Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
147 results
aisecplus-week01-servicenow-ai-security-incident preview

aisecplus-week01-servicenow-ai-security-incident

GitHubololadeabiola03/aisecplus-week01-servicenow-ai-security-incident

Research and analysis of the ServiceNow Virtual Agent vulnerability (CVE-2025-12420), including attack flow, MITRE ATT&CK mapping, detection…

ai-securityauthentication-authorizationcloud-security+5
3 months ago
CVE-2023-28121-WordPress-Privilege-Escalation preview

CVE-2023-28121-WordPress-Privilege-Escalation

GitHubluisdevpentest/cve-2023-28121-wordpress-privilege-escalation

Exploração prática de vulnerabilidade crítica no WordPress usando o plugin WooCommerce Payments.

authentication-authorizationeducationexploitation+4
14 months ago
Shadow-Vault preview

Shadow-Vault

GitHubjenderal92/shadow-vault

Shadow Vault – Add shadow users with SHA-512 hash, auto aging match, multiple write fallbacks.

authentication-authorizationemail-securityidentity-access-management+3
3 months ago
CVE-2026-28372-telnetd-Privilege-Escalation preview

CVE-2026-28372-telnetd-Privilege-Escalation

GitHubrohitberiwala/cve-2026-28372-telnetd-privilege-escalation

This Proof‑of‑Concept demonstrates a **Local Privilege Escalation** vulnerability in GNU inetutils `telnetd`. `telnetd` improperly passes…

authentication-authorizationexploitationpenetration-testing+2
16 months ago
CVE-2025-3604 preview

CVE-2025-3604

GitHubnxploited/cve-2025-3604

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

authentication-authorizationeducationexploitation+5
11 year ago
wordpress-CVE-2024-10924--exploit preview

wordpress-CVE-2024-10924--exploit

GitHubmaleeshaudan/wordpress-cve-2024-10924--exploit

WordPress CVE-2024-10924 Exploit for Really Simple Security plugin

authentication-authorizationexploitationpenetration-testing+3
11 year ago
CVE-2024-5324 preview

CVE-2024-5324

GitHubrandomrobbiebf/cve-2024-5324

Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Update

authentication-authorizationexploitationmisconfiguration+3
12 years ago
CVE-2025-9209 preview

CVE-2025-9209

GitHubnxploited/cve-2025-9209

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

authentication-authorizationexploitationinformation-gathering+5
10 months ago
CrushFTP-auth-bypass-CVE-2025-31161 preview

CrushFTP-auth-bypass-CVE-2025-31161

GitHub0xdtc/crushftp-auth-bypass-cve-2025-31161

Exploit for CrushFTP CVE-2025-31161 auth bypass: detects vulnerable targets, enumerates users, and creates unauthorized admin accounts through…

authentication-authorizationcommand-and-controlctf+7
11 months ago
CVE-2025-4796 preview

CVE-2025-4796

GitHubnxploited/cve-2025-4796

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

authentication-authorizationeducationexploitation+3
10 months ago
CVE-2025-54309__Enhanced_exploit preview

CVE-2025-54309__Enhanced_exploit

GitHubwhisperer1290/cve-2025-54309__enhanced_exploit

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

authentication-authorizationeducationexploitation+4
11 year ago
CVE-2025-49173 preview

CVE-2025-49173

GitHubaliyabuz25/cve-2025-49173

Security research — PoC for local root privilege escalation on macOS Mavericks 10.9.

authentication-authorizationeducationexploitation+2
9 months ago
CVE-2025-29556 preview

CVE-2025-29556

GitHub0xsu3ks/cve-2025-29556

PoC for CVE-2025-29556 creating Security Officer accounts on ExaGrid EX10 backup appliances via a low-privilege API session, enabling privilege…

api-security-testingauthentication-authorizationexploitation+4
1 year ago
CVE-2026-41940 preview

CVE-2026-41940

GitHub0xblackash/cve-2026-41940

CVE-2026-41940

authentication-authorizationcommand-and-controlexploitation+5
4 months ago
CVE-2025-8570 preview

CVE-2025-8570

GitHubnxploited/cve-2025-8570

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

authentication-authorizationeducationexploitation+6
1 year ago
CVE-2021-1675 preview

CVE-2021-1675

GitHubtanarchytan/cve-2021-1675

Fix without disabling Print Spooler

authentication-authorizationconfiguration-auditingmisconfiguration+2
5 years ago
freemius-exploit preview

freemius-exploit

GitHubrandomrobbiebf/freemius-exploit

Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update

authentication-authorizationexploitationpenetration-testing+3
3 years ago
CVE-2024-10508 preview

CVE-2024-10508

GitHububaydev/cve-2024-10508

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

authentication-authorizationeducationpassword-attacks+3
1 year ago
Previous1…6789Next