Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
421 results
CVE-2025-69212-Exploit preview

CVE-2025-69212-Exploit

GitHubpasindu-sd/cve-2025-69212-exploit

Automated exploit for CVE-2025-69212 command injection in OpenSTAManager, featuring admin authentication, malicious ZIP upload, and reverse shell or…

command-and-controlexploitationpayload-development+2
12 days ago
CVE-2026-73847-emlog-PoC preview

CVE-2026-73847-emlog-PoC

GitHubsqueeze440/cve-2026-73847-emlog-poc

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

exploitationpenetration-testingvulnerability-analysis+2
15 days ago
CVE-2025-34077 preview

CVE-2025-34077

GitHubmrjhaxcore/cve-2025-34077

WordPress Pie Register ≤ 3.7.1.4 - Admin Privilege Escalation (Unauthenticated)

authentication-authorizationexploitationpenetration-testing+3
61 year ago
CVE-2022-0441 preview

CVE-2022-0441

GitHubbiulove0x/cve-2022-0441

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

authenticationexploitationpenetration-testing+2
64 years ago
CVE-2023-41362_MyBB_ACP_RCE preview

CVE-2023-41362_MyBB_ACP_RCE

GitHubsorceryie/cve-2023-41362_mybb_acp_rce

Exploit for CVE-2023-41362, a remote code execution vulnerability in MyBB Admin Control Panel, allowing authenticated attackers to execute arbitrary…

exploitationpenetration-testingred-teaming+2
72 years ago
CVE-2024-4040-CrushFTP-File-Read-vulnerability preview

CVE-2024-4040-CrushFTP-File-Read-vulnerability

GitHubjakabakos/cve-2024-4040-crushftp-file-read-vulnerability

Python exploit script for CVE-2024-4040 CrushFTP file read vulnerability with file reading, admin session token retrieval, and vulnerability check…

educationexploitationinformation-gathering+3
42 years ago
CVE-2021-37580 preview

CVE-2021-37580

GitHubrabbitsafe/cve-2021-37580

Proof-of-concept exploit for Apache ShenYu Admin JWT authentication bypass (CVE-2021-37580). Includes a scanning script to detect vulnerable…

api-securityauthentication-authorizationexploitation+3
44 years ago
CVE-2026-29000-PoC-Exploit preview

CVE-2026-29000-PoC-Exploit

GitHubtc4dy/cve-2026-29000-poc-exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

authentication-authorizationeducationexploitation+6
32 months ago
CVE-2020-25790 preview

CVE-2020-25790

GitHub7mitu/cve-2020-25790

Dockerized Typesetter CMS environment reproducing CVE-2020-25790 file upload vulnerability, with default admin credentials and a walkthrough for…

educationexploitationlabs-practice+2
53 years ago
CVE-2026-10288-AUTH-BYPASS preview

CVE-2026-10288-AUTH-BYPASS

GitHubxmyronn/cve-2026-10288-auth-bypass

Proof-of-concept exploit for an authentication bypass in Hotel and Tourism Reservation System 1.0, allowing unauthenticated admin access via inverted…

authenticationexploitationpenetration-testing+3
2 months ago
CVE-2026-54807 preview

CVE-2026-54807

GitHubizxci/cve-2026-54807

Proof-of-concept exploit for CVE-2026-54807 demonstrating unauthenticated privilege escalation via WooCommerce registration form, enabling admin role…

exploitationpenetration-testingprivilege-escalation+2
2 months ago
CVE-2026-61343-poc-librebooking-rce preview

CVE-2026-61343-poc-librebooking-rce

GitHubnmagill123/cve-2026-61343-poc-librebooking-rce

Librebooking Admin RCE PoC CVE-2026-61343

exploitationpayload-generationpenetration-testing+2
1 month ago
CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction preview

CVE-2024-1698-NotificationX-WordPress-Plugin-SQL-Injection-to-Admin-Credential-Extraction

GitHubdhananjayasj/cve-2024-1698-notificationx-wordpress-plugin-sql-injection-to-admin-credential-extraction

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

exploitationinformation-gatheringpassword-cracking+3
3 months ago
CVE-2026-67206 preview

CVE-2026-67206

GitHubanirbala98/cve-2026-67206

PoC exploit for Wolf CMS <= 0.8.3.1: authenticates to Admin, writes an arbitrary PHP file to /public via FileManagerController, and executes commands…

educationexploitationpayload-development+3
113 days ago
CVE-2023-25690 preview

CVE-2023-25690

GitHubthanhlam-attt/cve-2023-25690

Proof-of-concept exploit for CVE-2023-25690 HTTP Request Smuggling in Apache mod_proxy. Includes lab environment with Docker, BurpSuite walkthrough,…

educationexploitationpenetration-testing+3
42 years ago
CVE-2024-6043 preview

CVE-2024-6043

GitHublfillaz/cve-2024-6043

Automated SQL injection exploit for CVE-2024-6043 targeting SourceCodester Best House Rental Management System. Detects vulnerable endpoint and…

educationexploitationpenetration-testing+2
42 years ago
tplink-CVE-2017-11519 preview

tplink-CVE-2017-11519

GitHubvakzz/tplink-cve-2017-11519

POC for TP-Link Archer C9 - Admin Password Reset and RCE (CVE-2017-11519)

exploitationiot-securitypenetration-testing+3
48 years ago
CVE-2024-7313 preview

CVE-2024-7313

GitHubwayne-ker/cve-2024-7313

Custom Proof-of-Concept on XSS to Unauthorized Admin Account Creation via WordPress Plugin Shield Security < 20.0.6

educationexploitationpayload-generation+3
32 years ago
Previous1…345…24Next