Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
203 results
CVE-2025-8570 preview

CVE-2025-8570

GitHubnxploited/cve-2025-8570

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

authentication-authorizationeducationexploitation+6
0 years ago
Password-Strength-Evaluator preview

Password-Strength-Evaluator

GitHubjenderal92/password-strength-evaluator

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

authentication-authorizationdefensive-toolseducation+1
3 months ago
synapse preview
Archived

synapse

GitHubmatrix-org/synapse

Synapse: Matrix homeserver written in Python/Twisted.

api-securityauthentication-authorizationencryption-decryption-tools+3
12.1k2 years ago
symfony preview

symfony

GitHubsymfony/symfony

The Symfony PHP framework

api-securityauthentication-authorizationconfiguration-auditing+3
31.1k7 days ago
YourMemory preview

YourMemory

GitHubsachitrafa/yourmemory

Agentic AI memory with Ebbinghaus forgetting curve decay. +16pp better recall than Mem0 on LoCoMo.

ai-securityauthentication-authorizationforensics+5
2651 month ago
CVE-2025-47227_CVE-2025-47228 preview

CVE-2025-47227_CVE-2025-47228

GitHubsynacktiv/cve-2025-47227_cve-2025-47228

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

authentication-authorizationcommand-and-controlexploitation+3
111 year ago
CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC preview

CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC

GitHubdollarboysushil/cve-2024-47533-cobbler-xmlrpc-authentication-bypass-rce-exploit-poc

CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated…

authentication-authorizationcommand-and-controlexploitation+6
81 year ago
caos-os preview

caos-os

GitHubdigicred-oss/caos-os

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

authentication-authorizationdefensive-toolsinformation-gathering+2
27 days ago
CVE-2026-28372-telnetd-Privilege-Escalation preview

CVE-2026-28372-telnetd-Privilege-Escalation

GitHubrohitberiwala/cve-2026-28372-telnetd-privilege-escalation

This Proof‑of‑Concept demonstrates a **Local Privilege Escalation** vulnerability in GNU inetutils `telnetd`. `telnetd` improperly passes…

authentication-authorizationexploitationpenetration-testing+2
16 months ago
bola-CVE-2023-27524 preview

bola-CVE-2023-27524

GitHubrachidafaf/bola-cve-2023-27524

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

api-security-testingauthentication-authorizationeducation+3
5 months ago
ff4j__ff4j_CVE-2022-44262_1-8-13 preview

ff4j__ff4j_CVE-2022-44262_1-8-13

GitHubshoucheng3/ff4j__ff4j_cve-2022-44262_1-8-13

Feature toggle framework for Java enabling runtime feature activation, role-based access, AOP-driven toggling, monitoring, audit trails, and a web…

authentication-authorizationconfiguration-auditingdevsecops+3
1 year ago
milvus-auth-audit preview

milvus-auth-audit

GitHubqianlijaingshan/milvus-auth-audit

Milvus 认证安全检测脚本:CVE-2025-64513 (sourceid后门) / CVE-2026-26190 (/expr弱token) / 内部端口53100

api-security-testingauthentication-authorizationdatabase-security+4
1 month ago
CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation preview

CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

GitHubninjazan420/cve-2026-1529-poc-keycloak-unauthorized-registration-via-improper-invitation-token-validation

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

authentication-authorizationeducationexploitation+4
6 months ago
svja preview

svja

GitHubtheronielanddaronpodcastshow/svja

The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

api-security-testingauthentication-authorizationeducation+5
138 months ago
CVE-2026-53625-GLPI-PoC preview

CVE-2026-53625-GLPI-PoC

GitHub7h30th3r0n3/cve-2026-53625-glpi-poc

GLPI Privilege Escalation via authtype Manipulation PoC - CVE-2026-53625. Ethical PoC for the GLPI vulnerability allowing a Technician to take full…

api-security-testingauthentication-authorizationexploitation+4
1 month ago
headscale preview

headscale

GitHubjuanfont/headscale

An open source, self-hosted implementation of the Tailscale control server

authentication-authorizationcloud-infrastructure-securityidentity-access-management+2
43.6k2 days ago
API-Security-Checklist preview

API-Security-Checklist

GitHubshieldfy/api-security-checklist

Checklist of the most important security countermeasures when designing, testing, and releasing your API

api-securityauthentication-authorizationcurated-resources+4
23.3k1 month ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.9k12 days ago
Previous123…12Next