Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
33 results
CVE-2026-72815-poc preview

CVE-2026-72815-poc

GitHubsaku0512/cve-2026-72815-poc

Local Go PoC demonstrating CVE-2026-72815, an X-Forwarded-For IP spoofing flaw in go-chi/chi middleware.RealIP that bypasses IP-based ACLs, with a…

authenticationcode-analysisdefensive-tools+5
1 month ago
Hack-Captive-Portal preview
Archived

Hack-Captive-Portal

GitHubpriyankvadaliya/hack-captive-portal

This script helps to pass through the captive portals in public Wi-Fi networks. It hijacks IP and MAC from somebody who is already connected and…

authenticationimpersonation-toolsnetwork-access-control+2
328 years ago
CP-PLUS-EZ-P21-CVE-2026-65893-65894 preview

CP-PLUS-EZ-P21-CVE-2026-65893-65894

GitHubcybervinner/cp-plus-ez-p21-cve-2026-65893-65894

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

authenticationeducationembedded-systems-security+5
2 months ago
CVE-2017-7921 preview

CVE-2017-7921

GitHub0xf3d0rq/cve-2017-7921

CVE-2017-7921 is a critical vulnerability (CVSS score: 9.8) affecting multiple Hikvision IP camera and DVR models, first disclosed in 2017. It stems…

authenticationexploitationinformation-gathering+3
110 months ago
CVE-2025-67158 preview

CVE-2025-67158

GitHubremenis/cve-2025-67158

Revotech I6032W-FHW IP camera firmware fails to validate authentication fields in API requests, allowing attackers to bypass authentication and…

authenticationexploitationiot-security+3
9 months ago
CVE-2023-27100 preview

CVE-2023-27100

GitHubfabdotnet/cve-2023-27100

Exploit for CVE-2023-27100 bypassing pfSense anti-brute force protection via crafted X-Forwarded-For headers and anti-CSRF tokens to evade sshguard…

authenticationexploitationids-ips-evasion+3
2 years ago
CVE-2021-29441 preview

CVE-2021-29441

GitHubbysinks/cve-2021-29441

Exploit for CVE-2021-29441 in Alibaba Nacos, enabling unauthorized addition of user accounts by sending crafted requests to the target IP.

authenticationexploitationpenetration-testing+2
24 years ago
CVE-2026-6274 preview

CVE-2026-6274

GitHubbugresearch/cve-2026-6274

Proof-of-concept exploit for CVE-2026-6274, an authentication bypass in Redline WR3200 routers allowing unauthorized password change via static…

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2025-1868 preview

CVE-2025-1868

GitHubitres-labs/cve-2025-1868

CVE-2025-1868: Advanced IP Scanner & Advanced Port Scanner NTLM Leakage HTTP Tester

authenticationexploitationinformation-gathering+3
28 months ago
CVE-2025-67159 preview

CVE-2025-67159

GitHubremenis/cve-2025-67159

Vatilon-based IP camera firmware allows authentication bypass and plaintext credential exposure via web.cgi API requests.

authenticationexploitationhardware-iot-security+3
9 months ago
Modlishka preview

Modlishka

GitHubdrk1wi/modlishka

Modlishka. Reverse Proxy.

authenticationimpersonation-toolspenetration-testing+6
5.4k1 month ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
CredKing preview

CredKing

GitHubustayready/credking

Password spraying using AWS Lambda for IP rotation

authenticationcloud-securityidentity-access-management+3
6708 years ago
dahua-cve-research preview

dahua-cve-research

GitHubumair-aziz025/dahua-cve-research

Dahua IP camera CVE research toolkit (CVE-2021-33044/33045, CVE-2025-31700/31701)

authenticationeducationexploitation+5
296 months ago
CVE-2025-63667 preview

CVE-2025-63667

GitHubremenis/cve-2025-63667

Vatilon-based IP camera firmwares issue Session-Id tokens without verifying credentials, allowing attackers to obtain sessions and retrieve plaintext…

api-securityauthenticationembedded-systems-security+4
111 months ago
evilgophish preview

evilgophish

GitHubfin3ss3g0d/evilgophish

evilginx3 + gophish

authenticationcommand-and-controlpenetration-testing+5
2.0k2 years ago
NTLMRecon preview

NTLMRecon

GitHubpwnfoo/ntlmrecon

Enumerate information from NTLM authentication enabled web endpoints 🔎

authenticationinformation-gatheringnetwork-security+3
5101 year ago
device-pharmer preview

device-pharmer

GitHubdanmcinerney/device-pharmer

Opens 1K+ IPs or Shodan search results and attempts to login

authenticationinformation-gatheringnetwork-mapping+5
1497 years ago
Previous12Next