Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
76 results
PENTEST-LAB preview

PENTEST-LAB

GitHubpannagkumaar/pentest-lab

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

ai-securityapi-securityauthentication+8
1 month ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
django_cve_2019_19844_poc preview

django_cve_2019_19844_poc

GitHubryu22e/django_cve_2019_19844_poc

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

authenticationexploitationpenetration-testing+2
1006 years ago
dcpwn preview

dcpwn

GitHubqax-a-team/dcpwn

an impacket-dependent script exploiting CVE-2019-1040

authenticationexploitationpenetration-testing+2
725 years ago
CVE-2019-12476 preview

CVE-2019-12476

GitHub0katz/cve-2019-12476
authenticationexploitationpenetration-testing+2
436 years ago
grafana-CVE-2018-15727 preview

grafana-CVE-2018-15727

GitHubu238/grafana-cve-2018-15727

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

authenticationexploitationpenetration-testing+2
227 years ago
CVE-2024-4040 preview

CVE-2024-4040

GitHubrbih-boulanouar/cve-2024-4040
authenticationexploitationpenetration-testing+2
152 years ago
CVE-2021-44910_SpringBlade preview

CVE-2021-44910_SpringBlade

GitHubw000i/cve-2021-44910_springblade

SpringBlade框架JWT认证的漏洞检测工具

authenticationexploitationpenetration-testing+2
111 year ago
CVE-2022-28601 preview

CVE-2022-28601

GitHubflaviupopescu/cve-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationexploitationpenetration-testing+2
84 years ago
cve-2021-33045 preview

cve-2021-33045

GitHubdongpohezui/cve-2021-33045
authenticationexploitationvulnerability-analysis+2
84 years ago
CVE-2023-0264 preview

CVE-2023-0264

GitHubtwwd/cve-2023-0264

A small PoC for the Keycloak vulnerability CVE-2023-0264

authenticationexploitationvulnerability-analysis+1
73 years ago
CVE-2022-0441 preview

CVE-2022-0441

GitHubbiulove0x/cve-2022-0441

WordPress Plugin MasterStudy LMS 2.7.5 - Unauthenticated Admin Account Creation

authenticationexploitationpenetration-testing+2
64 years ago
CVE-2023-46805_CVE-2024-21887 preview

CVE-2023-46805_CVE-2024-21887

GitHubraminkarimkhani1996/cve-2023-46805_cve-2024-21887

The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.

authenticationexploitationpenetration-testing+2
52 years ago
CVE-2025-23048-POC preview

CVE-2025-23048-POC

GitHubabsholi7ly/cve-2025-23048-poc

Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used…

authenticationexploitationpenetration-testing+3
410 months ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubund3sc0n0c1d0/cve-2022-40684

Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).

authenticationexploitationpenetration-testing+2
43 years ago
frevvomapexec preview
Archived

frevvomapexec

GitHubhateshape/frevvomapexec

PoC Exploit for CVE-2018-8820

authenticationexploitationpenetration-testing+2
48 years ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubmurrez/cve-2026-8181

CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports.…

authenticationexploitationpenetration-testing+3
33 months ago
magento2-session-reaper-patch preview

magento2-session-reaper-patch

GitHubwubinworks/magento2-session-reaper-patch

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

authenticationexploitationvulnerability-analysis+2
39 months ago
Previous12345Next