Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
47 results
CVE-2025-70829 preview

CVE-2025-70829

GitHubxiaoxiaoranxxx/cve-2025-70829

An information exposure vulnerability in Datart v1.0.0-rc.3 allows authenticated attackers to access sensitive data via a custom H2 JDBC connection…

authenticationdatabase-securityexploitation+3
4
7 months ago
CVE-2025-15602-PoC preview

CVE-2025-15602-PoC

GitHubnxvh1337/cve-2025-15602-poc

Snipe-IT < 8.3.7 Mass Assignment Vulnerability Leading to Privilege Escalation

authenticationexploitationinformation-gathering+4
5 months ago
CVE-2025-40554 preview

CVE-2025-40554

GitHubskynoxk/cve-2025-40554

CVE-2025-40554 Exploitation

authenticationexploitationinformation-gathering+4
8 months ago
CVE-2026-4282-Scanner preview

CVE-2026-4282-Scanner

GitHubhex0user/cve-2026-4282-scanner

Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code…

authenticationdefensive-toolsinformation-gathering+4
31 month ago
CVE-2025-33073-checker preview

CVE-2025-33073-checker

GitHubmatejsmycka/cve-2025-33073-checker

This rough PoC checker script tests targets for CVE-2025-33073 vulnerability by attempting to perform NTLM reflection attacks using NTLM auth…

authenticationexploitationinformation-gathering+3
1 year ago
CVE-2024-9014 preview

CVE-2024-9014

GitHubr0otk3r/cve-2024-9014

Scripts to detect and exploit CVE-2024-9014 OAuth2 authentication bypass in pgAdmin 4, including vulnerability checking and OAuth2 configuration…

authenticationexploitationinformation-gathering+3
1 year ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubtx-one/cve-2025-31161

CrushFTP CVE-2025-31161 Exploit Tool 🔓

authenticationexploitationinformation-gathering+3
21 year ago
CVE-2017-7921-EXPLOIT preview

CVE-2017-7921-EXPLOIT

GitHubk3ystr0k3r/cve-2017-7921-exploit

A PoC exploit for CVE-2017-7921 - Hikvision Camera Series Improper Authentication Vulnerability.

authenticationexploitationinformation-gathering+3
521 year ago
CVE-2024-27198-POC preview

CVE-2024-27198-POC

GitHubeynaexp/cve-2024-27198-poc

proof-of-concept mass scanner targeting JetBrains TeamCity instances affected by CVE-2024-27198

authenticationexploitationpenetration-testing+3
19 months ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubr0otk3r/cve-2025-31161

Python exploit for CVE-2025-31161, an authentication bypass in CrushFTP. Retrieves user lists via crafted CrushAuth and AWS4-HMAC-SHA256 headers.…

authenticationexploitationinformation-gathering+3
1 year ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubgrayxploit/cve-2026-0257

Automated vulnerability scanner for CVE-2026-0257 (PAN-OS GlobalProtect Authentication Bypass) with TLS certificate enumeration, authentication…

authenticationincident-responseinformation-gathering+6
13 months ago
cve-2025-24472-fortinet_authbypass_reproduction preview

cve-2025-24472-fortinet_authbypass_reproduction

GitHubrazureink/cve-2025-24472-fortinet_authbypass_reproduction

CVE Reproduction: cve-2025-24472-fortinet_authbypass_reproduction

authenticationexploitationinformation-gathering+4
2 months ago
CVE-2025-22963 preview

CVE-2025-22963

GitHubgmh5225/cve-2025-22963

Proof-of-concept exploit for CVE-2025-22963, a CSRF vulnerability in Teedy v1.11 allowing account takeover via user information change endpoint.

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
4 months ago
CVE-2020-1958 preview

CVE-2020-1958

GitHubggolawski/cve-2020-1958

Proof-of-concept exploit for CVE-2020-1958, an LDAP injection vulnerability in Apache Druid 0.17.0, enabling user enumeration and LDAP attribute…

authenticationexploitationinformation-gathering+3
216 years ago
exploit-mikrotik-2026 preview

exploit-mikrotik-2026

GitHubblackhatexploitation/exploit-mikrotik-2026

CVE-2026-67276 MikroTik RouterOS SSH Authentication Bypass Exploit

authenticationexploitationinformation-gathering+4
923 days ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubjenderal92/cve-2026-41940

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

authenticationcommand-and-controlexploitation+6
54 months ago
CVE-2025-2825-CrushFTP-AuthBypass preview

CVE-2025-2825-CrushFTP-AuthBypass

GitHubshivshantp/cve-2025-2825-crushftp-authbypass

Authentication Bypass PoC for CVE-2025-2825 – Exploiting CrushFTP 10.x

authenticationexploitationinformation-gathering+5
51 year ago
Previous123Next