Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
248 results
CVE-2025-52488 preview

CVE-2025-52488

GitHubsh4den/cve-2025-52488

This exploit targets a vulnerability in DNN (formerly DotNetNuke) versions 6.0.0 to before 10.0.1 that allows attackers to disclose NTLM hashes…

exploitationinformation-gatheringpassword-attacks+3
2
1 month ago
CVE-2026-45332-PoC preview

CVE-2026-45332-PoC

GitHublorenzocamilli/cve-2026-45332-poc

Proof-of-concept exploit for CVE-2026-45332, a broken access control in Automad CMS allowing unauthenticated dump of admin bcrypt hashes and TOTP…

authenticationexploitationinformation-gathering+6
2 months ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubshootcannon/cve-2026-5076

ARMember Premium <= 7.3.1 Full Admin Account Takeover

exploitationinformation-gatheringpassword-attacks+3
2 months ago
CVE-2026-32488-POC preview

CVE-2026-32488-POC

GitHubwebshellseo8/cve-2026-32488-poc

CVE-2026-32488

exploitationinformation-gatheringpassword-attacks+4
2 months ago
cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure preview

cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

GitHubminanagehsalalma/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure

CVE-2026-34474: unauthenticated ETHCheat=1 requests leak the admin password and Wi-Fi PSK from ZTE H298A/H108N routers.

exploitationinformation-gatheringiot-security+3
2 months ago
CVE-2026-27886-PoC-Account-Takeover preview

CVE-2026-27886-PoC-Account-Takeover

GitHubthesw0rd/cve-2026-27886-poc-account-takeover

Account takeover full PoC for CVE-2026-27886 in Strapi CMS

exploitationinformation-gatheringpassword-attacks+4
22 months ago
WCE preview

WCE

GitHubal1ex/wce

Window Hash&Password dump

authenticationinformation-gatheringpassword-attacks+2
35 years ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubth-secforge/cve-2025-24071

Security Vulnerability Report: CVE-2025-24071 - Windows File Explorer Spoofing Vulnerability

exploitationinformation-gatheringpassword-attacks+2
31 year ago
Confluence-Question-CVE-2022-26138- preview

Confluence-Question-CVE-2022-26138-

GitHubvulnmachines/confluence-question-cve-2022-26138-

Atlassian Confluence Server and Data Center: CVE-2022-26138

exploitationinformation-gatheringpassword-attacks+3
34 years ago
CVE-2005-2428-IBM-Lotus-Domino-R8-Password-Hash-Extraction-Exploit preview

CVE-2005-2428-IBM-Lotus-Domino-R8-Password-Hash-Extraction-Exploit

GitHubschwankner/cve-2005-2428-ibm-lotus-domino-r8-password-hash-extraction-exploit

IBM Lotus Domino <= R8 Password Hash Extraction Exploit

exploitationinformation-gatheringpassword-attacks+2
37 years ago
CVE-2019-17662 preview

CVE-2019-17662

GitHubwhokilleddb/cve-2019-17662

Exploit for CVE-2019-17662 (ThinVNC 1.0b1)

exploitationinformation-gatheringpassword-attacks+2
24 years ago
CVE-2018-15473-exp preview

CVE-2018-15473-exp

GitHublinyikai/cve-2018-15473-exp

This is a exp of CVE-2018-15473

exploitationinformation-gatheringpassword-attacks+3
17 years ago
CVE-2025-49132 preview

CVE-2025-49132

GitHubvimmwy/cve-2025-49132

A script that gives you the credentials of a Pterodactyl panel vulnerable to CVE-2025-49132

exploitationinformation-gatheringpassword-attacks+3
12 months ago
Multi-threaded-mass-exploiter-CVE-2018-13379-POC preview

Multi-threaded-mass-exploiter-CVE-2018-13379-POC

GitHubinstructor-admin/multi-threaded-mass-exploiter-cve-2018-13379-poc

CVE-2018-13379 mass exploiter for Fortinet FortiOS SSL VPN. Extracts credentials instantly, saves to CSV + PostgreSQL. Multi-threaded, no bullshit…

exploitationinformation-gatheringpassword-attacks+4
12 months ago
joombrute preview

joombrute

GitHubrvzsec/joombrute

Modern Joomla Auth-attack Toolkit J3 / J4 / J5 - CVE-2023-23752 · CVE-2023-23755 · CVE-2025-25227

exploitationinformation-gatheringpassword-attacks+3
12 months ago
CVE-2025-15521 preview

CVE-2025-15521

GitHubnxploited/cve-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

authenticationexploitationinformation-gathering+5
14 months ago
CVE-2023-30146 preview

CVE-2023-30146

GitHubl1-0/cve-2023-30146

Some Assmann manufactured IP-Cams leak the administrator password in their backup.

exploitationhardware-iot-securityinformation-gathering+3
23 years ago
kyocera-cve-2022-1026_SOAP1.1 preview

kyocera-cve-2022-1026_SOAP1.1

GitHubh4po0n/kyocera-cve-2022-1026_soap1.1

An unauthenticated data extraction vulnerability in Kyocera printers, which allows for recovery of cleartext address book and domain joined passwords.

exploitationinformation-gatheringpassword-attacks+3
28 months ago
Previous1…101112…14Next