Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
490 results
CVE-2017-7921 preview

CVE-2017-7921

GitHubmverschu/cve-2017-7921

HikVision Auth Bypass CVE, tool is able to extract credentials, and take snapshots based on magic cookie or supplied credentials.

authenticationexploitationinformation-gathering+5
6 months ago
CVE-2025-56764 preview

CVE-2025-56764

GitHubremenis/cve-2025-56764

Username Enumeration in Trivision NC-227WF

authenticationinformation-gatheringpassword-attacks+3
11 months ago
CVE-2025-24071 preview

CVE-2025-24071

GitHubroyall-researchers/cve-2025-24071

Proof-of-concept for CVE-2025-24071, demonstrating NTLM hash leak via crafted .library-ms file in RAR/ZIP archives, triggering SMB authentication on…

exploitationinformation-gatheringpassword-attacks+3
1 year ago
sickrageWTF preview

sickrageWTF

GitHubmechanico/sickragewtf

CVE-2018-9160

exploitationinformation-gatheringpassword-attacks+3
8 years ago
CVE-2025-2539 preview

CVE-2025-2539

GitHubyucaerin/cve-2025-2539

CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read

exploitationinformation-gatheringpassword-attacks+3
1 year ago
CVE-2020-15392 preview

CVE-2020-15392

GitHubinflixim4be/cve-2020-15392

Proof-of-concept exploit for user enumeration vulnerability in Supravizio BPM 10.1.2 via password recovery response differences, enabling brute force…

information-gatheringpassword-attackspenetration-testing+2
6 years ago
CVE-2025-4606 preview

CVE-2025-4606

GitHubyucaerin/cve-2025-4606

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

exploitationpassword-attacksprivilege-escalation+3
1 year ago
Tool_Exploit_Password_Camera_CVE-2018-9995 preview

Tool_Exploit_Password_Camera_CVE-2018-9995

GitHublequockhanh2k/tool_exploit_password_camera_cve-2018-9995

Exploit tool for CVE-2018-9995 that extracts credentials from vulnerable DVR devices via Google dorking and direct IP access.

exploitationiot-securitypassword-attacks+3
4 years ago
cve-2018-9995 preview

cve-2018-9995

GitHubdearpan/cve-2018-9995

Exploit for CVE-2018-9995 targeting DVR devices. Sends a crafted Cookie header to retrieve plaintext admin credentials from the web control panel.

exploitationiot-securitypassword-attacks+2
4 years ago
CVE-2020-25540 preview

CVE-2020-25540

GitHubsimonlee-hello/cve-2020-25540

ThinkAdmin v5 v6 任意文件读取漏洞利用,可自定义字典爆破

exploitationinformation-gatheringpassword-attacks+3
2 years ago
CVE-2023-22074 preview

CVE-2023-22074

GitHubemad-almousa/cve-2023-22074

Proof-of-concept exploit for CVE-2023-22074, an Oracle Database Sharding component vulnerability enabling password hash exposure in versions 19c,…

database-securityexploitationinformation-gathering+2
2 years ago
Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232 preview

Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232

GitHubredfox-security/digisol-dg-gr1321-s-password-storage-in-plaintext-cve-2024-4232

Proof-of-concept demonstrating plaintext password storage vulnerability in Digisol DG-GR1321 routers, enabling credential exposure and unauthorized…

hardware-securityiot-securitymisconfiguration+3
2 years ago
CVE-2020-25078 preview

CVE-2020-25078

GitHubchinayozz/cve-2020-25078

Batch exploit script for CVE-2020-25078 targeting D-Link DCS series cameras to extract account credentials via information disclosure vulnerability.

exploitationinformation-gatheringiot-security+3
4 years ago
Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache preview

Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache

GitHubspyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache

Targets versions ≤2.7.5 vulnerable to CVE-2023-5359

exploitationinformation-gatheringpassword-attacks+3
1 year ago
CVE-2023-0860 preview

CVE-2023-0860

GitHub0xsu3ks/cve-2023-0860

Proof-of-concept for CVE-2023-0860, demonstrating unauthenticated brute-force login attacks on Modoboa Mail Hosting and Management before v2.0.3.

information-gatheringpassword-attackspenetration-testing+2
3 years ago
CVE-2024-41290 preview

CVE-2024-41290

GitHubparagbagul111/cve-2024-41290

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to > store authentication data

authenticationexploitationinformation-gathering+3
1 year ago
iberyanbytes preview

iberyanbytes

GitHubleviathanfromdeepsea/iberyanbytes

PowerShell-based Active Directory enumeration tool for gathering network configuration, domain objects, user sessions, share permissions, and…

information-gatheringpassword-attackspenetration-testing+2
2 years ago
easy_security preview

easy_security

GitHubmoon1705/easy_security

Project with sublist3r, massan, CVE-2018-15473, ssh bruteforce, ftp bruteforce and nikto.

exploitationinformation-gatheringnetwork-security+5
2 years ago
Previous1…262728Next