Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
811 results
CVE-2024-50477 preview

CVE-2024-50477

GitHubrandomrobbiebf/cve-2024-50477

Stacks Mobile App Builder <= 5.2.3 - Authentication Bypass via Account Takeover

authentication-authorizationexploitationinformation-gathering+3
1 year ago
apache__nifi_CVE-2022-33140_1-16-22 preview

apache__nifi_CVE-2022-33140_1-16-22

GitHubshoucheng3/apache__nifi_cve-2022-33140_1-16-22

Automated data flow processing and distribution system with secure configuration, provenance tracking, and extensible plugin architecture for…

api-securityauthentication-authorizationcloud-security+4
1 year ago
CVE-2023-27350-PoC preview

CVE-2023-27350-PoC

GitHub0xb0y426/cve-2023-27350-poc

Proof-of-concept exploit for CVE-2023-27350 authentication bypass in PaperCut MF/NG, allowing unauthenticated interaction with vulnerable print…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2020-24030 preview

CVE-2020-24030

GitHubunderprotection/cve-2020-24030

Proof-of-concept for CVE-2020-24030: weak token expiration in ForLogic Qualiex v1/v3 enabling remote unauthenticated privilege escalation and…

authentication-authorizationexploitationpenetration-testing+3
6 years ago
CVE-2024-5326-Poc preview

CVE-2024-5326-Poc

GitHubcve-2024/cve-2024-5326-poc

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

authentication-authorizationexploitationmisconfiguration+3
2 years ago
CVE-2024-12172 preview

CVE-2024-12172

GitHubrandomrobbiebf/cve-2024-12172

WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses <= 3.2.21 - Missing Authorization to Authenticated…

authentication-authorizationexploitationmisconfiguration+3
1 year ago
CVE-2023-47564 preview

CVE-2023-47564

GitHubc411e/cve-2023-47564

CVE-2023-47564

authentication-authorizationinformation-gatheringpenetration-testing+2
2 years ago
CVE-2024-11643 preview

CVE-2024-11643

GitHubrandomrobbiebf/cve-2024-11643

Accessibility by AllAccessible <= 1.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Option Update

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2024-8349-and-CVE-2024-8350 preview

CVE-2024-8349-and-CVE-2024-8350

GitHubkarlemilnikka/cve-2024-8349-and-cve-2024-8350

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

authentication-authorizationexploitationpenetration-testing+3
2 years ago
CVE-2024-9890 preview

CVE-2024-9890

GitHubrandomrobbiebf/cve-2024-9890

User Toolkit <= 1.2.3 - Authenticated (Subscriber+) Authentication Bypass

authentication-authorizationexploitationpenetration-testing+2
1 year ago
middleware-auth-bypass preview

middleware-auth-bypass

GitHubvalgrace/middleware-auth-bypass

CVE-2025-29927 ~ a poc of the next.js middleware authentication bypass

authentication-authorizationexploitationpenetration-testing+2
1 year ago
ABO.CMS-EXPLOIT-Unauthenticated-Login-Bypass-CVE-2024-25227 preview

ABO.CMS-EXPLOIT-Unauthenticated-Login-Bypass-CVE-2024-25227

GitHubthetrueartist/abo.cms-exploit-unauthenticated-login-bypass-cve-2024-25227

SQL injection exploit for ABO.CMS 5.8 that bypasses authentication via the tb_login parameter, granting unauthenticated admin panel access. Includes…

authentication-authorizationexploitationpenetration-testing+2
2 years ago
CVE-2023-32749 preview

CVE-2023-32749

GitHubxcr-19/cve-2023-32749

PoC for CVE-2023-32749 affecting Pydio Cells

authentication-authorizationexploitationpenetration-testing+3
2 years ago
CVE-2024-10924-PoC preview

CVE-2024-10924-PoC

GitHubhunt3r850/cve-2024-10924-poc

Proof-of-concept exploit for CVE-2024-10924, an authentication bypass vulnerability in the Really Simple Security WordPress plugin, enabling MFA…

authentication-authorizationexploitationpenetration-testing+2
1 year ago
CVE-2022-37017 preview

CVE-2022-37017

GitHubapeppels/cve-2022-37017

Bypass for Symantec Endpoint Protection's Client User Interface Password

authentication-authorizationbinary-exploitationexploitation+4
2 years ago
CVE-2024-50478 preview

CVE-2024-50478

GitHubrandomrobbiebf/cve-2024-50478

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubasg-castle/cve-2023-27350

Proof-of-concept exploit for CVE-2023-27350 in PaperCut NG; exploits SetupCompleted access-control flaw to bypass authentication and execute code as…

authentication-authorizationexploitationpenetration-testing+3
2 years ago
CVE-2024-10924 preview

CVE-2024-10924

GitHubsariamubeen/cve-2024-10924

Python exploit for CVE-2024-10924 that bypasses Two-Factor Authentication in the Really Simple SSL WordPress plugin, enabling unauthorized…

authentication-authorizationeducationexploitation+3
1 year ago
Previous1…414243…46Next