Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
299 results
CVE-2024-5324 preview

CVE-2024-5324

GitHubrandomrobbiebf/cve-2024-5324

Login/Signup Popup ( Inline Form + Woocommerce ) 2.7.1 - 2.7.2 - Missing Authorization to Arbitrary Options Update

authentication-authorizationexploitationmisconfiguration+3
1
2 years ago
CVE-2024-9822 preview

CVE-2024-9822

GitHubrandomrobbiebf/cve-2024-9822

Pedalo Connector <= 2.0.5 - Authentication Bypass to Administrator

authentication-authorizationexploitationpenetration-testing+3
11 year ago
CVE-2024-9821 preview

CVE-2024-9821

GitHubrandomrobbiebf/cve-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
11 year ago
CVE-2026-1729-PoC-AdForest-WordPress-Authentication-Bypass preview

CVE-2026-1729-PoC-AdForest-WordPress-Authentication-Bypass

GitHubninjazan420/cve-2026-1729-poc-adforest-wordpress-authentication-bypass

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions including, 6.0.12. This is due to the plugin not properly…

authentication-authorizationexploitationpenetration-testing+3
6 months ago
CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation preview

CVE-2026-1529-PoC-keycloak-unauthorized-registration-via-improper-invitation-token-validation

GitHubninjazan420/cve-2026-1529-poc-keycloak-unauthorized-registration-via-improper-invitation-token-validation

CVE-2026-1529 (PoC) is a critical vulnerability in Keycloak that allows unauthorized organization registration through improper invitation token…

authentication-authorizationeducationexploitation+4
6 months ago
CVE-2025-9209 preview

CVE-2025-9209

GitHubnxploited/cve-2025-9209

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

authentication-authorizationexploitationinformation-gathering+5
9 months ago
CVE-2025-8359 preview

CVE-2025-8359

GitHubnxploited/cve-2025-8359

AdForest <= 6.0.9 - Authentication Bypass to Admin

authentication-authorizationexploitationpenetration-testing+2
10 months ago
CVE-2025-8570 preview

CVE-2025-8570

GitHubnxploited/cve-2025-8570

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

authentication-authorizationeducationexploitation+6
11 months ago
CVE-2025-67070-Intelbras-CFTV-MFA-Bypass preview

CVE-2025-67070-Intelbras-CFTV-MFA-Bypass

GitHubteteco/cve-2025-67070-intelbras-cftv-mfa-bypass

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

authentication-authorizationexploitationpenetration-testing+3
7 months ago
poc-cve-2016-10555 preview

poc-cve-2016-10555

GitHubcircuitsoul/poc-cve-2016-10555

Change the algorithm RS256(asymmetric) to HS256(symmetric) - POC (CVE-2016-10555)

authentication-authorizationencryption-decryption-toolsexploitation+3
15 years ago
CVE-2024-52429 preview

CVE-2024-52429

GitHubrandomrobbiebf/cve-2024-52429

WP Quick Setup <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin/Theme Installation

authentication-authorizationexploitationmisconfiguration+3
11 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubricsirigu/cve-2025-29927

A deliberately Next.js app, vulnerable to CVE-2025-29927, Authorization Bypass

authentication-authorizationeducationlabs-practice+3
11 year ago
CVE-2024-4875 preview

CVE-2024-4875

GitHubrandomrobbiebf/cve-2024-4875

HT Mega – Absolute Addons For Elementor <= 2.5.2 - Missing Authorization to Options Update

authentication-authorizationexploitationmisconfiguration+2
12 years ago
Password-Strength-Evaluator preview

Password-Strength-Evaluator

GitHubjenderal92/password-strength-evaluator

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

authentication-authorizationdefensive-toolseducation+1
2 months ago
CVE-2024-4898 preview

CVE-2024-4898

GitHubgh-ost00/cve-2024-4898

CVE-2024-4898 InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.38 - Missing Authorization to Unauthenticated API setup/Arbitrary Options…

authentication-authorizationexploitationpenetration-testing+2
2 years ago
CVE-2025-27580 preview

CVE-2025-27580

GitHubtruststacksecurity/cve-2025-27580

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2024-8349-and-CVE-2024-8350 preview

CVE-2024-8349-and-CVE-2024-8350

GitHubkarlemilnikka/cve-2024-8349-and-cve-2024-8350

Authenticated Privilege Escalation to Admin exploiting Uncanny Groups for LearnDash.

authentication-authorizationexploitationpenetration-testing+3
1 year ago
bludit-CVE-2019-17240 preview

bludit-CVE-2019-17240

GitHubjayngng/bludit-cve-2019-17240

Bypass bludit mitigation login form and upload malicious to call a rev shell

authentication-authorizationexploitationpayload-generation+2
5 years ago
Previous1…678…17Next