Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
268 results
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
5 months ago
CVE-2019-20933 preview

CVE-2019-20933

GitHubdungsocool/cve-2019-20933

Step-by-step lab writeup demonstrating CVE-2019-20933 InfluxDB authentication bypass via forged JWT tokens, including exploitation,…

authentication-authorizationctfdatabase-security+5
3 months ago
nexus-os preview

nexus-os

GitLabnexaiceo/nexus-os

The Governed Agentic AI Operating System — Rust + Tauri 2.0 | 65 crates, 658 commands, 84 pages, 5,029 tests, 10/10 OWASP

ai-securityauthentication-authorizationcloud-security+8
4 months ago
CVE-2026-35616 preview

CVE-2026-35616

GitHub0xblackash/cve-2026-35616

CVE-2026-35616

authentication-authorizationeducationexploitation+3
15 months ago
CVE-2025-54309 preview

CVE-2025-54309

GitHubblueisbeautiful/cve-2025-54309

CrushFTP AS2 Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
1 year ago
CVE-2024-11318 preview

CVE-2024-11318

GitHubxthalach/cve-2024-11318

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

authentication-authorizationexploitationinformation-gathering+3
11 year ago
CVE-2024-5324 preview

CVE-2024-5324

GitHubrandomrobbiebf/cve-2024-5324

Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Update

authentication-authorizationexploitationmisconfiguration+3
12 years ago
CVE-2024-52429 preview

CVE-2024-52429

GitHubrandomrobbiebf/cve-2024-52429

WP Quick Setup <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin/Theme Installation

authentication-authorizationexploitationmisconfiguration+3
11 year ago
Owa-Valid-Login-Checker preview

Owa-Valid-Login-Checker

GitHubjenderal92/owa-valid-login-checker

Owa Valid Login Checker

authentication-authorizationinformation-gatheringpassword-attacks+2
3 months ago
CVE-2023-30486 preview

CVE-2023-30486

GitHubrandomrobbiebf/cve-2023-30486

Square <= 2.0.0 - Missing Authorization via activate_plugin

authentication-authorizationexploitationmisconfiguration+3
11 year ago
sudowp-postgallery preview

sudowp-postgallery

GitHubsudo-wp/sudowp-postgallery

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

authentication-authorizationcode-analysisconfiguration-auditing+3
16 months ago
CVE-2025-41646---Critical-Authentication-Bypass- preview

CVE-2025-41646---Critical-Authentication-Bypass-

GitHubgreenforcenetworks/cve-2025-41646---critical-authentication-bypass-

CVE-2025-41646 - Critical Authentication bypass

authentication-authorizationexploitationids-ips-evasion+5
11 year ago
CVE-2025-9209 preview

CVE-2025-9209

GitHubnxploited/cve-2025-9209

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

authentication-authorizationexploitationinformation-gathering+5
10 months ago
BlockGuard preview

BlockGuard

GitHubm2l33k/blockguard

BlockGuard is a Windows Data Loss Prevention (DLP) agent that intercepts and controls file access at the process level. It ensures that only…

authentication-authorizationconfiguration-auditingdata-exfiltration+4
6 months ago
CVE-2024-33676 preview

CVE-2024-33676

GitHubdersecure/cve-2024-33676

Technical disclosure of CVE-2024-33676: weak authentication on Enel X JuiceBox EV chargers enabling PII extraction, settings manipulation, and OS…

authentication-authorizationeducationembedded-systems-security+9
1 year ago
day10-nextjs-middleware-lab preview

day10-nextjs-middleware-lab

GitHubamalpvatayam67/day10-nextjs-middleware-lab

Next.js middleware auth-bypass lab (CVE-2025-29927 simulation)

authentication-authorizationeducationlabs-practice+3
11 months ago
CVE-2021-1675 preview

CVE-2021-1675

GitHubtanarchytan/cve-2021-1675

Fix without disabling Print Spooler

authentication-authorizationconfiguration-auditingmisconfiguration+2
5 years ago
asf__karaf_CVE-2022-22932_4-3-5 preview

asf__karaf_CVE-2022-22932_4-3-5

GitHubshoucheng3/asf__karaf_cve-2022-22932_4-3-5

Modulith runtime with hot deployment, dynamic configuration, JAAS-based RBAC, and centralized logging. Supports REST/API, web, and Spring Boot…

authentication-authorizationconfiguration-auditingexploitation+3
1 year ago
Previous1…131415Next