Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
570 results
CVE-2025-31161 preview

CVE-2025-31161

GitHubimmersive-labs-sec/cve-2025-31161

Proof of Concept for CVE-2025-31161 / CVE-2025-2825

authentication-authorizationexploitationpenetration-testing+3
48
1 year ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubomnigodz/cve-2022-1388

This repository consists of the python exploit for CVE-2022-1388 (F5's BIG-IP Authentication Bypass to RCE)

authentication-authorizationexploitationpenetration-testing+2
4 years ago
Blackash-CVE-2025-31161 preview

Blackash-CVE-2025-31161

GitHubdrelinss/blackash-cve-2025-31161

CVE-2025-31161

authentication-authorizationexploitationpenetration-testing+3
1 year ago
CVE-2026-27944 preview

CVE-2026-27944

GitHubskynoxk/cve-2026-27944

Automated exploit for CVE-2026-27944 in Nginx UI: downloads and decrypts backups, extracts secrets, and creates rogue admin accounts for full…

authentication-authorizationdata-exfiltrationexploitation+3
95 months ago
CVE-2025-54309__Enhanced_exploit preview

CVE-2025-54309__Enhanced_exploit

GitHubwhisperer1290/cve-2025-54309__enhanced_exploit

Multi-threaded exploit for CrushFTP authentication bypass (CVE-2025-54309) with race condition implementation, XML payload generation, and admin user…

authentication-authorizationeducationexploitation+4
10 years ago
CVE-2022-1388 preview

CVE-2022-1388

GitHubgotr00t0day/cve-2022-1388

A remote code execution vulnerability exists in the iControl REST API feature of F5's BIG-IP product. An unauthenticated, remote attacker can exploit…

authentication-authorizationexploitationpenetration-testing+3
72 years ago
CVE-2026-54121-CertiGhost preview

CVE-2026-54121-CertiGhost

GitHubkrakeneu/cve-2026-54121-certighost

CVE-2026-54121(CertiGhost) without MachineAccountQuota POC

authentication-authorizationexploitationpenetration-testing+3
11 month ago
POC-CVE-2025-29927 preview

POC-CVE-2025-29927

GitHubeve-satoru/poc-cve-2025-29927

CVE-2025-29927 Proof of Concept

authentication-authorizationexploitationvulnerability-analysis+3
31 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubaydinnyunus/cve-2025-29927

CVE-2025-29927 Proof of Concept

authentication-authorizationeducationexploitation+3
1031 year ago
CVE-2021-24085 preview

CVE-2021-24085

GitHubsourceincite/cve-2021-24085

Proof-of-concept exploit for CVE-2021-24085: CSRF-based elevation of privilege in Microsoft Exchange Server via msExchEcpCanary token forgery,…

authentication-authorizationexploitationpenetration-testing+2
715 years ago
cve-2022-39227-jwt-auth-bypass-demo preview

cve-2022-39227-jwt-auth-bypass-demo

GitHubmelikesraoz/cve-2022-39227-jwt-auth-bypass-demo

Educational lab demonstrating CVE-2022-39227 JWT authentication bypass in python-jwt. Step-by-step attack against vulnerable and patched Flask apps…

authentication-authorizationeducationexploitation+3
13 months ago
CVE-2022-32532 preview

CVE-2022-32532

GitHublay0us/cve-2022-32532

Apache Shiro CVE-2022-32532

authentication-authorizationexploitationpenetration-testing+2
134 years ago
CVE-2026-73673 preview

CVE-2026-73673

GitHubozcanpng/cve-2026-73673

Non-destructive PoC and technical write-up for CVE-2026-73673, an unauthenticated firmware-update flaw in Netis NC63 router, with reproduction and…

authentication-authorizationembedded-systems-securityexploitation+3
320 days ago
CVE-2024-41958-PoC preview

CVE-2024-41958-PoC

GitHuborangejuicehu/cve-2024-41958-poc

This is a small proof of concept for CVE-2024-41958

authentication-authorizationexploitationpenetration-testing+2
42 years ago
CVE-2021-3560 preview

CVE-2021-3560

GitHubwinmin/cve-2021-3560

PolicyKit CVE-2021-3560 Exploitation (Authentication Agent)

authentication-authorizationexploitationpenetration-testing+2
253 years ago
CVE-2024-38821-POC preview

CVE-2024-38821-POC

GitHubmasa42/cve-2024-38821-poc

Proof-of-concept exploit for CVE-2024-38821, demonstrating authentication bypass in Spring Framework via path traversal to access restricted…

authentication-authorizationeducationexploitation+3
11 year ago
CVE-2025-29927 preview

CVE-2025-29927

GitHub0xnxt1me/cve-2025-29927

Proof-of-concept exploit for CVE-2025-29927 that adds x-middleware-subrequest to bypass Next.js middleware authentication checks.

authentication-authorizationeducationlabs-practice+3
11 year ago
CVE-2025-3639 preview

CVE-2025-3639

GitHub6lj/cve-2025-3639

login bypass vulnerability in Liferay Portal (versions 7.3.0–7.4.3.132) and Liferay DXP (various versions from 2024.Q1 to 2025.Q1.6)

authentication-authorizationeducationexploitation+3
211 months ago
Previous12…32Next