Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
12 results
CVE-2026-4282-Scanner preview

CVE-2026-4282-Scanner

GitHubhex0user/cve-2026-4282-scanner

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

authenticationdefensive-toolsinformation-gathering+4
3
1 month ago
CVE-2026-82329-PoC-Exploit preview

CVE-2026-82329-PoC-Exploit

GitHubtc4dy/cve-2026-82329-poc-exploit

Exploit and detection toolkit for CVE-2026-82329, a JFrog Artifactory auth bypass. Forges join JWTs to mint admin tokens; includes a non-intrusive…

authenticationdefensive-toolsexploitation+7
216 days ago
CVE-2026-21994 preview

CVE-2026-21994

GitHubg0w6y/cve-2026-21994

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

authenticationcloud-securityexploitation+3
6 months ago
CentOS-Control-Web-Panel-CVE preview

CentOS-Control-Web-Panel-CVE

GitHubi3umi3iei3ii/centos-control-web-panel-cve

CentOS Control Web Panel, Root Privilege Escalation

authenticationeducationinformation-gathering+3
656 years ago
CVE-2025-64513 preview

CVE-2025-64513

GitHubshinyseam/cve-2025-64513

PoC for CVE-2025-64513 — Milvus Proxy Authentication Bypass Vulnerability Batch scanner to verify unauthorized access and gather Milvus version,…

authenticationdatabase-securityexploitation+3
110 months ago
CVE-2025-65899 preview

CVE-2025-65899

GitHubnoxurge/cve-2025-65899

DifuseHQ Kalmia CMS version 0.2.0 is vulnerable to user enumeration through distinguishable error responses in the /kal-api/auth/jwt/create…

authenticationinformation-gatheringpenetration-testing+3
110 months ago
CVE-2025-65900 preview

CVE-2025-65900

GitHubnoxurge/cve-2025-65900

DifuseHQ Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due to insufficient…

authenticationexploitationmisconfiguration+3
10 months ago
CVE-2025-14269 preview

CVE-2025-14269

GitHubr0binak/cve-2025-14269

CVE-2025-14269 PoC exploit

authenticationcloud-securityexploitation+3
9 months ago
CVE-2022-43959 preview

CVE-2022-43959

GitHubsecware-ru/cve-2022-43959

Bitrix Vulnerability CVE-2022-43959

authenticationconfiguration-auditingmisconfiguration+3
43 years ago
Check-AAD-Connect-for-CVE-2021-36949-vulnerability preview

Check-AAD-Connect-for-CVE-2021-36949-vulnerability

GitHubmaxwitat/check-aad-connect-for-cve-2021-36949-vulnerability

check if Azure AD Connect is affected by the vulnerability described in CVE-2021-36949

authenticationcloud-securitymisconfiguration+2
35 years ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubdante01yoon/cve-2025-29927

Demonstration of CVE-2025-29927: Next.js middleware authentication bypass via x-middleware-subrequest header spoofing. Includes vulnerable and fixed…

authenticationeducationmisconfiguration+3
1 year ago
CVE-2024-10449-patch preview

CVE-2024-10449-patch

GitHubg-u-i-d/cve-2024-10449-patch

Patch for CVE-2024-10449: replaces vulnerable loginAction.php with a hardened version that requires database configuration for secure authentication.

authenticationcode-analysismisconfiguration+2
1 year ago