Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
116 results
CVE-2024-34568 preview

CVE-2024-34568

GitHubsanupl/cve-2024-34568

In LetterPress plugin <= 1.2.1 is vulnerable to Cookie Stealing Vulnerability. An attacker can able to steal the cookies by injecting the JavaScript…

exploitationphishingvulnerability-analysis+2
1
4 months ago
cloudscraper preview

cloudscraper

GitHubvenomous/cloudscraper

A Python module to bypass Cloudflare's anti-bot page.

anti-botcaptcha-bypasscrawler+4
6.7k1 year ago
CVE-2026-74252 preview

CVE-2026-74252

GitHubtoanln-cov/cve-2026-74252

Stored XSS in J2Commerce Guest Checkout via Cookie Filter Bypass

exploitationvulnerability-analysisweb-application-exploitation+1
19 days ago
CVE-2025-63498 preview

CVE-2025-63498

GitHubxryptoh/cve-2025-63498

Stored XSS proof-of-concept for SOGo groupware, exploiting the 'Remember Username' cookie to inject JavaScript payloads via the login endpoint.

exploitationpenetration-testingvulnerability-analysis+2
29 months ago
cve-2022-23131 preview

cve-2022-23131

GitHubwr0x00/cve-2022-23131

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Generates a signed session cookie to gain unauthorized admin access.

authenticationexploitationpenetration-testing+2
13 years ago
FallingSkies-CVE-2023-35885 preview

FallingSkies-CVE-2023-35885

GitHubdatackmy/fallingskies-cve-2023-35885

Python exploit for CVE-2023-35885 targeting CloudPanel v2.0.0–v2.3.0. Injects a webshell via a crafted serialized cookie to achieve remote code…

educationexploitationpayload-generation+3
553 years ago
CVE-2025-2825 preview

CVE-2025-2825

GitHubwooooong/cve-2025-2825

Exploit script for CrushFTP authentication bypass (CVE-2025-2825) using crafted Authorization header and CrushAuth cookie to gain unauthorized access.

authentication-authorizationexploitationpenetration-testing+2
11 year ago
oxasploits preview

oxasploits

GitHuboxasploits/oxasploits

A number of exploits and tools I've written for CVEs accredited to Marshall Whittaker/oxagast

binary-exploitationbluetooth-securityexploitation+6
3 months ago
cve-2018-9995 preview

cve-2018-9995

GitHubdearpan/cve-2018-9995

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

exploitationiot-securitypassword-attacks+2
4 years ago
CVE-2026-48909-Joomla-SP-Exploit preview

CVE-2026-48909-Joomla-SP-Exploit

GitHubcerberusmrxi/cve-2026-48909-joomla-sp-exploit

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

code-analysiscommand-and-controleducation+8
21 month ago
CVE-2026-0257-PoC preview

CVE-2026-0257-PoC

GitHubakashsingh0454/cve-2026-0257-poc

Passive, read-only remote detection tool for CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect. Fingerprints PAN-OS…

information-gatheringnetwork-securitypenetration-testing+3
23 months ago
grafana-CVE-2018-15727 preview

grafana-CVE-2018-15727

GitHubu238/grafana-cve-2018-15727

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

authenticationexploitationpenetration-testing+2
228 years ago
CVE-2026-7222-XSS preview

CVE-2026-7222-XSS

GitHubxmyronn/cve-2026-7222-xss

Proof-of-concept exploit for stored XSS (CWE-79) in a PHP coaching management system, demonstrating session hijacking and privilege escalation from…

educationexploitationpenetration-testing+3
4 months ago
POC-CVE-2014-0166 preview

POC-CVE-2014-0166

GitHubettack/poc-cve-2014-0166

POC of CVE-2014-0166 (WordPress cookie forgery vulnerability)

exploitationpassword-attackspenetration-testing+2
512 years ago
CVE-2025-45250 preview

CVE-2025-45250

GitHubanike-x/cve-2025-45250

Proof-of-concept exploit for CVE-2025-45250, an SSRF vulnerability in MrDoc's validate_url function, allowing authenticated attackers to make…

exploitationinformation-gatheringreconnaissance+2
1 year ago
laravel_cookie_killer preview

laravel_cookie_killer

GitHubsynacktiv/laravel_cookie_killer

Decrypt and re-encrypt Laravel session cookies to exploit insecure PHP deserialization for remote code execution.

encryption-decryption-toolsexploitationpayload-development+4
283 years ago
CVE-2025-45250 preview

CVE-2025-45250

GitHubxp3s/cve-2025-45250

CVE-2025-45250 POC

exploitationinformation-gatheringpenetration-testing+2
1 year ago
Zabbix-cve-2022-23131-SSO-bypass preview

Zabbix-cve-2022-23131-SSO-bypass

GitHubdagowda/zabbix-cve-2022-23131-sso-bypass

Exploit script for CVE-2022-23131 that bypasses Zabbix SSO authentication by forging JWT tokens, enabling unauthorized admin access to the monitoring…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
Previous1234567Next