Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
145 results
CVE-2025-53640 preview

CVE-2025-53640

GitHubrafaelcorvino1/cve-2025-53640

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

api-security-testinginformation-gatheringosint+3
1
7 months ago
CVE-2024-11972-POC preview

CVE-2024-11972-POC

GitHubronf98/cve-2024-11972-poc

CVE-2024-11972 in Hunk Companion <1.9.0 allows unauthenticated attackers to exploit insecure REST API endpoints and install vulnerable plugins,…

api-security-testingcode-analysisexploitation+3
11 year ago
CVE-2024-9707 preview

CVE-2024-9707

GitHubrandomrobbiebf/cve-2024-9707

Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation

api-security-testingexploitationpenetration-testing+3
11 year ago
CVE-2025-61148 preview

CVE-2025-61148

GitHubsharma19d/cve-2025-61148

The vulnerability exists in the Student Payment API. The application fails to properly validate whether the user requesting a receipt is authorized…

api-security-testingeducationinformation-gathering+3
8 months ago
CVE-2025-12720 preview

CVE-2025-12720

GitHubd0n601/cve-2025-12720

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

api-security-testingauthenticationexploitation+3
9 months ago
CVE-2025-55817 preview

CVE-2025-55817

GitHub5qu1n7/cve-2025-55817

ChilliCream Nitro GraphQL version 28.0.13 is vulnerable to multiple Stored Cross Site Scripting (XSS) Vulnerabilities

api-securityapi-security-testingvulnerability-analysis+2
11 months ago
CVE-2023-45857-Demo preview

CVE-2023-45857-Demo

GitHubfuyuooumi1027/cve-2023-45857-demo

Interactive demo for CVE-2023-45857 (axios XSRF token bypass). Step-by-step guide to reproduce the vulnerability in a controlled dev container…

api-security-testingctfeducation+3
12 years ago
vert-x3__vertx-web_CVE-2018-12542_3-5-3-CR1 preview

vert-x3__vertx-web_CVE-2018-12542_3-5-3-CR1

GitHubshoucheng3/vert-x3__vertx-web_cve-2018-12542_3-5-3-cr1

Exploit for CVE-2018-12542 in Vert.x-Web, a Java web framework. Demonstrates a path traversal vulnerability allowing unauthorized access to static…

api-securityapi-security-testingpenetration-testing+3
1 year ago
MCP-Inspector-CVE-2025-49596 preview

MCP-Inspector-CVE-2025-49596

GitHubashiqrehan-21/mcp-inspector-cve-2025-49596

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

api-security-testingeducationexploitation+3
1 year ago
CVE-2025-51867 preview

CVE-2025-51867

GitHubsecsys-fdu/cve-2025-51867

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

api-security-testinginformation-gatheringpenetration-testing+3
1 year ago
CVE-2025-51862 preview

CVE-2025-51862

GitHubsecsys-fdu/cve-2025-51862

Demonstrates an IDOR vulnerability in TelegAI's chat API allowing unauthorized conversation tampering, leading to phishing and XSS-based account…

api-security-testingexploitationpenetration-testing+3
1 year ago
CVE-2024-50633 preview

CVE-2024-50633

GitHubcetinpy/cve-2024-50633

Proof-of-concept exploit for CVE-2024-50633, a Broken Object Level Authorization (BOLA) vulnerability in Indico v3.2.9–v3.3.2, enabling unauthorized…

api-security-testingexploitationinformation-gathering+3
1 year ago
Swagger-HTML-Injection-CVE-2025-8191 preview

Swagger-HTML-Injection-CVE-2025-8191

GitHubmayank-s16/swagger-html-injection-cve-2025-8191

XSS Test Swagger 3.14.1 to 3.37.0

api-security-testingexploitationvulnerability-analysis+2
8 months ago
CVE-2023-6289 preview

CVE-2023-6289

GitHubrandomrobbiebf/cve-2023-6289

Swift Performance Lite <= 2.3.6.14 - Missing Authorization to Unauthenticated Settings Export

api-security-testingexploitationinformation-gathering+3
2 years ago
Burp_CVE-2025-31324 preview

Burp_CVE-2025-31324

GitHubblueowl-overlord/burp_cve-2025-31324

Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324

api-security-testingexploitationpenetration-testing+3
1 year ago
CVE-2024-54369 preview

CVE-2024-54369

GitHubrandomrobbiebf/cve-2024-54369

Zita Site Builder <= 1.0.2 - Missing Authorization to Arbitrary Plugin Installation

api-security-testingexploitationmisconfiguration+3
1 year ago
CVE-2024-9707-Poc preview

CVE-2024-9707-Poc

GitHubnxploited/cve-2024-9707-poc

he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4)

api-security-testingeducationexploitation+3
1 year ago
httptoolkit preview

httptoolkit

GitHubhttptoolkit/httptoolkit

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac 🎉 Open an issue here to…

api-security-testinggeneral-purpose-utilitiespenetration-testing+1
3.6k6 months ago
Previous1…345…9Next