Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
643 results
nextjs-middleware-exploit preview

nextjs-middleware-exploit

GitHubl1uk/nextjs-middleware-exploit

Research on Next.js middleware vulnerability (CVE-2025-29927) allowing authorization bypass and potential exploits.

authenticationeducationexploitation+3
1 year ago
CVE-2024-27198 preview

CVE-2024-27198

GitHubjrbh4ck/cve-2024-27198

PoC about CVE-2024-27198

authenticationeducationexploitation+3
2 years ago
CVE-2018-15473-py3 preview

CVE-2018-15473-py3

GitHubdirty-racoon/cve-2018-15473-py3

Python3 exploit for CVE-2018-15473 that enumerates valid usernames on OpenSSH servers via timing-based authentication analysis.

authenticationexploitationpenetration-testing+1
5 years ago
CVE-2025-0108-Authentication-Bypass-checker preview

CVE-2025-0108-Authentication-Bypass-checker

GitHubbarcrange/cve-2025-0108-authentication-bypass-checker

Python script that tests PAN-OS devices for CVE-2025-0108 authentication bypass by sending crafted HTTP requests and analyzing responses.

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2020-27747 preview

CVE-2020-27747

GitHubjet-pentest/cve-2020-27747

Possible Account Takeover | Brute Force Ability

authenticationexploitationpassword-attacks+2
5 years ago
CVE-2019-1619 preview

CVE-2019-1619

GitHubcipolone95/cve-2019-1619

Powershell Script to build token for CVE-2019-1619

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2024-57610 preview

CVE-2024-57610

GitHubh4ckm3-png/cve-2024-57610

Proof-of-concept demonstrating lack of rate limiting on the Sylius v2.0.2 login endpoint, enabling unrestricted automated authentication attempts.

authenticationpapers-researchpenetration-testing+2
1 year ago
demo-cve-2022-21449 preview

demo-cve-2022-21449

GitHubvolodymyr-hladkyi-symphony/demo-cve-2022-21449

Educational demo of CVE-2022-21449 Java ECDSA signature bypass using real and fake JWT tokens to illustrate the vulnerability and its impact on…

authenticationcryptographyeducation+3
1 year ago
bloodit preview

bloodit

GitHubbrunosergi/bloodit

Bludit 3.9.2 - Auth Brute Force Mitigation Bypass. CVE-2019-17240

authenticationexploitationpenetration-testing+2
5 years ago
CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7 preview

CVE-2025-25749-Weak-Password-Policy-in-HotelDruid-3.0.7

GitHubhuyvo2910/cve-2025-25749-weak-password-policy-in-hoteldruid-3.0.7

Proof-of-concept for CVE-2025-25749 demonstrating weak password policy in HotelDruid 3.0.7, with automated test scripts and mitigation…

authenticationeducationpassword-attacks+3
1 year ago
CVE-2024-10511 preview

CVE-2024-10511

GitHubrevengsmk/cve-2024-10511

Schneider Electric PowerChute Serial Shutdown vulnerability.

authenticationexploitationmisconfiguration+3
1 year ago
Event-ID-229-Rule-Name-SOC262-CVE-2024-1709- preview

Event-ID-229-Rule-Name-SOC262-CVE-2024-1709-

GitHubahmedmansour93/event-id-229-rule-name-soc262-cve-2024-1709-

Event ID 229 Rule Name SOC262 ScreenConnect Authentication Bypass Exploitation Detected (CVE-2024-1709)

authenticationexploitationids-ips-evasion+2
2 years ago
ansible-ssh-hardening preview
Archived

ansible-ssh-hardening

GitHubdev-sec/ansible-ssh-hardening

This Ansible role provides numerous security-related ssh configurations, providing all-round base protection.

authenticationcloud-infrastructure-securityconfiguration-auditing+2
7865 years ago
ssh-mitm preview
Archived

ssh-mitm

GitHubjtesta/ssh-mitm

SSH man-in-the-middle tool

authenticationids-ips-evasioninformation-gathering+6
1.7k5 years ago
passfault preview
Archived

passfault

GitHubowasp/passfault

OWASP Passfault evaluates passwords and enforces password policy in a completely different way.

authenticationeducationpassword-cracking+2
1805 years ago
MITMf preview
Archived

MITMf

GitHubbyt3bl33d3r/mitmf

Framework for Man-In-The-Middle attacks

authenticationcommand-and-controldns-analysis+8
3.6k8 years ago
KnockKnock preview
Archived

KnockKnock

GitHuboptiv/knockknock

Enumerate valid users within Microsoft Teams and OneDrive with clean output.

authenticationcloud-securityinformation-gathering+3
621 year ago
frevvomapexec preview
Archived

frevvomapexec

GitHubhateshape/frevvomapexec

PoC Exploit for CVE-2018-8820

authenticationexploitationpenetration-testing+2
48 years ago
Previous1…323334…36Next