Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
133 results
CVE-2025-14340 preview

CVE-2025-14340

GitHubdeepsecurityresearch/cve-2025-14340

PoC for CVE-2025-14340: Admin account takeover in Payara Server

authenticationexploitationpenetration-testing+3
1
5 months ago
CVE-2024-50483 preview

CVE-2024-50483

GitHubrandomrobbiebf/cve-2024-50483

Meetup <= 0.1 - Authentication Bypass via Account Takeover

authenticationexploitationpenetration-testing+3
21 year ago
CVE-2025-9967 preview

CVE-2025-9967

GitHubjfriedli/cve-2025-9967

Proof-of-concept exploit for an unauthenticated OTP password reset vulnerability in WordPress, enabling attackers to reset a victim's password…

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2025-9485 preview

CVE-2025-9485

GitHubjfriedli/cve-2025-9485

Proof-of-concept exploit for CVE-2025-9485 demonstrating authentication bypass via unsigned JWT (alg: none) in a WordPress-like OAuth flow. Includes…

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2025-12028 preview

CVE-2025-12028

GitHubjfriedli/cve-2025-12028

Proof-of-concept exploit for CVE-2025-12028 demonstrating CSRF-based OAuth token theft in WordPress IndieAuth plugin, enabling unauthorized API…

authenticationexploitationpenetration-testing+3
5 months ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubpykiller/cve-2022-23131

Proof-of-concept exploit for CVE-2022-23131, an SSO authentication bypass vulnerability in Zabbix. Allows unauthorized access to Zabbix frontend.

authenticationexploitationpenetration-testing+2
24 years ago
CVE-2022-1903 preview

CVE-2022-1903

GitHubbiulove0x/cve-2022-1903

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

authenticationexploitationpenetration-testing+3
14 years ago
oauth-client-exploit preview

oauth-client-exploit

GitHubmari6274/oauth-client-exploit

Applications that reproduce CVE-2021-22119

authenticationexploitationpenetration-testing+2
14 years ago
CVE-2024-8682 preview

CVE-2024-8682

GitHub4minx/cve-2024-8682

PoC exploit for CVE-2024-8682, enabling unauthenticated user registration on JNews WordPress themes via crafted AJAX requests.

authenticationexploitationpenetration-testing+2
21 year ago
CVE-2021-24647 preview

CVE-2021-24647

GitHubrandomrobbiebf/cve-2021-24647

CVE-2021-24647 Pie Register < 3.7.1.6 - Unauthenticated Arbitrary Login

authenticationexploitationpenetration-testing+2
13 years ago
cve-2022-23131 preview

cve-2022-23131

GitHubwr0x00/cve-2022-23131

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Generates a signed session cookie to gain unauthorized admin access.

authenticationexploitationpenetration-testing+2
13 years ago
CVE-2022-31294 preview

CVE-2022-31294

GitHubbigzooooz/cve-2022-31294

Online Discussion Forum Site 1.0 - Account Takeover

authenticationexploitationpenetration-testing+2
14 years ago
securenvoy-cve-2024-37393 preview

securenvoy-cve-2024-37393

GitHubnoways-io/securenvoy-cve-2024-37393

Vulnerability check script for CVE-2024-37393 (SecurEnvoy MFA 9.4.513)

authenticationexploitationpenetration-testing+2
12 years ago
CVE-2025-4603 preview

CVE-2025-4603

GitHubd0n601/cve-2025-4603

eMagicOne Store Manager for WooCommerce <= 1.2.5 - Unauthenticated Arbitrary File Deletion

authenticationexploitationpenetration-testing+3
11 year ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubtrganda/cve-2022-23131

Proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML SSO authentication bypass vulnerability. Includes environment setup and a Go-based checker…

authenticationexploitationpenetration-testing+2
14 years ago
moodle-token-stealer preview

moodle-token-stealer

GitHubfr3d-/moodle-token-stealer

CVE-2019-14830

authenticationexploitationpenetration-testing+2
17 years ago
CVE-2023-47504-POC preview

CVE-2023-47504-POC

GitHubdavidxbors/cve-2023-47504-poc

Proof-of-concept exploit for CVE-2023-47504 targeting Elementor WordPress plugin. Requires subscriber credentials and wp-config.php access to delete…

authenticationexploitationpenetration-testing+2
12 years ago
proftpd_bypass preview

proftpd_bypass

GitHubjptr218/proftpd_bypass

An implementation of CVE-2015-3306

authenticationexploitationpenetration-testing+2
15 years ago
Previous1234…8Next