Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
24 results
Flowise-CVE-2025-58434-PasswordReset preview

Flowise-CVE-2025-58434-PasswordReset

GitHubarensballiu/flowise-cve-2025-58434-passwordreset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

authenticationexploitationpenetration-testing+3
1
7 days ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
1 month ago
CVE-2026-51788 preview

CVE-2026-51788

GitHubaykhan32/cve-2026-51788

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

authenticationeducationemail-security+3
2 months ago
cve-2025-29927-nextjs preview

cve-2025-29927-nextjs

GitHubgitgudkrish/cve-2025-29927-nextjs

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

authenticationeducationpenetration-testing+3
4 months ago
alpr-dashboard-patches preview

alpr-dashboard-patches

GitHubthewaterbug/alpr-dashboard-patches

Runtime patches for algertc/alpr-dashboard: async logger fix and CVE-2025-29927 nginx mitigation

authenticationauthentication-authorizationdevsecops+3
5 months ago
CVE-2026-31282 preview

CVE-2026-31282

GitHubsaykino/cve-2026-31282

Proof-of-concept for CVE-2026-31282: Totara LMS login page access control bypass enabling unauthenticated brute-force credential attacks. Includes…

authenticationeducationmisconfiguration+3
5 months ago
CVE-2025-0108 preview

CVE-2025-0108

GitHubkso4more/cve-2025-0108

Reproduces CVE-2025-0108 path confusion vulnerability in Nginx/Apache stacks. Includes a vulnerable PoC and a patched implementation demonstrating…

authenticationeducationlabs-practice+3
6 months ago
CVE-2026-24858 preview

CVE-2026-24858

GitHubm0d0ri205/cve-2026-24858

Detailed analysis of Fortinet FortiCloud SSO authentication bypass (CVE-2026-24858) including technical breakdown, attack scenarios, detection…

authenticationexploitationincident-response+4
8 months ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubbodoinon/cve-2024-10924

Demonstrates exploitation and mitigation of CVE-2024-10924, an authentication bypass in WordPress Really Simple Security, with automated Python…

authenticationeducationexploitation+3
9 months ago
2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424 preview

2FA-Bypass-using-a-Brute-Force-Attack-CVE-2025-60424

GitHubaakashtyal/2fa-bypass-using-a-brute-force-attack-cve-2025-60424

Demonstrates a brute-force attack bypassing two-factor authentication in Nagios Fusion due to missing rate limiting and lockout, with CVE-2025-60424…

authenticationexploitationpassword-attacks+3
111 months ago
Session-Persistence-After-Enabling-2FA-CVE-2025-60425 preview

Session-Persistence-After-Enabling-2FA-CVE-2025-60425

GitHubaakashtyal/session-persistence-after-enabling-2fa-cve-2025-60425

Detailed vulnerability report on Nagios Fusion session persistence after enabling 2FA, including CVE-2025-60425, affected versions, mitigation…

authenticationexploitationpenetration-testing+3
11 months ago
CVE-2025-56221 preview

CVE-2025-56221

GitHubsaykino/cve-2025-56221

Advisory detailing CVE-2025-56221, an authentication rate-limiting flaw in Ascertia SigningHub allowing brute-force attacks, with affected versions…

authenticationcurated-resourceseducation+2
11 months ago
CVE-2025-56224 preview

CVE-2025-56224

GitHubsaykino/cve-2025-56224

Documents an OTP verification bypass vulnerability in Ascertia SigningHub, allowing attackers to brute-force OTP codes and impersonate mobile…

authenticationexploitationpenetration-testing+2
11 months ago
CVE-2025-4172025 preview

CVE-2025-4172025

GitHubnotitssixtyn3in/cve-2025-4172025

Security advisory for CVE-2025-4172025: an authentication bypass vulnerability in Copilot enabling unauthorized account access, session hijacking,…

authenticationcloud-securityidentity-access-management+3
1 year ago
CVE-2025-4162030 preview

CVE-2025-4162030

GitHubnotitssixtyn3in/cve-2025-4162030

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162030) in Copilot, involving user ID switching that could lead to…

authenticationauthentication-authorizationincident-response+3
1 year ago
CVE-2025-4162029 preview

CVE-2025-4162029

GitHubnotitssixtyn3in/cve-2025-4162029

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162029) in Copilot, enabling unauthorized account access via user ID…

authenticationexploitationinformation-gathering+3
1 year ago
CVE-2025-4162028 preview

CVE-2025-4162028

GitHubnotitssixtyn3in/cve-2025-4162028

Security advisory detailing a critical authentication vulnerability (CVE-2025-4162028) in Copilot, enabling unauthorized account access via user ID…

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2025-4162027 preview

CVE-2025-4162027

GitHubnotitssixtyn3in/cve-2025-4162027

Security advisory detailing a critical authentication vulnerability in Copilot where user IDs are switched, enabling unauthorized account access and…

authenticationexploitationincident-response+3
1 year ago
Previous12Next