Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
130 results
route-detect preview

route-detect

GitHubmschwager/route-detect

Find authentication (authn) and authorization (authz) security bugs in web application routes.

authenticationstatic-analysisvulnerability-analysis+1
280
1 year ago
crushftp_cve-2025-31161 preview

crushftp_cve-2025-31161

GitHubrufflabs/crushftp_cve-2025-31161

Pre-built vulnerable CrushFTP 10.8.0 binary for authorized penetration testing of CVE-2025-31161, an unauthenticated authentication bypass…

authenticationexploitationlabs-practice+3
2 months ago
janusec preview

janusec

GitHubjanusec/janusec

Unified application gateway providing reverse proxy, WAF, CC defense, OAuth2 authentication, ACME certificate automation, and GSLB for secure,…

api-securityauthenticationcloud-security+8
1.2k1 month ago
PENTEST-LAB preview

PENTEST-LAB

GitHubpannagkumaar/pentest-lab

Modern cyber range with 50 hands-on challenges across web, API, cloud, AI, and blue-team security tracks. Features guided attack chains, transparent…

ai-securityapi-securityauthentication+8
1 month ago
CVE-2026-34828 preview

CVE-2026-34828

GitHub0xmrma/cve-2026-34828

listmonk’s Session Persistence After Password Reset and Password Change

authenticationexploitationpenetration-testing+2
15 months ago
CVE-2021-3130 preview

CVE-2021-3130

GitHubjet-pentest/cve-2021-3130

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

authenticationmisconfigurationpenetration-testing+2
5 years ago
CheatSheetSeries preview

CheatSheetSeries

GitHubowasp/cheatsheetseries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

api-securityauthenticationcloud-security+6
33.2k2 days ago
CVE-2024-8465-PoC preview

CVE-2024-8465-PoC

GitHubsholls000/cve-2024-8465-poc

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

authenticationdatabase-securityeducation+3
7 months ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubeqstlab/cve-2026-18963

Proof-of-concept exploit for CVE-2026-18963, demonstrating unauthenticated account takeover by bypassing the reset-credentials flow in web…

authenticationexploitationpenetration-testing+2
213 days ago
cve-2024-55591-poc preview

cve-2024-55591-poc

GitHubull0a/cve-2024-55591-poc

Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability…

authenticationexploitationpenetration-testing+2
112 days ago
CVE-2026-5415 preview

CVE-2026-5415

GitHubizxci/cve-2026-5415

Exploit for CVE-2026-5415 targeting WP Captcha PRO to bypass authentication. Provides a proof-of-concept for testing authentication security in…

authenticationexploitationpenetration-testing+3
2 months ago
CVE-2025-56800 preview

CVE-2025-56800

GitHubshinycolumn/cve-2025-56800

Local Authentication Bypass Vulnerability in Reolink Desktop Application

authenticationexploitationpenetration-testing+2
10 months ago
django_cve_2019_19844_poc preview

django_cve_2019_19844_poc

GitHubryu22e/django_cve_2019_19844_poc

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

authenticationexploitationpenetration-testing+2
1006 years ago
dcpwn preview

dcpwn

GitHubqax-a-team/dcpwn

an impacket-dependent script exploiting CVE-2019-1040

authenticationexploitationpenetration-testing+2
735 years ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubmurrez/cve-2026-8181

CVE-2026-8181 PoC: Burst Statistics (3.4.0–3.4.1.1) authentication bypass. Python tool — single & multi-target scans, threaded workers, TXT reports.…

authenticationexploitationpenetration-testing+3
44 months ago
magento2-session-reaper-patch preview

magento2-session-reaper-patch

GitHubwubinworks/magento2-session-reaper-patch

Patch for CVE-2025-54236(a.k.a Session Reaper) which allows customer account takeover and RCE under certain conditions. This patch is actually a…

authenticationexploitationvulnerability-analysis+2
410 months ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubthanhlam-attt/cve-2023-7028

Exploit for GitLab account takeover via CVE-2023-7028, demonstrating password reset bypass by injecting attacker email to receive reset token.

authenticationexploitationpenetration-testing+2
22 years ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubcipher1x1/cve-2026-29000

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt via JWE-wrapped unsigned JWT, enabling privilege escalation.

authenticationexploitationpenetration-testing+2
5 months ago
Previous12…8Next