Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
461 results
keycloak__keycloak_CVE-2022-4137_20-0-3 preview

keycloak__keycloak_CVE-2022-4137_20-0-3

GitHubshoucheng3/keycloak__keycloak_cve-2022-4137_20-0-3

Open source identity and access management solution providing single sign-on, user federation, and centralized authentication for modern applications…

api-securityauthentication-authorizationcloud-security+3
7 months ago
rhuss__jolokia_CVE-2018-1000129_1-4-0 preview

rhuss__jolokia_CVE-2018-1000129_1-4-0

GitHubshoucheng3/rhuss__jolokia_cve-2018-1000129_1-4-0

Agent-based JMX access via JSON/HTTP with bulk requests, fine-grained security policies, and proxy mode for remote MBeanServer monitoring and…

api-securityconfiguration-auditingdynamic-analysis-sandboxing+2
10 months ago
westone-CVE-2021-45232-scanner preview

westone-CVE-2021-45232-scanner

GitHubosyanina/westone-cve-2021-45232-scanner

A vulnerability scanner that detects CVE-2021-45232 vulnerabilities.

api-securityexploitationpenetration-testing+2
4 years ago
westone-CVE-2021-37580-scanner preview

westone-CVE-2021-37580-scanner

GitHubosyanina/westone-cve-2021-37580-scanner

A vulnerability scanner that detects CVE-2021-37580 vulnerabilities.

api-securityauthenticationexploitation+2
4 years ago
CVE-2025-492030 preview

CVE-2025-492030

GitHubimthecopilotnow/cve-2025-492030

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

api-securityauthenticationexploitation+3
1 year ago
asf__cxf_CVE-2016-6812_3-0-11 preview

asf__cxf_CVE-2016-6812_3-0-11

GitHubshoucheng3/asf__cxf_cve-2016-6812_3-0-11

Open-source services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, JAX-WS, and JAX-RS APIs.

api-securityauthentication-authorizationcryptography+3
11 months ago
hapifhir__org_hl7_fhir_core_CVE-2023-28465_5-6-1055 preview

hapifhir__org_hl7_fhir_core_CVE-2023-28465_5-6-1055

GitHubshoucheng3/hapifhir__org_hl7_fhir_core_cve-2023-28465_5-6-1055

Java core library for FHIR specification with validator, version converters, and object models for R2 through R5, used in HAPI servers and HL7…

api-securitycode-analysiseducation+3
1 year ago
jenkinsci__script-security-plugin_CVE-2023-24422_1228.vd93135a_2fb_25 preview

jenkinsci__script-security-plugin_CVE-2023-24422_1228.vd93135a_2fb_25

GitHubshoucheng3/jenkinsci__script-security-plugin_cve-2023-24422_1228.vd93135a_2fb_25

Jenkins plugin providing script approval workflows and Groovy sandboxing to enforce secure script execution, with ACL-aware permission checks and…

api-securityauthentication-authorizationcode-analysis+5
7 months ago
CVE-2024-57972 preview

CVE-2024-57972

GitHubtania-silva/cve-2024-57972

Denial of Service exploit for Microsoft HoloLens Device Portal via repeated API pairing requests, causing CPU overload and system unresponsiveness.

api-securityexploitationhardware-iot-security+2
1 year ago
aws__aws-sdk-java_CVE-2022-31159_1-12-2600 preview

aws__aws-sdk-java_CVE-2022-31159_1-12-2600

GitHubshoucheng3/aws__aws-sdk-java_cve-2022-31159_1-12-2600

Java SDK for integrating with Amazon Web Services, providing secure API access to S3, DynamoDB, EC2, and more, with built-in authentication,…

api-securityauthentication-authorizationcloud-infrastructure-security+3
1 year ago
spring-cloud__spring-cloud-config_CVE-2020-5405_2-1-6-RELEASE preview

spring-cloud__spring-cloud-config_CVE-2020-5405_2-1-6-RELEASE

GitHubshoucheng3/spring-cloud__spring-cloud-config_cve-2020-5405_2-1-6-release

Centralized configuration server for distributed systems with HTTP API, encryption/decryption of properties, and support for Git, Vault, JDBC, and…

api-securityauthentication-authorizationcloud-security+3
1 year ago
CVE-2019-11287 preview

CVE-2019-11287

GitHubmbadanoiu/cve-2019-11287

CVE-2019-11287: DoS via Heap Overflow in RabbitMQ Web Management Plugin

api-securityexploitationvulnerability-analysis+1
1 year ago
apache__nifi_CVE-2022-33140_1-16-22 preview

apache__nifi_CVE-2022-33140_1-16-22

GitHubshoucheng3/apache__nifi_cve-2022-33140_1-16-22

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

api-securityauthentication-authorizationcloud-security+4
1 year ago
CVE-2021-37580 preview

CVE-2021-37580

GitHubwing-song/cve-2021-37580

Apache ShenYu 管理员认证绕过

api-securityauthentication-authorizationexploitation+2
4 years ago
SmartAsset-CORS-CVE-2020-26527 preview

SmartAsset-CORS-CVE-2020-26527

GitHublukaszstu/smartasset-cors-cve-2020-26527

Proof-of-concept for CVE-2020-26527: demonstrates a CORS misconfiguration in Damstra Smart Asset 2020.7 API that trusts arbitrary origins, allowing…

api-securitymisconfigurationpenetration-testing+2
5 years ago
CVE-2025-30144 preview

CVE-2025-30144

GitHubtibrn/cve-2025-30144

Proof-of-concept for CVE-2025-30144: JWT issuer validation bypass in fast-jwt library allowing attackers to forge tokens with array-based iss claims.

api-securityauthenticationexploitation+3
1 year ago
asf__nifi_CVE-2023-36542_1-22-0 preview

asf__nifi_CVE-2023-36542_1-22-0

GitHubshoucheng3/asf__nifi_cve-2023-36542_1-22-0

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

api-securityauthentication-authorizationcloud-security+4
1 year ago
SwaggerUI-CVE-2016-1000229 preview

SwaggerUI-CVE-2016-1000229

GitHubbarteeees/swaggerui-cve-2016-1000229

CVE-2016-1000229

api-securityexploitationpenetration-testing+2
11 months ago
Previous1…23242526Next