Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
37 results
Chrome-App-Bound-Encryption-Decryption preview

Chrome-App-Bound-Encryption-Decryption

GitHubxaitax/chrome-app-bound-encryption-decryption

Bypass Chromium's App-Bound Encryption via Direct Syscall-based Reflective Process Hollowing. Extract cookies, passwords, payment methods & tokens…

cryptographydata-exfiltrationencryption-decryption-tools+5
1.8k
6 months ago
CVE-2025-48932-Invision-Community-SQLi-Exploit preview

CVE-2025-48932-Invision-Community-SQLi-Exploit

GitHubcerberusmrxi/cve-2025-48932-invision-community-sqli-exploit

CVE-2025-48932 - Unauthenticated SQL injection exploit for Invision Community ≤ 4.7.20. Fully automated exploitation with database enumeration,…

data-exfiltrationexploitationinformation-gathering+6
11 month ago
CVE-2020-5148 preview

CVE-2020-5148

GitHubl0lsec/cve-2020-5148

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

authenticationexploitationinformation-gathering+6
1 month ago
wpbf preview

wpbf

GitHubdejanlevaja/wpbf

WPBF - a multithreaded WP brute forcer

authenticationinformation-gatheringpassword-attacks+2
512 years ago
CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below preview

CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37755---hardcoded-admin-credential-in-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

authenticationexploitationmisconfiguration+3
2 years ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
12 years ago
cve-2020-1472 preview

cve-2020-1472

GitHubshanfenglan/cve-2020-1472

Exploit for CVE-2020-1472 (Zerologon) that resets domain controller machine account password, enabling credential dumping and privilege escalation to…

exploitationlateral-movementpassword-attacks+3
25 years ago
CVE-2022-42176 preview

CVE-2022-42176

GitHubsoy-oreocato/cve-2022-42176

Proof-of-concept for CVE-2022-42176: hard-coded credentials in PCSecure configuration file allow local privilege escalation to admin panel and…

authenticationexploitationmisconfiguration+3
12 years ago
xpl-ModernWMS-CVE-2024-57698 preview

xpl-ModernWMS-CVE-2024-57698

GitHubrodolfomarianocy/xpl-modernwms-cve-2024-57698

It is possible to view the MD5 hash of the admin password and other attributes without authentication, even after initial setup and password change.…

exploitationinformation-gatheringmisconfiguration+3
1 year ago
CVE-2026-8181 preview

CVE-2026-8181

GitHubxshadow-here/cve-2026-8181

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

authenticationexploitationinformation-gathering+6
13 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubshootcannon/cve-2026-5076

ARMember Premium <= 7.3.1 Full Admin Account Takeover

exploitationinformation-gatheringpassword-attacks+3
2 months ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
3 months ago
CVE-2025-57819_FreePBX preview

CVE-2025-57819_FreePBX

GitHuborange0mint/cve-2025-57819_freepbx

This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), and another to extract…

educationexploitationinformation-gathering+4
211 months ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
13 months ago
CVE-2020-7378 preview

CVE-2020-7378

GitHubloganpkinfosec/cve-2020-7378

Proof-of-concept exploit for CVE-2020-7378 chaining predictable password reset token generation with blind XXE to gain admin access and exfiltrate…

exploitationpassword-attackspayload-development+3
1 year ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
3 months ago
cve-2019-17240 preview

cve-2019-17240

GitHubspyx/cve-2019-17240

Go-based brute-force tool exploiting Bludit bruteforce mitigation bypass (CVE-2019-17240) for automated password cracking against admin login pages.

exploitationpassword-attackspenetration-testing+2
15 years ago
CVE-2017-7921 preview

CVE-2017-7921

GitHubgabrielavls/cve-2017-7921

CVE-2017-7921 exploit. Allows admin password retrieval and automatic snapshot download.

exploitationinformation-gatheringiot-security+3
3 years ago
Previous123Next