Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
97 results
Discuz-X5.0-Authentication-Bypass-Exploit-Framework preview

Discuz-X5.0-Authentication-Bypass-Exploit-Framework

GitHubcerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

authentication-authorizationdatabase-securityexploit-frameworks+4
1
1 month ago
CVE-2023-33730 preview

CVE-2023-33730

GitHubsahiloj/cve-2023-33730

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

authentication-authorizationeducationexploitation+8
16 months ago
CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise preview

CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise

GitHubsteampunk424/cve-2025-58434-unauthenticated-password-reset-flowwise

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

authentication-authorizationexploitationpenetration-testing+3
14 months ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubrubikcuv5/cve-2018-10933

libSSH-Authentication-Bypass

authentication-authorizationexploitationinformation-gathering+3
14 years ago
CVE-2025-31161 preview

CVE-2025-31161

GitHub0xblackash/cve-2025-31161

CVE-2025-31161

authentication-authorizationeducationexploitation+3
14 months ago
CVE-2026-44595 preview

CVE-2026-44595

GitHubex-cal1bur/cve-2026-44595

# CVE-2026-44595 YAMCS Unauthorized User Enumeration via IAM API

api-securityauthentication-authorizationexploitation+3
3 months ago
Automated-scanner-CVE-2026-41940 preview

Automated-scanner-CVE-2026-41940

GitHubsardine-web/automated-scanner-cve-2026-41940

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

authentication-authorizationcommand-and-controlexploitation+8
13 months ago
CVE-2025-64446 preview

CVE-2025-64446

GitHub0xblackash/cve-2025-64446

CVE-2025-64446

authentication-authorizationexploitationpenetration-testing+3
4 months ago
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
4 months ago
Silverpeas-AuthBypass-CVE-2024-36042 preview

Silverpeas-AuthBypass-CVE-2024-36042

GitHubha5ant/silverpeas-authbypass-cve-2024-36042

Python PoC for CVE-2024-36042 authentication bypass in Silverpeas < 6.3.5. Features version detection, multi-threaded user enumeration, message…

authentication-authorizationexploitationinformation-gathering+5
3 months ago
CVE-2024-11318 preview

CVE-2024-11318

GitHubxthalach/cve-2024-11318

This repository details an IDOR vulnerability in AbsysNet 2.3.1, which allows a remote attacker to brute-force session IDs via the /cgi-bin/ocap/…

authentication-authorizationexploitationinformation-gathering+3
11 year ago
wordpress-CVE-2024-10924--exploit preview

wordpress-CVE-2024-10924--exploit

GitHubmaleeshaudan/wordpress-cve-2024-10924--exploit

WordPress CVE-2024-10924 Exploit for Really Simple Security plugin

authentication-authorizationexploitationpenetration-testing+3
11 year ago
CVE-2024-9821 preview

CVE-2024-9821

GitHubrandomrobbiebf/cve-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
11 year ago
CVE-2024-9106 preview

CVE-2024-9106

GitHubrandomrobbiebf/cve-2024-9106

Wechat Social login <= 1.3.0 - Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
11 year ago
Blackash-CVE-2025-20343 preview

Blackash-CVE-2025-20343

GitHubfevar54/blackash-cve-2025-20343

Technical documentation and proof-of-concept for CVE-2025-20343, a high-severity denial-of-service vulnerability in Cisco ISE allowing…

authentication-authorizationexploitationinformation-gathering+2
9 months ago
CVE-2025-54309 preview

CVE-2025-54309

GitHubblueisbeautiful/cve-2025-54309

CrushFTP AS2 Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
1 year ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubethan-repo-lab4b6/cve-2022-36537

Python exploit for CVE-2022-36537, an authentication bypass in ZK Framework affecting R1Soft Server Backup Manager, allowing retrieval of web context…

authentication-authorizationexploitationinformation-gathering+3
11 months ago
CVE-2025-3604 preview

CVE-2025-3604

GitHubnxploited/cve-2025-3604

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

authentication-authorizationeducationexploitation+5
11 year ago
Previous123456Next