Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
650 results
BruteLoops preview

BruteLoops

GitHubimpostorkeanu/bruteloops

Protocol agnostic online password guessing API.

authenticationpassword-attackspenetration-testing+1
85
3 years ago
CVE-2024-55591-POC preview

CVE-2024-55591-POC

GitHubumchacker/cve-2024-55591-poc

Proof-of-concept exploit for CVE-2024-55591, enabling unauthenticated WebSocket CLI access to FortiOS devices, with interactive shell and admin…

authenticationexploitationpenetration-testing+3
21 year ago
zitadel preview

zitadel

GitHubzitadel/zitadel

Open-source identity and access management platform providing SSO, MFA, passkeys, OIDC, SAML, SCIM, and multi-tenant access control for developers…

authenticationauthentication-authorizationidentity-access-management+1
15.0k17h 43m ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubjulesbsz/cve-2024-10924

POC for CVE-2024-10924 written in Python

authenticationeducationexploitation+3
1 year ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubcy3erdr4g0n/cve-2024-10924

Exploit for CVE-2024-10924, a critical authentication bypass in WordPress Really Simple Security plugin (versions 9.0.0-9.1.1.1). Allows…

authenticationeducationexploitation+3
1 year ago
pingap preview

pingap

GitHubvicanso/pingap

A reverse proxy like nginx, built on pingora, simple and efficient.

api-securityauthenticationauthentication-authorization+4
1.4k1 day ago
cPanelWHM-AuthBypass preview

cPanelWHM-AuthBypass

GitHubkagantua/cpanelwhm-authbypass

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

authenticationexploitationpenetration-testing+3
114 months ago
0-click-RCE-Exploit-for-CVE-2024-10924 preview

0-click-RCE-Exploit-for-CVE-2024-10924

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-10924

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

authenticationexploitationpayload-development+4
147 months ago
CVE-2022-28601 preview

CVE-2022-28601

GitHubflaviupopescu/cve-2022-28601

A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationexploitationpenetration-testing+2
84 years ago
CVE-2024-10924-Wordpress-Docker preview

CVE-2024-10924-Wordpress-Docker

GitHubtrackflaw/cve-2024-10924-wordpress-docker

Vulnerable docker container for Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass CVE-2023-50164

authenticationexploitationlabs-practice+3
31 year ago
CVE-2026-10523-Ivanti-sentry preview

CVE-2026-10523-Ivanti-sentry

GitHubgagaltotal/cve-2026-10523-ivanti-sentry

Proof-of-concept detection tool for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520, CVE-2026-10523).…

authenticationcommand-and-controlexploitation+3
32 months ago
wordpress-really-simple-security-authn-bypass-vulnerable-application preview

wordpress-really-simple-security-authn-bypass-vulnerable-application

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-vulnerable-application

WARNING: This is a vulnerable application to test the exploit for the Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924). Run it…

authenticationexploitationlabs-practice+3
81 year ago
CVE-2024-10924-Bypass-MFA-Wordpress-LAB preview

CVE-2024-10924-Bypass-MFA-Wordpress-LAB

GitHubd1se0/cve-2024-10924-bypass-mfa-wordpress-lab

Lab environment and exploit script for CVE-2024-10924, demonstrating MFA bypass in WordPress via the Really Simple SSL plugin's skip_onboarding…

authenticationctfeducation+5
41 year ago
wordpress-cve-2024-10924-pentest preview

wordpress-cve-2024-10924-pentest

GitHubademto/wordpress-cve-2024-10924-pentest

Penetration testing report and exploit for CVE-2024-10924, a 2FA bypass in Really Simple SSL, including reconnaissance, exploitation, and remediation…

authenticationeducationexploitation+5
31 year ago
CVE-2022-28986 preview

CVE-2022-28986

GitHubflaviupopescu/cve-2022-28986

A Insecure direct object references (IDOR) vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor

authenticationeducationids-ips-evasion+3
24 years ago
CVE-2026-37749 preview

CVE-2026-37749

GitHubmenevarad007/cve-2026-37749

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

authenticationexploitationvulnerability-analysis+2
14 months ago
CVE-2026-6182-SQLI-auth preview

CVE-2026-6182-SQLI-auth

GitHubxmyronn/cve-2026-6182-sqli-auth

Proof-of-concept for SQL injection authentication bypass in Simple Content Management System PHP, allowing unauthenticated attackers to gain admin…

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubbodoinon/cve-2024-10924

Demonstrates exploitation and mitigation of CVE-2024-10924, an authentication bypass in WordPress Really Simple Security, with automated Python…

authenticationeducationexploitation+3
8 months ago
Previous12…37Next