Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
28 results
CVE-2025-29927 preview

CVE-2025-29927

GitHubdante01yoon/cve-2025-29927

Demonstration of CVE-2025-29927: Next.js middleware authentication bypass via x-middleware-subrequest header spoofing. Includes vulnerable and fixed…

authenticationeducationmisconfiguration+3
1 year ago
CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient preview

CVE-2024-40586-Windows-Coerced-Authentication-in-FortiClient

GitHubhagrid29/cve-2024-40586-windows-coerced-authentication-in-forticlient

Exploit for CVE-2024-40586: coerces Windows hosts to authenticate via a vulnerable FortiClient named pipe, enabling privilege escalation to SYSTEM or…

authenticationexploitationlateral-movement+4
11 year ago
vuln-bank-mobile preview

vuln-bank-mobile

GitHubcommando-x/vuln-bank-mobile

A deliberately vulnerable mobile banking application designed for practicing mobile security testing. Features common vulnerabilities found in…

android-securityauthenticationcryptography+8
1011 year ago
Damn-Vulnerable-Android-Components preview

Damn-Vulnerable-Android-Components

GitHubzinja-coder/damn-vulnerable-android-components

An intentionally vulnerable Android Application to demonstrate various vulnerabilities that airses in Android Components.

android-securityauthenticationctf+7
471 year ago
Aegis preview

Aegis

GitHubbeemdevelopment/aegis

A free, secure and open source app for Android to manage your 2-step verification tokens.

android-securityauthenticationauthentication-authorization+5
13.0k2 days ago
CVE-2026-7671 preview

CVE-2026-7671

GitHubcaginkyr/cve-2026-7671

Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.

android-securityauthenticationexploitation+2
24 months ago
phonepe-sensitive-data-exposure-cve-2025-5154 preview

phonepe-sensitive-data-exposure-cve-2025-5154

GitHubhonestcorrupt/phonepe-sensitive-data-exposure-cve-2025-5154

CVE-2025-5154: Proof-of-concept for unencrypted local storage of authentication tokens, PII, and KYC data in the PhonePe Android app, enabling…

android-securityauthenticationdata-exfiltration+6
11 year ago
CVE-2021-36808 preview

CVE-2021-36808

GitHubctuihu/cve-2021-36808

A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

android-securityauthenticationexploitation+2
4 years ago
django-defender preview

django-defender

GitHubjazzband/django-defender

A simple super fast django reusable app that blocks people from brute forcing login attempts

authenticationdefensive-toolspassword-attacks+1
1.1k7 months ago
igoat preview

igoat

GitHubowasp/igoat

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

authenticationcryptographydata-exfiltration+9
4613 years ago
filekey preview

filekey

GitHubrockwellshah/filekey

Offline, open-source web app for passkey-based file encryption and sharing. AES-256-GCM/HPKE, no cloud, no accounts; encrypt to recipients with…

authenticationcryptographydata-recovery+2
48418 days ago
dc34-vault preview

dc34-vault

GitHubbunnie/dc34-vault

Vault app for DC34 badge

authenticationcryptographyembedded-systems-security+2
6120 days ago
By-Poloss..-..CVE-2026-10580 preview

By-Poloss..-..CVE-2026-10580

GitHubpolosss/by-poloss..-..cve-2026-10580

Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover

authenticationexploitationinformation-gathering+3
13 months ago
CVE-2021-36460 preview

CVE-2021-36460

GitHubmartinfrancois/cve-2021-36460

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

authenticationexploitationmobile-security+2
1 month ago
CVE-2023-1665 preview

CVE-2023-1665

GitHub0xsu3ks/cve-2023-1665

CVE-2023-1665 - Twake App

authenticationinformation-gatheringpenetration-testing+2
3 years ago
pyrexecd preview

pyrexecd

GitHubeuske/pyrexecd

Standalone SSH server for Windows

authenticationremote-access-toolutilities-frameworks
2263 years ago
oauthseeker preview

oauthseeker

GitHubpraetorian-inc/oauthseeker

A malicious OAuth application that can be leveraged for both internal and external phishing attacks targeting Microsoft Azure and Office365 users.

authenticationcloud-securityidentity-access-management+6
1791 year ago
CVE-2022-22845-Exploit preview

CVE-2022-22845-Exploit

GitHubomribaso/cve-2022-22845-exploit

Exploit for CVE-2022-22845 - Unauthenticated Admin Takeover On QXIP SIPCAPTURE Homer-App up to 1.4.27

authenticationexploitationpenetration-testing+2
24 years ago
Previous12Next