Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems Security
General Purpose Utilities
Indicator of Compromise (IOC) Management
OSINT (Open Source Intelligence)
Packet Sniffing & Analysis
Password Cracking
Penetration Testing Frameworks
Phishing Tools
Privilege Escalation
Reconnaissance
Static Analysis
Vulnerability Scanners
Web Vulnerability Scanners
Wi-Fi Auditing
Bluetooth Security
Container Security
Dynamic Analysis (Sandboxing)
Encryption/Decryption Tools
Exploit Frameworks
Identity Management
iOS Security
IoT Security
Memory Forensics
Network Mapping
OSINT for Social Engineering
Password Attacks
Payload Generation
Persistence Mechanisms
Port Scanning
Static Code Analysis (SAST)
Threat Feeds & Aggregators
Vulnerability Analysis
Web Proxies & Interception
Code Analysis
DNS & Subdomain Enumeration
Dynamic Code Analysis (DAST)
Exploitation
Hash Analysis
IDS/IPS Evasion
Impersonation Tools
Lateral Movement
Mobile App Pentesting
Network Forensics
Reverse Engineering
RFID/NFC Tools
SCADA/ICS Security
Scripting & Automation
Serverless Security
Shellcode
Web Application Exploitation
API Security Testing
Configuration Auditing
Data Exfiltration
Debuggers
Forensics
Information Gathering
Mobile Forensics
Network Access Control
Post-Exploitation
Security Virtualization
Phishing
WAF Bypass
Web Security
Fuzzing
Network Security
Steganography
Wireless Security
Data Recovery
Malware Analysis
Digital Forensics
Hardware Hacking
Cryptography
CTF
Penetration Testing
Cloud Security
DevSecOps
Mobile Security
Privacy
Command and Control
Social Engineering
Hardware Security
Utilities & Frameworks
Hardware & IoT Security
Secret Detection
Binary Analysis
Threat Intelligence
Identity & Access Management (IAM)
Supply Chain Security
Authentication
Machine Learning
Intrusion Detection
Papers & Research
Misconfiguration
Subdomain Enumeration
Email Harvesting
Learning & Education
AI-Assisted Reversing
DNS Fuzzing
Red Teaming
Incident Response
Crawler
Curated Resources
Remote Access Tool
Shellcode Generation
Payload Development
Remote Access Trojan
API Security
Anti-Bot
Fingerprint Spoofing
CAPTCHA Bypass
Email Security
DNS Analysis
Chaos Engineering
Learning Paths & Courses
Container Escape
AI Security
Database Security
Firmware Analysis
Anomaly Detection
Log Analysis
Adversarial Attack
Binary Exploitation
Labs & Practice
NewestRelevanceMost popularRecently updated
145 results
messari-crack preview

messari-crack

GitHubtimuronlinq/messari-crack

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

authenticationcryptographyexploitation+3
21914 days ago
CVE-2022-26923 preview

CVE-2022-26923

GitHubeliasdekiniweek/cve-2022-26923

Exploitation de CVE-2022-26923

authenticationeducationexploitation+6
16 months ago
Flowise-CVE-2025-58434-PasswordReset preview

Flowise-CVE-2025-58434-PasswordReset

GitHubr3nsi15/flowise-cve-2025-58434-passwordreset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

authenticationeducationexploitation+3
14 months ago
CVE-2025-58434-poc preview

CVE-2025-58434-poc

GitHubkartik2005221/cve-2025-58434-poc

Proof-of-concept exploit for CVE-2025-58434, demonstrating unauthenticated account takeover in Flowise via leaked password reset tokens. Includes…

authenticationeducationexploitation+4
14 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubjacubes/cve-2026-24061

CVE-2026-24061 exploit PoC

authenticationeducationexploitation+3
82414 days ago
CVE-2025-53770 preview

CVE-2025-53770

GitHubsaladin0x1/cve-2025-53770

Proof-of-concept exploit toolkit for SharePoint ToolPane RCE (CVE-2025-53770) with scanner, payload analysis, and multiple exploitation methods for…

authenticationeducationexploitation+5
40 years ago
CVE-2025-0108 preview

CVE-2025-0108

GitHubkso4more/cve-2025-0108

Reproduces CVE-2025-0108 path confusion vulnerability in Nginx/Apache stacks. Includes a vulnerable PoC and a patched implementation demonstrating…

authenticationeducationlabs-practice+3
5 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHublucastran05/cve-2026-29000

Local lab simulating CVE-2026-29000 JWT/JWE authentication bypass in pac4j-jwt. Provides login, token forging, and dashboard APIs for practicing web…

authenticationctfeducation+3
3 months ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
1 month ago
Moniker-Link-Lab-Setup preview

Moniker-Link-Lab-Setup

GitHube-m-e-k-a/moniker-link-lab-setup

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

authenticationeducationexploitation+6
5 months ago
CVE-2026-8181-Lab preview

CVE-2026-8181-Lab

GitHubrootdirective-sec/cve-2026-8181-lab

Docker lab demonstrating CVE-2026-8181 authentication bypass in Burst Statistics WordPress plugin. Compares vulnerable and patched versions with a…

authenticationctfeducation+5
3 months ago
CVE-2023-6329 preview

CVE-2023-6329

GitHubitzvenom/cve-2023-6329

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

authenticationeducationexploitation+4
15 months ago
CVE-2017-11427-DEMO preview

CVE-2017-11427-DEMO

GitHubchybeta/cve-2017-11427-demo

The Demo for CVE-2017-11427

authenticationeducationlabs-practice+3
128 years ago
CVE-2025-66204 preview

CVE-2025-66204

GitHublukasz-rybak/cve-2025-66204

Proof-of-concept for CVE-2025-66204: brute-force protection bypass in WBCE CMS via spoofed X-Forwarded-For header, with automated Python exploit…

authenticationeducationpapers-research+3
4 months ago
passfault preview
Archived

passfault

GitHubowasp/passfault

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

authenticationeducationpassword-cracking+2
1795 years ago
CVE-2026-18963-keycloak preview

CVE-2026-18963-keycloak

GitHubred-darkin/cve-2026-18963-keycloak

Proof-of-concept exploit for CVE-2026-18963, a critical Keycloak reset-credentials bypass enabling unauthenticated account takeover. Includes lab…

authenticationeducationexploitation+3
198 days ago
POC_CVE-2015-9235 preview

POC_CVE-2015-9235

GitHubtierchampion/poc_cve-2015-9235

Demo of the algorithm confusion attack on various JWT libraries

authenticationctfeducation+3
5 months ago
pentest-guide preview

pentest-guide

GitHubvoorivex/pentest-guide

Penetration tests guide based on OWASP including test cases, resources and examples.

authenticationcryptographyeducation+6
2.8k5 years ago
Previous12…9Next