Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
811 results
asf__cxf_CVE-2016-6812_3-0-11 preview

asf__cxf_CVE-2016-6812_3-0-11

GitHubshoucheng3/asf__cxf_cve-2016-6812_3-0-11

Open-source services framework for building and developing SOAP, RESTful, and CORBA services with support for WS-Security, JAX-WS, and JAX-RS APIs.

api-securityauthentication-authorizationcryptography+3
11 months ago
asf__nifi_CVE-2023-36542_1-22-0 preview

asf__nifi_CVE-2023-36542_1-22-0

GitHubshoucheng3/asf__nifi_cve-2023-36542_1-22-0

Automated data flow platform for processing and distributing data with built-in provenance tracking, secure configuration, and scalable pipeline…

api-securityauthentication-authorizationcloud-security+4
1 year ago
next.js_cve-2025-29927 preview

next.js_cve-2025-29927

GitHub0xpthree/next.js_cve-2025-29927

Reproduces CVE-2025-29927 middleware authorization bypass in Next.js 14.2.24 and demonstrates exploitation with curl to bypass authentication and…

authentication-authorizationids-ips-evasionpenetration-testing+3
1 year ago
CVE-2012-6066 preview

CVE-2012-6066

GitHubbongbongco/cve-2012-6066

FreeSSHD Remote Authentication Bypass Vulnerability (freeSSHd 2.1.3)

authentication-authorizationexploitationnetwork-security+2
9 years ago
jenkinsci__docker-commons-plugin_CVE-2022-20617_1-17 preview

jenkinsci__docker-commons-plugin_CVE-2022-20617_1-17

GitHubshoucheng3/jenkinsci__docker-commons-plugin_cve-2022-20617_1-17

Jenkins plugin providing shared API for Docker credential management, registry authentication, daemon configuration, and image fingerprinting across…

api-securityauthentication-authorizationcloud-infrastructure-security+3
1 year ago
CVE-2020-26061 preview

CVE-2020-26061

GitHubmissing0x00/cve-2020-26061

CVE-2020-26061 - ClickStudios Passwordstate Password Reset Portal

authentication-authorizationexploitationpenetration-testing+2
6 years ago
CVE-2023-43154-PoC preview

CVE-2023-43154-PoC

GitHubally-petitt/cve-2023-43154-poc

PoC for the type confusion vulnerability in Mac's CMS that results in authentication bypass and administrator account takeover.

authentication-authorizationexploitationpassword-attacks+3
3 years ago
CVE-2021-37580 preview

CVE-2021-37580

GitHubwing-song/cve-2021-37580

Apache ShenYu 管理员认证绕过

api-securityauthentication-authorizationexploitation+2
4 years ago
CVE-2023-49543 preview

CVE-2023-49543

GitHubgeraldoalcantara/cve-2023-49543

Book Store Management System v1.0 - Incorrect Access Control

authentication-authorizationmisconfigurationpenetration-testing+2
2 years ago
bludit-CVE-2019-17240 preview

bludit-CVE-2019-17240

GitHubjayngng/bludit-cve-2019-17240

Bypass bludit mitigation login form and upload malicious to call a rev shell

authentication-authorizationexploitationpayload-generation+2
5 years ago
aws__aws-sdk-java_CVE-2022-31159_1-12-2600 preview

aws__aws-sdk-java_CVE-2022-31159_1-12-2600

GitHubshoucheng3/aws__aws-sdk-java_cve-2022-31159_1-12-2600

Java SDK for integrating with Amazon Web Services, providing secure API access to S3, DynamoDB, EC2, and more, with built-in authentication,…

api-securityauthentication-authorizationcloud-infrastructure-security+3
1 year ago
CVE-2024-12252 preview

CVE-2024-12252

GitHubrandomrobbiebf/cve-2024-12252

SEO LAT Auto Post <= 2.2.1 - Missing Authorization to File Overwrite/Upload (Remote Code Execution)

authentication-authorizationexploitationmisconfiguration+5
1 year ago
CVE-2024-54378 preview

CVE-2024-54378

GitHubrandomrobbiebf/cve-2024-54378

Quietly Insights <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2024-27198 preview

CVE-2024-27198

GitHubrampantspark/cve-2024-27198

A PoC for CVE-2024-27198 written in Go

authentication-authorizationexploitationpenetration-testing+2
2 years ago
CVE-2024-44812-PoC preview

CVE-2024-44812-PoC

GitHubb1u3st0rm/cve-2024-44812-poc

Proof of Concept Exploit for CVE-2024-44812 - SQL Injection Authentication Bypass vulnerability in Online Complaint Site v1.0

authentication-authorizationexploitationpassword-attacks+3
2 years ago
CVE-2023-49547 preview

CVE-2023-49547

GitHubgeraldoalcantara/cve-2023-49547

Customer Support System 1.0 - SQL Injection Login Bypass

authentication-authorizationexploitationinformation-gathering+3
2 years ago
CVE-2023-52268 preview

CVE-2023-52268

GitHubsqu1dw3rm/cve-2023-52268

Authentication Bypass for FreeScout End-User Portal

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2024-4040-CrushFTP-server preview

CVE-2024-4040-CrushFTP-server

GitHubgraysignal/cve-2024-4040-crushftp-server

Exploit for CVE-2024-4040 affecting CrushFTP server in all versions before 10.7.1 and 11.1.0 on all platforms

authentication-authorizationexploitationpenetration-testing+3
2 years ago
Previous1…404142…46Next