Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
83 results
CVE-2018-13379-FortinetVPN preview

CVE-2018-13379-FortinetVPN

GitHubpwn3z/cve-2018-13379-fortinetvpn

Exploit for CVE-2018-13379: unauthenticated path traversal in Fortinet FortiOS SSL VPN portal allowing system file download via crafted HTTP requests.

exploitationinformation-gatheringpenetration-testing+2
1
5 years ago
CVE-2024-24919-POC preview

CVE-2024-24919-POC

GitHubseed1337/cve-2024-24919-poc

Proof-of-concept exploit for CVE-2024-24919, an unauthenticated arbitrary file read vulnerability in Check Point SSL VPN appliances. Includes Nuclei…

educationexploitationpenetration-testing+2
472 years ago
CVE-2024-9474 preview

CVE-2024-9474

GitHubk4nfr3/cve-2024-9474

Python exploit script for CVE-2024-9474 targeting PAN-OS SSL VPN, enabling remote code execution and reverse shell deployment for penetration testing.

exploitationpayload-generationpenetration-testing+3
101 year ago
ivantiunlocker preview

ivantiunlocker

GitHubvinylrider/ivantiunlocker

Prevent CVE-2025-22457 and other security problems with Juniper/Ivanti Secure Connect SSL VPN

authenticationids-ips-evasionnetwork-security+2
21 year ago
poodle-PoC preview

poodle-PoC

GitHubmpgn/poodle-poc

:poodle: Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566 :poodle:

cryptographyeducationencryption-decryption-tools+4
2673 years ago
CVE-2024-21762 preview

CVE-2024-21762

GitHub0x13-bytezer0/cve-2024-21762

Detects and exploits CVE-2024-21762 pre-authentication RCE in FortiGate SSL VPN, featuring baseline validation, automatic exploitation, ROP…

exploitationpayload-generationpenetration-testing+4
8 months ago
CVE-2024-0012-POC preview

CVE-2024-0012-POC

GitHubsachinart/cve-2024-0012-poc

CVE-2024-0012 PAN-OS: Authentication Bypass in the Management Web Interface (PAN-SA-2024-0015) RCE POC

authentication-authorizationexploitationpenetration-testing+3
211 year ago
CVE-2019-11510_poc preview

CVE-2019-11510_poc

GitHubes0/cve-2019-11510_poc

PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability

exploitationinformation-gatheringpenetration-testing+2
57 years ago
CVE-2018-13379-Fortinet preview

CVE-2018-13379-Fortinet

GitHubk4nfr3/cve-2018-13379-fortinet

Exploit for CVE-2018-13379 targeting Fortinet SSL VPN path traversal vulnerability. Enables automated exploitation and credential extraction for…

exploitationinformation-gatheringpenetration-testing+2
65 years ago
Netgear-ssl-vpn-20211222-CVE-2022-29383 preview

Netgear-ssl-vpn-20211222-CVE-2022-29383

GitHubbadboycxcc/netgear-ssl-vpn-20211222-cve-2022-29383

SQL injection exploit for CVE-2022-29383 in NETGEAR ProSafe SSL VPN, targeting scgi-bin/platform.cgi with sqlmap commands for FVS336Gv2 and FVS336Gv3…

exploitationnetwork-securitypenetration-testing+3
254 years ago
CVE-2014-3566-poodle-cookbook preview

CVE-2014-3566-poodle-cookbook

GitHubmikesplain/cve-2014-3566-poodle-cookbook

Chef cookbook that detects and fails runs on servers vulnerable to CVE-2014-3566 (POODLE) by scanning specified SSL ports, serving as both a security…

configuration-auditingdevsecopseducation+2
311 years ago
CVE-2024-21762-Safe-Check preview

CVE-2024-21762-Safe-Check

GitHubsxmpl3/cve-2024-21762-safe-check

Safe, non-intrusive scanner that detects FortiOS SSL VPN out-of-bounds write vulnerability (CVE-2024-21762) by comparing normal and chunked HTTP POST…

exploitationinformation-gatheringnetwork-security+3
3 months ago
CVE-2024-10924-Bypass-MFA-Wordpress-LAB preview

CVE-2024-10924-Bypass-MFA-Wordpress-LAB

GitHubd1se0/cve-2024-10924-bypass-mfa-wordpress-lab

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

authenticationctfeducation+5
41 year ago
CVE-2024-27956-RCE-File-Package preview

CVE-2024-27956-RCE-File-Package

GitHubw3bw/cve-2024-27956-rce-file-package

Exploit scripts and scanner for CVE-2024-27956, a WordPress plugin vulnerability, including a modified exploit with SSL verification bypass.

exploitationpayload-generationpenetration-testing+3
2 years ago
fortiscan preview

fortiscan

GitHubanasbousselham/fortiscan

A high performance FortiGate SSL-VPN vulnerability scanning and exploitation tool.

exploitationpenetration-testingvulnerability-analysis+1
1603 years ago
Fortigate-SSL-VPN-Exploit-Kit preview

Fortigate-SSL-VPN-Exploit-Kit

GitHubabraxas/fortigate-ssl-vpn-exploit-kit

The FortiGate SSL-VPN pot of gold. CVE-2024-21762 and CVE-2023-27997. 79 working exploit clients. 53 hardware SKUs. 55 FortiOS builds.

command-and-controldata-exfiltrationexploitation+7
127 days ago
CVE-2021-3560 preview

CVE-2021-3560

GitHubneonwhiterabbit/cve-2021-3560

One-command Polkit privilege escalation exploit for CVE-2021-3560, creating a passwordless user and switching to root on vulnerable Linux systems.

exploitationpenetration-testingprivilege-escalation+2
34 years ago
patch-CVE-2026-12087 preview

patch-CVE-2026-12087

GitHubgduma-phdata/patch-cve-2026-12087

Patch for CVE-2026-12087, a critical heap overflow in Fortinet FortiOS SSL-VPN, deployed to production and validated by SecOps.

defensive-toolsincident-responsenetwork-security+1
1 month ago
Previous12345Next