Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
133 results
route-detect preview

route-detect

GitHubmschwager/route-detect

Find authentication (authn) and authorization (authz) security bugs in web application routes.

authenticationstatic-analysisvulnerability-analysis+1
280
11 months ago
CVE-2024-8465-PoC preview

CVE-2024-8465-PoC

GitHubsholls000/cve-2024-8465-poc

Intentionally vulnerable web application demonstrating SQL injection vulnerabilities (CVE-2024-8465) for educational purposes, including…

authenticationdatabase-securityeducation+3
7 months ago
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
3 months ago
CVE-2025-56800 preview

CVE-2025-56800

GitHubshinycolumn/cve-2025-56800

Local Authentication Bypass Vulnerability in Reolink Desktop Application

authenticationexploitationpenetration-testing+2
10 months ago
OWA-Password-Sprayer preview

OWA-Password-Sprayer

GitHubh3x0v3rl0rd/owa-password-sprayer

OWA Password Sprayer

authenticationpassword-attackspenetration-testing+2
1 year ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubthanhlam-attt/cve-2023-7028

Exploit for GitLab account takeover via CVE-2023-7028, demonstrating password reset bypass by injecting attacker email to receive reset token.

authenticationexploitationpenetration-testing+2
22 years ago
django_cve_2019_19844_poc preview

django_cve_2019_19844_poc

GitHubryu22e/django_cve_2019_19844_poc

PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)

authenticationexploitationpenetration-testing+2
1006 years ago
dcpwn preview

dcpwn

GitHubqax-a-team/dcpwn

an impacket-dependent script exploiting CVE-2019-1040

authenticationexploitationpenetration-testing+2
725 years ago
CVE-2019-12476 preview

CVE-2019-12476

GitHub0katz/cve-2019-12476

PoC for CVE-2019-12476, a Windows authentication bypass in ManageEngine ADSelfService Plus that provides an unauthenticated SYSTEM shell via crafted…

authenticationexploitationpenetration-testing+2
436 years ago
grafana-CVE-2018-15727 preview

grafana-CVE-2018-15727

GitHubu238/grafana-cve-2018-15727

a small utility to generate a cookie in order to exploit a grafana vulnerability (CVE-2018-15727)

authenticationexploitationpenetration-testing+2
227 years ago
CVE-2024-4040 preview

CVE-2024-4040

GitHubrbih-boulanouar/cve-2024-4040

Proof-of-concept exploit for CVE-2024-4040, a server-side template injection in CrushFTP allowing unauthenticated file read, authentication bypass,…

authenticationexploitationpenetration-testing+2
152 years ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubl0ggg/cve-2026-55040

Exploit code for CVE-2026-55040, it can create auth header for any validate account.

authenticationexploitationpenetration-testing+2
31 month ago
cve-2021-33045 preview

cve-2021-33045

GitHubdongpohezui/cve-2021-33045

Exploit for Dahua camera authentication bypass (CVE-2021-33045) using mitmproxy to intercept and modify login requests to /RPC2_Login.

authenticationexploitationvulnerability-analysis+2
94 years ago
CVE-2021-44910_SpringBlade preview

CVE-2021-44910_SpringBlade

GitHubw000i/cve-2021-44910_springblade

SpringBlade框架JWT认证的漏洞检测工具

authenticationexploitationpenetration-testing+2
111 year ago
CVE-2022-28601 preview

CVE-2022-28601

GitHubflaviupopescu/cve-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationexploitationpenetration-testing+2
84 years ago
CVE-2026-60206 preview

CVE-2026-60206

GitHubdebajyoti0-0/cve-2026-60206

Technical analysis and Proof-of-Concept for CVE-2026-60206, a critical Oracle WebLogic Server SAML authentication bypass vulnerability.

authenticationexploitationpenetration-testing+2
1 month ago
CVE-2023-0264 preview

CVE-2023-0264

GitHubtwwd/cve-2023-0264

A small PoC for the Keycloak vulnerability CVE-2023-0264

authenticationexploitationvulnerability-analysis+1
73 years ago
CVE-2026-41940-Exploit-PoC preview

CVE-2026-41940-Exploit-PoC

GitHubdefacto-ridgepole254/cve-2026-41940-exploit-poc

Test authentication bypass vulnerabilities in cPanel and WHM using this proof of concept exploit tool written in Go.

authenticationexploitationpenetration-testing+3
15 days ago
Previous12…8Next