Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
643 results
Flowise-CVE-2025-58434-Chain-59528 preview

Flowise-CVE-2025-58434-Chain-59528

GitHub0xdaeras/flowise-cve-2025-58434-chain-59528

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE.…

authenticationeducationexploitation+4
14 months ago
cve-2025-22235-demo preview

cve-2025-22235-demo

GitHubidealzh/cve-2025-22235-demo

Demonstrates CVE-2025-22235 Spring Boot authentication bypass via EndpointRequest.to() misconfiguration. Includes environment setup, reproduction…

authenticationeducationexploitation+3
1 year ago
CVE-2024-10924-Wordpress-Docker preview

CVE-2024-10924-Wordpress-Docker

GitHubhunt3r850/cve-2024-10924-wordpress-docker

Dockerized exploit environment for CVE-2024-10924, an authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1)…

authenticationeducationexploitation+4
1 year ago
CVE-2025-4679-SecureOAuth-Demo---Enfoque-educativo preview

CVE-2025-4679-SecureOAuth-Demo---Enfoque-educativo

GitHubfevar54/cve-2025-4679-secureoauth-demo---enfoque-educativo

Isolated educational lab simulating CVE-2025-4679 OAuth credential exposure. Learn offensive and defensive security through hands-on exercises,…

api-securityauthenticationctf+6
10 months ago
django_cve_2019_19844_poc preview

django_cve_2019_19844_poc

GitHubryu22e/django_cve_2019_19844_poc

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

authenticationexploitationpenetration-testing+2
1006 years ago
CVE-2026-29145-Tester preview

CVE-2026-29145-Tester

GitHubchenjp/cve-2026-29145-tester

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

authenticationeducationexploitation+3
5 months ago
CVE-2026-29145-Tester preview

CVE-2026-29145-Tester

GitHubsancliffe/cve-2026-29145-tester

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

authenticationeducationexploitation+3
5 months ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubtrganda/cve-2022-23131

Proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML SSO authentication bypass vulnerability. Includes environment setup and a Go-based checker…

authenticationexploitationpenetration-testing+2
14 years ago
CVE-2022-4361 preview

CVE-2022-4361

GitHubfaccimatteo/cve-2022-4361

Proof-of-concept exploit for CVE-2022-4361, a reflected XSS vulnerability in Keycloak's OIDC authentication flow, with Docker-based test environment…

api-securityauthenticationexploitation+3
10 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubprzemytn/cve-2026-24061

Proof-of-concept exploit for CVE-2026-24061, a telnetd authentication bypass via argument injection in the USER environment variable, allowing…

authenticationexploitationnetwork-security+3
6 months ago
PoC_CVE-2019-0217 preview

PoC_CVE-2019-0217

GitHubsavsch/poc_cve-2019-0217

Proof-of-concept exploit for CVE-2019-0217, a race condition in Apache HTTP Server's mod_auth_digest allowing authentication bypass. Includes…

authenticationeducationexploitation+3
1 year ago
CVE-2025-54918-POC preview

CVE-2025-54918-POC

GitHubwh0am123/cve-2025-54918-poc

POC for CVE-2025-54918 and a technical demonstration.

authenticationeducationexploitation+5
648 months ago
CVE-2026-20896 preview

CVE-2026-20896

GitHubxaoczenon/cve-2026-20896

this is a modified POC of rz1027 for CVE-2026-20896

authenticationeducationexploitation+3
62 months ago
GEVAUDAN preview

GEVAUDAN

GitHubmauroeldritch/gevaudan

Exploit for Red Hat / GlusterFS CVE-2018-1088 & CVE-2018-1112, featured @ DEFCON 26, Las Vegas!

authenticationcontainer-securityexploitation+3
106 years ago
starlette-host-header-lab preview

starlette-host-header-lab

GitHubxtremebeing/starlette-host-header-lab

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

authenticationeducationlabs-practice+3
14 months ago
CVE-2025-0108 preview

CVE-2025-0108

GitHubkso4more/cve-2025-0108

Reproduces CVE-2025-0108 path confusion vulnerability in Nginx/Apache stacks. Includes a vulnerable PoC and a patched implementation demonstrating…

authenticationeducationlabs-practice+3
6 months ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
121 month ago
CVE-2026-13447 preview

CVE-2026-13447

GitHubabraxas/cve-2026-13447

Proof-of-concept exploit for CVE-2026-13447, a critical authentication bypass in the WordPress MStore API plugin via forged Firebase JWT tokens, with…

authenticationcryptographyexploitation+5
3 days ago
Previous123…36Next