Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
546
4 years ago
ScreenConnect-AuthBypass-RCE preview

ScreenConnect-AuthBypass-RCE

GitHubw01fh4cker/screenconnect-authbypass-rce

Exploit script for CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, enabling authentication bypass and remote code execution with user…

authentication-authorizationexploitationpenetration-testing+3
1122 years ago
RCity-CVE-2024-27198 preview

RCity-CVE-2024-27198

GitHubstuub/rcity-cve-2024-27198

CVE-2024-27198 & CVE-2024-27199 PoC - RCE, Admin Account Creation, Enum Users, Server Information

authentication-authorizationeducationexploitation+4
352 years ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubnxploited/cve-2025-3102

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

authentication-authorizationeducationexploitation+3
81 year ago
CVE-2026-13610 preview

CVE-2026-13610

GitHubghostpels/cve-2026-13610

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

authentication-authorizationexploitationpenetration-testing+4
19 days ago
CVE-2026-8732 preview

CVE-2026-8732

GitHubjenderal92/cve-2026-8732

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

authentication-authorizationexploitationpenetration-testing+4
33 months ago
CVE-2025-31161 preview

CVE-2025-31161

GitHub0xgh057r3c0n/cve-2025-31161

🛡️ CVE-2025-31161 - CrushFTP User Creation Authentication Bypass Exploit

authentication-authorizationeducationexploitation+3
51 year ago
CVE-2024-0204 preview

CVE-2024-0204

GitHubm-cetin/cve-2024-0204

This script exploits the CVE-2024-0204 vulnerability in Fortra GoAnywhere MFT, allowing the creation of unauthorized administrative users, for…

authentication-authorizationeducationexploitation+3
22 years ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubrhz0d/cve-2025-3102

Wordpress SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation

authentication-authorizationeducationexploitation+3
21 year ago
zeroheight-account-verification-bypass-CVE-2025-65925 preview

zeroheight-account-verification-bypass-CVE-2025-65925

GitHubsneden/zeroheight-account-verification-bypass-cve-2025-65925

Independent security finding – Zeroheight account creation bypass via missing verification enforcement (patched June 2025)

authentication-authorizationexploitationmisconfiguration+3
28 months ago
CVE-2025-2825 preview

CVE-2025-2825

GitHubiteride/cve-2025-2825

Detailed analysis and PoC exploit for CVE-2025-2825, an authentication bypass in CrushFTP. Includes nuclei templates, multi-threaded scanner, and…

authentication-authorizationexploitationpayload-development+3
111 months ago
CVE-2025-54309__Enhanced_exploit preview

CVE-2025-54309__Enhanced_exploit

GitHubwhisperer1290/cve-2025-54309__enhanced_exploit

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

authentication-authorizationeducationexploitation+4
10 years ago
CVE-2024-4898 preview

CVE-2024-4898

GitHubgh-ost00/cve-2024-4898

Proof-of-concept exploit for CVE-2024-4898, demonstrating unauthenticated API setup, arbitrary options update, and administrative user creation in…

authentication-authorizationexploitationpenetration-testing+2
2 years ago
OpenSSL_1_1_1_g preview

OpenSSL_1_1_1_g

GitHubsatheesh575555/openssl_1_1_1_g

Robust toolkit implementing TLS/SSL protocols and a full-strength cryptographic library for encryption, decryption, certificate creation, and secure…

authentication-authorizationcryptographyencryption-decryption-tools+2
4 years ago
monitorr-exploit-toolkit preview

monitorr-exploit-toolkit

GitHubsec-it/monitorr-exploit-toolkit

Multiple exploits for Monitorr

authentication-authorizationexploitationinformation-gathering+3
105 years ago
CVE-2025-54309 preview

CVE-2025-54309

GitHubblueisbeautiful/cve-2025-54309

CrushFTP AS2 Authentication Bypass

authentication-authorizationexploitationinformation-gathering+3
1 year ago
CVE-2025-29556 preview

CVE-2025-29556

GitHub0xsu3ks/cve-2025-29556

PoC for CVE-2025-29556 creating Security Officer accounts on ExaGrid EX10 backup appliances via a low-privilege API session, enabling privilege…

api-security-testingauthentication-authorizationexploitation+4
1 year ago
CVE-2025-3102 preview

CVE-2025-3102

GitHub0xgh057r3c0n/cve-2025-3102

SureTriggers <= 1.0.78 - Authorization Bypass Exploit

authentication-authorizationeducationexploitation+3
1 year ago