Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
328 results
vulnerable-nextjs-14-CVE-2025-29927 preview

vulnerable-nextjs-14-CVE-2025-29927

GitHubsugib3o/vulnerable-nextjs-14-cve-2025-29927

vulnerable-nextjs-14-CVE-2025-29927

authentication-authorizationeducationlabs-practice+3
7 months ago
CVE-2018-0114-Exploit preview

CVE-2018-0114-Exploit

GitHubpandora-research/cve-2018-0114-exploit

Exploit for CVE-2018-0114: re-signs JWT tokens by embedding an attacker-controlled public key in the JWS header, bypassing authentication in…

authentication-authorizationencryption-decryption-toolsexploitation+2
4 years ago
Blackash-CVE-2025-31161 preview

Blackash-CVE-2025-31161

GitHubdrelinss/blackash-cve-2025-31161

CVE-2025-31161

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2018-10933_ssh preview

CVE-2018-10933_ssh

GitHublikekabin/cve-2018-10933_ssh

Python exploit for CVE-2018-10933 that bypasses libssh server authentication and spawns an unauthenticated shell on vulnerable SSH servers.

authentication-authorizationexploitationpenetration-testing+3
7 years ago
freemius-exploit preview

freemius-exploit

GitHubrandomrobbiebf/freemius-exploit

Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update

authentication-authorizationexploitationpenetration-testing+3
3 years ago
keycloak__keycloak_CVE-2014-3656_1-0-5-Final preview

keycloak__keycloak_CVE-2014-3656_1-0-5-Final

GitHubshoucheng3/keycloak__keycloak_cve-2014-3656_1-0-5-final

Open-source identity and access management solution providing authentication, user federation, single sign-on, and fine-grained authorization for…

api-securityauthentication-authorizationcloud-security+3
6 months ago
CVE-2023-52268 preview

CVE-2023-52268

GitHubsqu1dw3rm/cve-2023-52268

Authentication Bypass for FreeScout End-User Portal

authentication-authorizationexploitationpenetration-testing+3
1 year ago
asf__nifi_CVE-2023-36542_1-22-0 preview

asf__nifi_CVE-2023-36542_1-22-0

GitHubshoucheng3/asf__nifi_cve-2023-36542_1-22-0

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

api-securityauthentication-authorizationcloud-security+4
1 year ago
apache__nifi_CVE-2022-33140_1-16-22 preview

apache__nifi_CVE-2022-33140_1-16-22

GitHubshoucheng3/apache__nifi_cve-2022-33140_1-16-22

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

api-securityauthentication-authorizationcloud-security+4
1 year ago
CVE-2023-4696 preview

CVE-2023-4696

GitHubmnqazi/cve-2023-4696

https://medium.com/@mnqazi/cve-2023-4696-account-takeover-due-to-improper-handling-of-jwt-tokens-in-memos-v0-13-2-13104e1412f3

authentication-authorizationexploitationpenetration-testing+2
2 years ago
CVE-2022-37017 preview

CVE-2022-37017

GitHubapeppels/cve-2022-37017

Bypass for Symantec Endpoint Protection's Client User Interface Password

authentication-authorizationbinary-exploitationexploitation+4
2 years ago
CVE-2023-43154-PoC preview

CVE-2023-43154-PoC

GitHubally-petitt/cve-2023-43154-poc

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

authentication-authorizationexploitationpassword-attacks+3
2 years ago
freeipa preview

freeipa

GitHubfreeipa/freeipa

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

authenticationauthentication-authorizationcryptography+2
1.3k9 days ago
casbin preview

casbin

GitHubapache/casbin

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

api-securityauthenticationauthentication-authorization+2
20.3k8 days ago
CVE-2026-29000-pac4j-jwt preview

CVE-2026-29000-pac4j-jwt

GitHubstrikoder-premium/cve-2026-29000-pac4j-jwt

CVE-2026-29000 PoC: pac4j-jwt PlainJWT-in-JWE authentication bypass.

authentication-authorizationexploitationpenetration-testing+2
33 months ago
keycloak preview

keycloak

GitHubkeycloak/keycloak

Open Source Identity and Access Management For Modern Applications and Services

api-securityauthenticationauthentication-authorization+3
36.3k6 days ago
dex preview

dex

GitHubdexidp/dex

OpenID Connect (OIDC) identity and OAuth 2.0 provider with pluggable connectors

authenticationauthentication-authorizationcloud-infrastructure-security+4
11.1k23 days ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubtypeconfused/cve-2026-24061

GNU telnetd service from GNU InetUtils authentication-bypass

authentication-authorizationexploitationpenetration-testing+2
7 months ago
Previous1…171819Next