Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
87 results
CVE-2025-58434-AND-59528-POC preview

CVE-2025-58434-AND-59528-POC

GitHubkartik2005221/cve-2025-58434-and-59528-poc

Modular PoC for CVE-2025-58434 (account takeover) and CVE-2025-59528 (RCE) in Flowise. Automates the full attack chain from unauthenticated token…

authenticationeducationexploitation+5
17
4 months ago
2026-11551 preview

2026-11551

GitHubxxconi/2026-11551

CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover

authenticationexploitationpenetration-testing+3
2 months ago
CVE-2026-7458 preview

CVE-2026-7458

GitHubsangsenimanwartefak/cve-2026-7458

Python proof-of-concept exploit for CVE-2026-7458, an unauthenticated authentication bypass in PickPlugins User Verification WordPress plugin via…

authenticationexploitationpenetration-testing+2
2 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
2 months ago
CVE-2026-54415-PoC preview

CVE-2026-54415-PoC

GitHubabdugafforov-bobur/cve-2026-54415-poc

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

authenticationctfeducation+4
21 month ago
CVE-2026-12416-CVE-2026-12417 preview

CVE-2026-12416-CVE-2026-12417

GitHubnxploited/cve-2026-12416-cve-2026-12417

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

authenticationexploitationpassword-attacks+3
22 months ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
1 month ago
gitlab-exploit preview

gitlab-exploit

GitHubhackeremmen/gitlab-exploit

Exploit for GitLab CVE-2023-7028: password reset bypass via dual email verification, allowing unauthorized account takeover. Includes affected…

authenticationexploitationpassword-attacks+3
12 years ago
CVE-2022-22845-Exploit preview

CVE-2022-22845-Exploit

GitHubomribaso/cve-2022-22845-exploit

Exploit for CVE-2022-22845 - Unauthenticated Admin Takeover On QXIP SIPCAPTURE Homer-App up to 1.4.27

authenticationexploitationpenetration-testing+2
24 years ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubdungsocool/cve-2026-8206

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

authenticationeducationexploitation+6
11 month ago
magento2-session-reaper-patch preview

magento2-session-reaper-patch

GitHubwubinworks/magento2-session-reaper-patch

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

authenticationexploitationvulnerability-analysis+2
39 months ago
CVE-2025-58434_CVE-2025-59528 preview

CVE-2025-58434_CVE-2025-59528

GitHubhonney336/cve-2025-58434_cve-2025-59528

CVE-2025-58434 Flowise <= 3.0.5 and earlier allows account takeover via unauthenticated forgot-password token. CVE-2025-59528 lowiseAI Custom MCP…

authenticationexploitationpenetration-testing+3
4 months ago
CVE-2021-46067 preview

CVE-2021-46067

GitHubsanupl/cve-2021-46067

CVE-2021-46067 - In Vehicle Service Management System 1.0 an attacker can steal the cookies leading to Full Account Takeover.

authenticationexploitationimpersonation-tools+3
13 months ago
CVE-2022-1903 preview

CVE-2022-1903

GitHubbiulove0x/cve-2022-1903

ARMember < 3.4.8 - Unauthenticated Admin Account Takeover

authenticationexploitationpenetration-testing+3
14 years ago
CVE-2024-50483 preview

CVE-2024-50483

GitHubrandomrobbiebf/cve-2024-50483

Meetup <= 0.1 - Authentication Bypass via Account Takeover

authenticationexploitationpenetration-testing+3
21 year ago
CVE-2025-14998 preview

CVE-2025-14998

GitHubktn1990/cve-2025-14998

CVE-2025-14998 Wordpress Plugin - Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via…

authenticationexploitationpassword-attacks+3
27 months ago
CVE-2025-10658 preview

CVE-2025-10658

GitHubjfriedli/cve-2025-10658

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

authenticationexploitationpassword-attacks+3
15 months ago
CVE-2025-2563 preview

CVE-2025-2563

GitHubdokter69/cve-2025-2563

Multi-threaded exploit for CVE-2025-2563 targeting unauthenticated privilege escalation in the WordPress User Registration & Membership plugin.…

authenticationexploitationpenetration-testing+4
14 months ago
Previous12345Next