Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
383 results
wordpress-skelersecurity-core-security-CVE-2026-63030 preview

wordpress-skelersecurity-core-security-CVE-2026-63030

GitHubskelersecurity/wordpress-skelersecurity-core-security-cve-2026-63030

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…

api-securityauthentication-authorizationdefensive-tools+3
1 month ago
roninforge-hono preview

roninforge-hono

GitHubroninforge/roninforge-hono

Cursor plugin for Hono v4 (TypeScript edge web framework). 59 LLM regressions with BAD/CORRECT pairs. Pinned to hono ^4.12.19 (>= 4.9.7 for…

api-securitycloud-securitycode-analysis+8
3 months ago
CVE-2026-5724 preview

CVE-2026-5724

GitHubtibrn/cve-2026-5724

Proof-of-concept exploit for CVE-2026-5724, an authentication bypass in Temporal's frontend gRPC service allowing unauthenticated access to workflow…

api-securityauthenticationexploitation+2
4 months ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubx48ps/cve-2026-8181

This vulnerability allows unauthenticated attackers who know a valid administrator username to impersonate that admin during REST API requests by…

api-securityauthenticationexploitation+3
3 months ago
Check Risk WAF preview

Check Risk WAF

GitLabcheck-risk-waf/check-risk-waf

Cloud-based Web Application Firewall (WAF) providing L3/L7 protection against SQLi, XSS, DDoS, and bot attacks. Features AI assistant, anti-bot…

anti-botapi-securitycloud-security+3
3 months ago
CVE-2026-28767 preview

CVE-2026-28767

GitHubmichaeladamgroberman/cve-2026-28767

CVE-2026-28767: Missing Authentication on Admin Notifications Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securitycloud-securityiot-security+3
3 months ago
CVE-2026-23745-via-graphql-DEMO preview

CVE-2026-23745-via-graphql-DEMO

GitHubnovem13th/cve-2026-23745-via-graphql-demo

Proof-of-concept exploit for CVE-2026-23745 targeting GraphQL endpoints, demonstrating the vulnerability and potential impact for security testing…

api-securityexploitationpenetration-testing+2
5 months ago
CVE-2024-46635 preview

CVE-2024-46635

GitHubh1thub/cve-2024-46635

Proof-of-concept for CVE-2024-46635: an improper input validation vulnerability in GongZhiDao System's API endpoint that exposes sensitive user…

api-securityinformation-gatheringmisconfiguration+3
11 year ago
CVE-2026-30945-PoC preview

CVE-2026-30945-PoC

GitHubfilipegaudard/cve-2026-30945-poc

Proof-of-concept exploit for CVE-2026-30945, an IDOR in StudioCMS allowing arbitrary API token revocation and denial of service. Includes manual and…

api-securityeducationexploitation+3
6 months ago
CVE-2025-55462 preview

CVE-2025-55462

GitHubsibikrish001/cve-2025-55462

Technical documentation and proof-of-concept for CVE-2025-55462, a CORS misconfiguration in Eramba v3.26.0 allowing cross-origin authentication…

api-securityauthenticationmisconfiguration+3
8 months ago
CVE-2022-4361 preview

CVE-2022-4361

GitHubfaccimatteo/cve-2022-4361

Proof-of-concept exploit for CVE-2022-4361, a reflected XSS vulnerability in Keycloak's OIDC authentication flow, with Docker-based test environment…

api-securityauthenticationexploitation+3
10 months ago
vert-x3__vertx-web_CVE-2018-12542_3-5-3-CR1 preview

vert-x3__vertx-web_CVE-2018-12542_3-5-3-CR1

GitHubshoucheng3/vert-x3__vertx-web_cve-2018-12542_3-5-3-cr1

Exploit for CVE-2018-12542 in Vert.x-Web, a Java web framework. Demonstrates a path traversal vulnerability allowing unauthorized access to static…

api-securityapi-security-testingpenetration-testing+3
1 year ago
spring-cloud__spring-cloud-gateway_CVE-2022-22947_3-0-6 preview

spring-cloud__spring-cloud-gateway_CVE-2022-22947_3-0-6

GitHubshoucheng3/spring-cloud__spring-cloud-gateway_cve-2022-22947_3-0-6

Spring Cloud Gateway repository demonstrating CVE-2022-22947 exploitation for API security testing and vulnerability analysis.

api-securityapi-security-testingexploitation+3
1 year ago
ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-23457_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-23457_2-2-3-1

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

api-securityauthentication-authorizationcode-analysis+6
1 year ago
ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1 preview

ESAPI__esapi-java-legacy_CVE-2022-24891_2-2-3-1

GitHubshoucheng3/esapi__esapi-java-legacy_cve-2022-24891_2-2-3-1

OWASP Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input…

api-securityauthentication-authorizationcode-analysis+5
1 year ago
SpringSource__spring-security-oauth_CVE-2018-1260_2-3-2-RELEASE preview

SpringSource__spring-security-oauth_CVE-2018-1260_2-3-2-RELEASE

GitHubshoucheng3/springsource__spring-security-oauth_cve-2018-1260_2-3-2-release

OAuth and OAuth2 support library for Spring Security, enabling secure API authentication and authorization for consumer and provider implementations…

api-securityauthentication-authorizationencryption-decryption-tools+3
1 year ago
apache__sling-org-apache-sling-xss_CVE-2016-5394_1-0-8 preview

apache__sling-org-apache-sling-xss_CVE-2016-5394_1-0-8

GitHubshoucheng3/apache__sling-org-apache-sling-xss_cve-2016-5394_1-0-8

Java library providing XSS escaping and filtering services (XSSAPI, XSSFilter) to sanitize user-submitted content and prevent cross-site scripting…

api-securitycode-analysisstatic-analysis+2
1 year ago
keycloak__keycloak_CVE-2022-4361_21-1-1 preview

keycloak__keycloak_CVE-2022-4361_21-1-1

GitHubshoucheng3/keycloak__keycloak_cve-2022-4361_21-1-1

Open source identity and access management solution providing single sign-on, user federation, and centralized authentication for modern applications…

api-securityauthentication-authorizationcloud-security+2
7 months ago
Previous1…345…22Next