Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
168 results
cve-2026-29204-whmcs-clientarea-addonid preview

cve-2026-29204-whmcs-clientarea-addonid

GitHubbogdanrotariu/cve-2026-29204-whmcs-clientarea-addonid

Provides community notes and an optional temporary hook to guard against CVE-2026-29204, a WHMCS client area addonId ownership vulnerability, with…

authentication-authorizationcurated-resourceseducation+3
4 months ago
bulwark preview

bulwark

GitHubsoftrams/bulwark

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

api-securityauthentication-authorizationconfiguration-auditing+3
18710 months ago
apache__jspwiki_CVE-2022-46907_2-11-3 preview

apache__jspwiki_CVE-2022-46907_2-11-3

GitHubshoucheng3/apache__jspwiki_cve-2022-46907_2-11-3

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

authentication-authorizationconfiguration-auditingeducation+3
11 months ago
apache__jspwiki_CVE-2019-10078_2_11_0_M4_fixed preview

apache__jspwiki_CVE-2019-10078_2_11_0_M4_fixed

GitHubshoucheng3/apache__jspwiki_cve-2019-10078_2_11_0_m4_fixed

Exploit testing repository for Apache JSPWiki CVE-2019-10078, demonstrating a cross-site scripting vulnerability in a Java-based wiki platform with…

authentication-authorizationconfiguration-auditingeducation+3
1 year ago
Discuz-X5.0-Authentication-Bypass-Exploit-Framework preview

Discuz-X5.0-Authentication-Bypass-Exploit-Framework

GitHubcerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

authentication-authorizationdatabase-securityexploit-frameworks+4
12 months ago
CVE-2019-19033 preview

CVE-2019-19033

GitHubricardojoserf/cve-2019-19033

CVE-2019-19033 description and scripts to check the vulnerability in Jalios JCMS 10 (Authentication Bypass)

authentication-authorizationexploitationinformation-gathering+4
36 years ago
CVE-2026-8239 preview

CVE-2026-8239

GitHubaj2108/cve-2026-8239

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

authentication-authorizationeducationinformation-gathering+3
1 month ago
wp-allowed-hosts preview

wp-allowed-hosts

GitHubalash3al/wp-allowed-hosts

a plugin that protects your wp site from the CVE-2017-8295 vulnerability

authentication-authorizationdefensive-toolsmisconfiguration+2
29 years ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubh454nsec/cve-2023-42793

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

authentication-authorizationexploitationpenetration-testing+3
452 years ago
CVE-2026-27771 preview

CVE-2026-27771

GitHubportbuster1337/cve-2026-27771

CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

authentication-authorizationcontainer-securityeducation+5
193 months ago
CVE-2023-32315 preview

CVE-2023-32315

GitHubmiko550/cve-2023-32315

Openfire Console Authentication Bypass Vulnerability with RCE plugin

authentication-authorizationexploitationpayload-development+3
602 years ago
bola-CVE-2023-27524 preview

bola-CVE-2023-27524

GitHubrachidafaf/bola-cve-2023-27524

Demonstrates CVE-2023-27524 Broken Object Level Authorization (BOLA) vulnerability with vulnerable and fixed Flask API implementations for security…

api-security-testingauthentication-authorizationeducation+3
5 months ago
Zabbix-CVE-2022-23131 preview

Zabbix-CVE-2022-23131

GitHubvulnmachines/zabbix-cve-2022-23131

Zabbix-SAML-Bypass: CVE-2022-23131

authentication-authorizationexploitationpenetration-testing+2
24 years ago
CVE-2026-8347 preview

CVE-2026-8347

GitHubaj2108/cve-2026-8347

CVE-2026-8347 is an Insecure Direct Object Reference (IDOR) combined with a wrong authorization level vulnerability in Concrete CMS versions 9.5.0…

authentication-authorizationvulnerability-analysisweb-application-exploitation+1
1 month ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubgotr00t0day/cve-2022-1388

A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit…

authentication-authorizationexploitationpenetration-testing+3
52 years ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubimmersive-labs-sec/cve-2025-31161

Proof of Concept for CVE-2025-31161 / CVE-2025-2825

authentication-authorizationexploitationpenetration-testing+3
481 year ago
Blackash-CVE-2025-31161 preview

Blackash-CVE-2025-31161

GitHubdrelinss/blackash-cve-2025-31161

CVE-2025-31161

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2025-27580 preview

CVE-2025-27580

GitHubtruststacksecurity/cve-2025-27580

Exploit for CVE-2025-27580: A predictable token vulnerability in NIH BRICS through 14.0.0-67 allows unauthenticated users with a Common Access Card…

authentication-authorizationexploitationpenetration-testing+3
1 year ago
Previous12…10Next