Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
163 results
CVE-2025-58434-poc preview

CVE-2025-58434-poc

GitHubkartik2005221/cve-2025-58434-poc

Proof-of-concept exploit for CVE-2025-58434, demonstrating unauthenticated account takeover in Flowise via leaked password reset tokens. Includes…

authenticationeducationexploitation+4
14 months ago
FlowiseAI-Critical-KillChain preview

FlowiseAI-Critical-KillChain

GitHubcveteam/flowiseai-critical-killchain

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

authenticationeducationexploitation+5
14 months ago
Flowise-CVE-2025-58434-Chain-59528 preview

Flowise-CVE-2025-58434-Chain-59528

GitHub0xdaeras/flowise-cve-2025-58434-chain-59528

FlowiseAI CVE-2025-58434 & CVE-2025-59528 exploit PoC, demonstrating unauthenticated ATO via reset token leakage, followed by authenticated RCE.…

authenticationeducationexploitation+4
13 months ago
Flowise-CVE-2025-58434-PasswordReset preview

Flowise-CVE-2025-58434-PasswordReset

GitHubr3nsi15/flowise-cve-2025-58434-passwordreset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

authenticationeducationexploitation+3
14 months ago
CVE-2025-4322 preview

CVE-2025-4322

GitHubyucaerin/cve-2025-4322

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

authenticationeducationexploitation+5
11 year ago
CVE-2026-8181-Lab preview

CVE-2026-8181-Lab

GitHubrootdirective-sec/cve-2026-8181-lab

Docker lab demonstrating CVE-2026-8181 authentication bypass in Burst Statistics WordPress plugin. Compares vulnerable and patched versions with a…

authenticationctfeducation+5
3 months ago
CVE-2026-44338-Lab preview

CVE-2026-44338-Lab

GitHubrootdirective-sec/cve-2026-44338-lab

Docker-based lab demonstrating CVE-2026-44338 authentication bypass in PraisonAI's legacy Flask API. Includes vulnerable and patched services with…

authenticationeducationlabs-practice+3
3 months ago
pocketbase-CVE-2026-44166 preview

pocketbase-CVE-2026-44166

GitHubalardiians/pocketbase-cve-2026-44166

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

authenticationctfeducation+5
2 months ago
cve-2026-43512-poc preview

cve-2026-43512-poc

GitHubcovepseng/cve-2026-43512-poc

Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)

authenticationeducationexploitation+4
2 months ago
CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX preview

CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX

GitHubbimboxh4/cve-2025-66039_cve-2025-61675_cve-2025-61678_reepbx

This vulnerability allows both authenticated and unauthenticated remote attackers to execute remote code on vulnerable FreePBX instances. These…

authenticationeducationexploitation+3
18 months ago
CVE-2022-26923 preview

CVE-2022-26923

GitHubeliasdekiniweek/cve-2022-26923

Exploitation de CVE-2022-26923

authenticationeducationexploitation+6
16 months ago
CVE-2025-0108 preview

CVE-2025-0108

GitHubsohaibeb/cve-2025-0108

PAN-OS CVE POC SCRIPT

authenticationeducationexploitation+3
11 year ago
ssh_Enum_vaild preview

ssh_Enum_vaild

GitHub0xnehru/ssh_enum_vaild

A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2…

authenticationeducationexploitation+3
11 year ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubbodoinon/cve-2024-10924

Demonstrates exploitation and mitigation of CVE-2024-10924, an authentication bypass in WordPress Really Simple Security, with automated Python…

authenticationeducationexploitation+3
8 months ago
CVE-2021-21239 preview

CVE-2021-21239

GitHubillera88/cve-2021-21239

Exploit for CVE-2021-21239: SAML signature validation bypass in pysaml2/Redash. Forges SAML responses with embedded public keys to impersonate users…

authenticationeducationexploitation+3
11 months ago
CVE-2025-29927-Nextjs-Bypass-PoC preview

CVE-2025-29927-Nextjs-Bypass-PoC

GitHubdanielhallbro/cve-2025-29927-nextjs-bypass-poc

A Proof of Concept for CVE-2025-29927 demonstrating a middleware bypass in Next.js versions prior to 13.5.9

authenticationeducationexploitation+3
17 months ago
CVE-2022-23361 preview

CVE-2022-23361

GitHubvini0608/cve-2022-23361

CVE-2022-23361

authenticationeducationmobile-security+2
14 years ago
CVE-2025-29927-scanner preview

CVE-2025-29927-scanner

GitHubolimpiofreitas/cve-2025-29927-scanner

Python scanner that detects Next.js instances vulnerable to CVE-2025-29927, identifies versions, and tests for authentication bypass via the…

authenticationeducationexploitation+3
11 year ago
Previous1…678…10Next