Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
116 results
CVE-2023-38609 preview

CVE-2023-38609

GitHubmc-17/cve-2023-38609

SIP bypass using package scripts

exploitationpenetration-testingprivilege-escalation+2
32 years ago
Exploit-LPE-CVE-2026-21721 preview

Exploit-LPE-CVE-2026-21721

GitHubleonideath/exploit-lpe-cve-2026-21721

Proof-of-concept exploit for CVE-2026-21721 that escalates privileges to admin on affected dashboards, requiring a valid Editor account.

exploitationpenetration-testingprivilege-escalation+2
28 months ago
CVE-2026-5465 preview

CVE-2026-5465

GitHubkaleth4/cve-2026-5465

Exploit and analysis for CVE-2026-5465, an IDOR in Amelia WordPress plugin allowing authenticated Provider role to escalate privileges and achieve…

exploitationmisconfigurationpenetration-testing+4
6 months ago
CVE-2026-48172 preview

CVE-2026-48172

GitHubretmakarunia/cve-2026-48172

cPanel user run arbitrary scripts as root

exploitationpenetration-testingprivilege-escalation+2
4 months ago
CVE-2025-68723 preview

CVE-2025-68723

GitHubosmancanvural/cve-2025-68723

Axigen WebAdmin Stored XSS Vulnerabilities

exploitationpenetration-testingprivilege-escalation+3
8 months ago
CVE-2025-6934 preview

CVE-2025-6934

GitHubmrjhaxcore/cve-2025-6934

CVE-2025-6934 POC

exploitationpenetration-testingprivilege-escalation+3
11 year ago
CVE-2025-2304-POC preview

CVE-2025-2304-POC

GitHubinnocentx0/cve-2025-2304-poc

Manual poc for CVE-2025-2304

exploitationpenetration-testingprivilege-escalation+3
8 months ago
Session-Persistence-After-Enabling-2FA-CVE-2025-60425 preview

Session-Persistence-After-Enabling-2FA-CVE-2025-60425

GitHubaakashtyal/session-persistence-after-enabling-2fa-cve-2025-60425

Detailed vulnerability report on Nagios Fusion session persistence after enabling 2FA, including CVE-2025-60425, affected versions, mitigation…

authenticationexploitationpenetration-testing+3
11 months ago
CVE-2024-50476 preview

CVE-2024-50476

GitHubrandomrobbiebf/cve-2024-50476

GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2024-54239 preview

CVE-2024-54239

GitHubrandomrobbiebf/cve-2024-54239

Eyewear prescription form <= 4.0.18 - Missing Authorization to Unauthenticated Arbitrary Options Update

exploitationmisconfigurationprivilege-escalation+3
1 year ago
CVE-2024-57429 preview

CVE-2024-57429

GitHubahrixia/cve-2024-57429

CVE-2024-57429: PHPJabbers Cinema Booking System v2.0 is vulnerable to CSRF, allowing attackers to escalate privileges by forging requests on behalf…

exploitationpenetration-testingprivilege-escalation+3
1 year ago
CVE-2025-4162028 preview

CVE-2025-4162028

GitHubnotitssixtyn3in/cve-2025-4162028

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162028) in Copilot, enabling unauthorized account access via user ID…

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2025-4162026 preview

CVE-2025-4162026

GitHubnotitssixtyn3in/cve-2025-4162026

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162026) in Copilot, enabling unauthorized account access via user ID…

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2026-15989 preview

CVE-2026-15989

GitHubantid00t/cve-2026-15989

Python PoC scanner for CVE-2026-15989, exploiting unauthenticated role injection in WordPress Super Forms to create admin accounts and verify access.

exploitationpassword-attackspenetration-testing+6
13 days ago
JustTryHarder preview

JustTryHarder

GitHubsinfulz/justtryharder

Comprehensive penetration testing cheat sheet for PWK/OSCP exam preparation, covering privilege escalation, password cracking, payload generation,…

educationexploitationpassword-cracking+7
8393 months ago
poc_CVE-2018-1002105 preview

poc_CVE-2018-1002105

GitHubevict/poc_cve-2018-1002105

Proof-of-concept exploit for CVE-2018-1002105 targeting Kubernetes API server. Supports authenticated and unauthenticated privilege escalation to…

cloud-securitycontainer-securityexploitation+4
2237 years ago
openapi_security_scanner preview

openapi_security_scanner

GitHubngalongc/openapi_security_scanner

Automated authorization security scanner for OpenAPI-based APIs. Tests GET endpoints with multiple credential sets to detect privilege escalation and…

api-security-testingpenetration-testingvulnerability-scanners+1
1735 years ago
CVE-2026-12793 preview

CVE-2026-12793

GitHubmurrez/cve-2026-12793

Python PoC scanner and exploit for CVE-2026-12793, an unauthenticated privilege escalation in JetFormBuilder <=3.6.2 that creates WordPress admin…

exploitationinformation-gatheringpenetration-testing+7
520 days ago
Previous1234567Next