Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
73 results
CVE-2026-37749 preview

CVE-2026-37749

GitHubmenevarad007/cve-2026-37749

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

authenticationexploitationvulnerability-analysis+2
1
5 months ago
CVE-2026-18963-Exploit preview

CVE-2026-18963-Exploit

GitHubsnizi/cve-2026-18963-exploit

Exploit for Keycloak CVE-2026-18963 enabling unauthenticated account takeover via reset-credentials bypass. Includes safe detection, non-destructive…

authentication-authorizationexploitationpenetration-testing+2
4127 days ago
CVE-2017-8225-EXPLOIT preview

CVE-2017-8225-EXPLOIT

GitHubk3ystr0k3r/cve-2017-8225-exploit

A PoC exploit for CVE-2017-8225 - GoAhead System.ini Leak

exploitationinformation-gatheringiot-security+3
93 years ago
CVE-2019-9053-exploit preview

CVE-2019-9053-exploit

GitHubjeanback1/cve-2019-9053-exploit

Automated exploit for CVE-2019-9053, a time-based blind SQL injection in CMS Made Simple ≤2.2.9. Extracts admin credentials (username, email,…

exploitationinformation-gatheringpassword-cracking+3
3 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubx48ps/cve-2026-8181

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

api-securityauthenticationexploitation+3
3 months ago
CVE-2023-31719 preview

CVE-2023-31719

GitHubmateustesser/cve-2023-31719

Proof-of-concept exploit for CVE-2023-31719, demonstrating SQL injection in the FUXA web application's /api/signin endpoint via a crafted JSON…

api-security-testingdatabase-securityexploitation+3
2 years ago
CVE-2023-3897 preview

CVE-2023-3897

GitHubjfriedli/cve-2023-3897

Exploit for CVE-2023-3897 enabling username enumeration via CAPTCHA bypass in On-premise SureMDM on Windows. Includes PoC script for local user…

captcha-bypassexploitationinformation-gathering+3
2 years ago
wpbf preview

wpbf

GitHubatarantini/wpbf

Remotely test password strength of WordPress bloging software

information-gatheringpassword-attackspenetration-testing+3
10710 years ago
JoomlaCVE20168869 preview

JoomlaCVE20168869

GitHubrustyj4ck/joomlacve20168869

Exploit for Joomla 3.4.4 - 3.6.4 (CVE-2016-8869 and CVE-2016-8870)

exploitationpayload-generationpenetration-testing+2
79 years ago
CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053- preview

CMS-Made-Simple-2.2.9-Unauthenticated-SQL-Injection-Exploit-CVE-2019-9053-

GitHubhf3cyber/cms-made-simple-2.2.9-unauthenticated-sql-injection-exploit-cve-2019-9053-

Time-based blind SQL injection exploit for CMS Made Simple <= 2.2.9 (CVE-2019-9053) that extracts username, email, password hash, and salt, with…

exploitationinformation-gatheringpassword-cracking+3
1 year ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubjenderal92/cve-2026-8181

CVE-2026-8181: Burst Statistics Auth Bypass → REST API takeover & admin creation. Python 2.7. Educational use only.

authenticationeducationexploitation+3
3 months ago
CVE-2017-14980.RCE preview
Archived

CVE-2017-14980.RCE

GitHubdamariion/cve-2017-14980.rce

Buffer overflow in Sync Breeze Enterprise 10.0.28 allows remote attackers to have unspecified impact via a long username parameter to /login

binary-exploitationexploitationpayload-development+2
6 months ago
Splunk-RCE-poc preview

Splunk-RCE-poc

GitHubnathan31337/splunk-rce-poc

Python-based PoC for CVE-2023-46214 that exploits Splunk's adddatamethods feature to achieve remote code execution via a reverse shell.

educationexploitationpayload-generation+4
1142 years ago
CVE-2024-32113-POC preview

CVE-2024-32113-POC

GitHubracerz-fighting/cve-2024-32113-poc

Apache OfBiz vulns

authenticationexploitationpayload-generation+3
72 years ago
CVE-2026-8794 preview

CVE-2026-8794

GitHubh4zaz/cve-2026-8794

Username Enumeration via Authentication Timing Side-Channel in PaperCut NG

authenticationinformation-gatheringpenetration-testing+4
1 month ago
oracle-oam-authentication-bypas-exploit preview

oracle-oam-authentication-bypas-exploit

GitHubaymanelsherif/oracle-oam-authentication-bypas-exploit

Exploit for Oracle Access Manager padding oracle vulnerability (CVE-2018-2879)

authentication-authorizationcryptographyexploitation+3
77 years ago
exploit-CVE-2024-25723 preview

exploit-CVE-2024-25723

GitHubdavid-botelho-mariano/exploit-cve-2024-25723

Educational Proof of Concept exploit for CVE-2024-25723, demonstrating unauthorized account takeover in ZenML via API password reset, with version…

educationexploitationpassword-attacks+3
42 years ago
CVE-2026-11387 preview

CVE-2026-11387

GitHub1beelze/cve-2026-11387

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

authenticationexploitationpassword-attacks+4
12 months ago
Previous12345Next