Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
27 results
CVE-2023-24329-Exploit preview

CVE-2023-24329-Exploit

GitHubpentestmano/cve-2023-24329-exploit

Proof-of-concept demonstrating a URL parsing bypass in Python's urllib.parse (CVE-2023-24329) that allows bypassing blocklists by prepending spaces.

exploitationpenetration-testingvulnerability-analysis+2
2 years ago
CVE-2022-25581 preview

CVE-2022-25581

GitHubwooluo/cve-2022-25581

Python exploit script for CVE-2022-25581 (ClassCMS 2.4 arbitrary file download) that automates login, CSRF token extraction, malicious zip upload…

educationexploitationpayload-development+3
1 year ago
CVE-2023-42222 preview

CVE-2023-42222

GitHubitssixtyn3in/cve-2023-42222

Proof-of-concept exploit for CVE-2023-42222 in WebCatalog, demonstrating arbitrary URL execution via Electron's shell.openExternal to bypass security…

educationexploitationpapers-research+2
32 years ago
CVE-2023-49103 preview

CVE-2023-49103

GitHubcreacitysec/cve-2023-49103

Multi-threaded Python PoC scanner for CVE-2023-49103 that checks large URL lists for exposed phpinfo() output with .htaccess bypass via /.css path…

educationexploitationpenetration-testing+2
302 years ago
CVE-2026-71518 preview

CVE-2026-71518

GitHubilhomjonr/cve-2026-71518

Advisory and PoC for an unauthenticated authorization bypass in Typemill media downloads, using path-equivalent URL variants to access…

authentication-authorizationexploitationpenetration-testing+3
115 days ago
CVE-2023-40037 preview

CVE-2023-40037

GitHubmbadanoiu/cve-2023-40037

CVE-2023-40037: Incomplete Validation of JDBC and JNDI Connection URLs in Apache NiFi

educationexploitationpenetration-testing+2
2 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubamitlttwo/cve-2022-1388

Python-based exploit for CVE-2022-1388, an F5 BIG-IP iControl REST authentication bypass leading to remote code execution. Supports single URL,…

command-and-controlexploitationpenetration-testing+3
13 years ago
CVE-2020-2733 preview

CVE-2020-2733

GitHubanmolksachan/cve-2020-2733

Exploit for CVE-2020-2733 in JD Edwards EnterpriseOne Tools, demonstrating unauthenticated admin password decryption and authentication bypass to…

encryption-decryption-toolsexploitationinformation-gathering+5
12 years ago
CVE-2026-25604-PoC preview

CVE-2026-25604-PoC

GitHubjohn-jung/cve-2026-25604-poc

A PoC for demonstrating CVE-2026-25604

authentication-authorizationcloud-securityeducation+4
4 months ago
F5-BIG-IP-exploit preview

F5-BIG-IP-exploit

GitHubsashka3076/f5-big-ip-exploit

CVE-2022-1388

command-and-controlexploitationremote-access-tool+2
4 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubhenry4e36/cve-2022-1388

F5 BIG-IP iControl REST身份验证绕过漏洞

authentication-authorizationexploitationpenetration-testing+2
84 years ago
CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection preview

CVE-2026-4444-JWT-Algorithm-Confusion-via-kid-Injection

GitHubgeorge0papasotiriou/cve-2026-4444-jwt-algorithm-confusion-via-kid-injection

POC for CVE-2026-4444 demonstrating JWT algorithm confusion via untrusted kid injection, including vulnerable Node.js server and Python exploit for…

api-securityauthentication-authorizationcryptography+4
1 month ago
CVE-2022-33174 preview

CVE-2022-33174

GitHubhenry4e36/cve-2022-33174

Powertek PDU身份绕过

authentication-authorizationexploitationpenetration-testing+2
44 years ago
CVE-2021-42013 preview

CVE-2021-42013

GitHubjoapath/cve-2021-42013

Proof-of-concept exploit for CVE-2021-42013, demonstrating path traversal and remote code execution on Apache 2.4.50 via double URL encoding bypass…

educationexploitationpayload-generation+3
2 months ago
CVE-2019-17662 preview

CVE-2019-17662

GitHubbl4ck574r/cve-2019-17662

Exploit for CVE-2019-17662, a path traversal vulnerability in ThinVNC, demonstrating URL normalization bypass to access arbitrary files on the target…

exploitationpenetration-testingreconnaissance+2
23 years ago
DrupalCVE-2018-7602 preview

DrupalCVE-2018-7602

GitHubcyberharsh/drupalcve-2018-7602

Exploit for Drupal CVE-2018-7602 remote code execution vulnerability via double URL encoding bypass of sanitize() filter. Includes Docker-based lab…

code-analysiseducationexploitation+3
16 years ago
CVE-2023-41080 preview
Archived

CVE-2023-41080

GitHubshiomiyan/cve-2023-41080

Proof-of-concept exploit for CVE-2023-41080, demonstrating URL validation bypass in Apache Tomcat to redirect users to arbitrary external sites via…

exploitationpenetration-testingvulnerability-analysis+2
113 years ago
CVE-2025-60423 preview

CVE-2025-60423

GitHubzephyr1ng/cve-2025-60423

Analyzes CVE-2025-60423, an authentication bypass in JEECG versions 7.2.8 and 7.2.9, detailing path traversal and URL encoding techniques to bypass…

exploitationpenetration-testingvulnerability-analysis+2
110 months ago
Previous12Next