago
CVE-2025-2304-POC preview

CVE-2025-2304-POC

GitHubwhiteov3rflow/cve-2025-2304-poc

Proof-of-concept exploit for CVE-2025-2304, a mass assignment vulnerability in Camaleon CMS < 2.9.1 allowing authenticated privilege escalation to…

exploitationpenetration-testingprivilege-escalation+3
117 months ago
Previous123…27Next