Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1067 results
CVE-2025-62727-Demo preview

CVE-2025-62727-Demo

GitHubch4n3-yoon/cve-2025-62727-demo

Proof of concept of CVE-2025-62727 that can cause denial-of-service in FastAPI (based Starlette <= 0.48.0)

api-securityexploitationvulnerability-analysis+1
1
10 months ago
CVE-2021-45232 preview

CVE-2021-45232

GitHubyggcwhat/cve-2021-45232

Batch vulnerability scanner that integrates FOFA to discover and test Apache APISIX Dashboard instances for CVE-2021-45232 unauthorized access.

api-securityexploitationinformation-gathering+2
14 years ago
CVE-2025-56643 preview

CVE-2025-56643

GitHub0xbs0d27/cve-2025-56643

Public reference for CVE-2025-56643 – Wiki.js 2.5.307 JWT Session Vulnerability

api-securityauthenticationexploitation+2
110 months ago
CVE-2025-67923 preview

CVE-2025-67923

GitHubrandomrobbiebf/cve-2025-67923

JetEngine <= 3.7.7 — Unauthenticated Stored Cross-Site Scripting via CCT REST API

api-securityexploitationvulnerability-analysis+2
6 months ago
CVE-2026-23552 preview

CVE-2026-23552

GitHuboscerd/cve-2026-23552

CVE-2026-23552 - Cross-Realm Token Acceptance in camel-keycloak

api-securityauthentication-authorizationeducation+3
7 months ago
CVE-2021-45232 preview

CVE-2021-45232

GitHubltidi2000/cve-2021-45232

Proof-of-concept exploit for CVE-2021-45232, an unauthorized access vulnerability in Apache APISIX Dashboard allowing export/import of admin…

api-securityexploitationmisconfiguration+2
14 years ago
MicroserviceCVE-2021-39156 preview

MicroserviceCVE-2021-39156

GitHubmostafaanouarghorab/microservicecve-2021-39156
api-securityexploitationpenetration-testing+3
5 months ago
apache__dubbo_CVE-2021-30180_2-7-9 preview

apache__dubbo_CVE-2021-30180_2-7-9

GitHubshoucheng3/apache__dubbo_cve-2021-30180_2-7-9

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.

api-securityapi-security-testingexploitation+3
1 year ago
CVE-2021-45232 preview

CVE-2021-45232

GitHubdskho/cve-2021-45232

Proof-of-concept scanner for CVE-2021-45232, targeting unauthenticated API access and default credentials in Apache APISIX Dashboard.

api-securityexploitationmisconfiguration+2
4 years ago
CVE-2022-45354 preview

CVE-2022-45354

GitHubrandomrobbiebf/cve-2022-45354

Download Monitor <= 4.7.60 - Sensitive Information Exposure via REST API

api-securityexploitationinformation-gathering+3
3 years ago
CVE-2025-29557 preview

CVE-2025-29557

GitHub0xsu3ks/cve-2025-29557

Documents a high-severity ExaGrid EX10 MailConfiguration API access control flaw that leaks plaintext SMTP credentials to authenticated operators,…

api-securityeducationexploitation+3
1 year ago
westone-CVE-2021-37580-scanner preview

westone-CVE-2021-37580-scanner

GitHubosyanina/westone-cve-2021-37580-scanner

A vulnerability scanner that detects CVE-2021-37580 vulnerabilities.

api-securityauthenticationexploitation+2
4 years ago
westone-CVE-2021-45232-scanner preview

westone-CVE-2021-45232-scanner

GitHubosyanina/westone-cve-2021-45232-scanner

A vulnerability scanner that detects CVE-2021-45232 vulnerabilities.

api-securityexploitationpenetration-testing+2
4 years ago
CVE-2025-492030 preview

CVE-2025-492030

GitHubimthecopilotnow/cve-2025-492030

Proof-of-concept for CVE-2025-492030: account takeover via session token validation bypass in SecureVPN API endpoint /api/v1/authenticate.

api-securityauthenticationexploitation+3
1 year ago
CVE-2021-37580 preview

CVE-2021-37580

GitHubwing-song/cve-2021-37580

Apache ShenYu 管理员认证绕过

api-securityauthentication-authorizationexploitation+2
4 years ago
CVE-2018-25031 preview

CVE-2018-25031

GitHublucasrenaa/cve-2018-25031

Python-based proof-of-concept script demonstrating CVE-2018-25031 XSS vulnerability in Swagger UI using Selenium for automated detection across…

api-securityeducationexploitation+3
2 years ago
CVE-2025-30144 preview

CVE-2025-30144

GitHubtibrn/cve-2025-30144

Proof-of-concept for CVE-2025-30144: JWT issuer validation bypass in fast-jwt library allowing attackers to forge tokens with array-based iss claims.

api-securityauthenticationexploitation+3
1 year ago
SwaggerUI-CVE-2016-1000229 preview

SwaggerUI-CVE-2016-1000229

GitHubbarteeees/swaggerui-cve-2016-1000229

CVE-2016-1000229

api-securityexploitationpenetration-testing+2
11 months ago
Previous1…567…60Next