Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
575 results
CVE-2024-42849 preview

CVE-2024-42849

GitHubnjmbb8/cve-2024-42849

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

exploitationpassword-attackspenetration-testing+2
2 years ago
CVE-2022-45599 preview

CVE-2022-45599

GitHubethancunt/cve-2022-45599

Proof-of-concept for CVE-2022-45599: PHP type juggling vulnerability in Aztech WMB250AC router login.php allowing admin authentication bypass via…

authenticationexploitationpassword-attacks+3
3 years ago
CVE-2021-27187 preview

CVE-2021-27187

GitHubjet-pentest/cve-2021-27187

Proof-of-concept for CVE-2021-27187: cleartext credential storage in FX Aggregator terminal client login.sav file, enabling local credential theft…

data-exfiltrationexploitationinformation-gathering+3
5 years ago
CVE-2021-46366 preview

CVE-2021-46366

GitHubmbadanoiu/cve-2021-46366

CVE-2021-46366: Credential Bruteforce Attack via CSRF + Open Redirect in Magnolia CMS

exploitationinformation-gatheringpassword-attacks+3
2 years ago
Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232 preview

Digisol-DG--GR1321-s-Password-Storage-in-Plaintext--CVE-2024-4232

GitHubredfox-security/digisol-dg--gr1321-s-password-storage-in-plaintext--cve-2024-4232

Proof-of-concept exploit for CVE-2024-4232 targeting plaintext password storage in Digisol DG-GR1321 routers. Demonstrates extraction of credentials…

exploitationiot-securitymisconfiguration+3
2 years ago
CVE-2023-22074 preview

CVE-2023-22074

GitHubemad-almousa/cve-2023-22074

Proof-of-concept exploit for CVE-2023-22074, an Oracle Database Sharding component vulnerability enabling password hash exposure in versions 19c,…

database-securityexploitationinformation-gathering+2
2 years ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubmochammadrafi/cve-2023-7028

Python Code for Exploit Automation CVE-2023-7028

educationexploitationpassword-attacks+3
2 years ago
CVE-2017-13872-Patch preview

CVE-2017-13872-Patch

GitHubgiovannidispoto/cve-2017-13872-patch

Exploit for CVE-2017-13872 that escalates privileges by changing the root password on vulnerable systems. Requires execution and provides new root…

authenticationexploitationpassword-attacks+2
8 years ago
CVE-2019-18818_CVE-2019-19609 preview

CVE-2019-18818_CVE-2019-19609

GitHubabelsrzz/cve-2019-18818_cve-2019-19609

This repository contains a Python script to exploit two vulnerabilities: CVE-2019-18818 and CVE-2019-19609.

educationexploitationpassword-attacks+3
1 year ago
CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below preview

CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37755---hardcoded-admin-credential-in-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

authenticationexploitationmisconfiguration+3
2 years ago
Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232 preview

Digisol-DG-GR1321-s-Password-Storage-in-Plaintext-CVE-2024-4232

GitHubredfox-security/digisol-dg-gr1321-s-password-storage-in-plaintext-cve-2024-4232

Proof-of-concept demonstrating plaintext password storage vulnerability in Digisol DG-GR1321 routers, enabling credential exposure and unauthorized…

hardware-securityiot-securitymisconfiguration+3
2 years ago
CVE-2023-0860 preview

CVE-2023-0860

GitHub0xsu3ks/cve-2023-0860

Proof-of-concept for CVE-2023-0860, demonstrating unauthenticated brute-force login attacks on Modoboa Mail Hosting and Management before v2.0.3.

information-gatheringpassword-attackspenetration-testing+2
3 years ago
CVE-2018-9995_dvr_credentials preview

CVE-2018-9995_dvr_credentials

GitHubbatmoshka55/cve-2018-9995_dvr_credentials

Exploit tool for CVE-2018-9995 that retrieves DVR credentials via crafted HTTP request, targeting multiple DVR vendors for security testing.

exploitationinformation-gatheringiot-security+3
1 year ago
CVE-2020-25078 preview

CVE-2020-25078

GitHubchinayozz/cve-2020-25078

Batch exploit script for CVE-2020-25078 targeting D-Link DCS series cameras to extract account credentials via information disclosure vulnerability.

exploitationinformation-gatheringiot-security+3
4 years ago
Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache preview

Cleartext-Storage-vulnerability-CVE-2023-5359-in-W3-Total-Cache

GitHubspyata123/cleartext-storage-vulnerability-cve-2023-5359-in-w3-total-cache

Targets versions ≤2.7.5 vulnerable to CVE-2023-5359

exploitationinformation-gatheringpassword-attacks+3
1 year ago
hikvision_CVE-2017-7921_auth_bypass_config_decryptor preview

hikvision_CVE-2017-7921_auth_bypass_config_decryptor

GitHubp4tq/hikvision_cve-2017-7921_auth_bypass_config_decryptor

Decrypts Hikvision IP camera configuration files extracted via CVE-2017-7921 authentication bypass, revealing user credentials and device settings.

encryption-decryption-toolsexploitationinformation-gathering+3
4 years ago
CVE-2020-27747 preview

CVE-2020-27747

GitHubjet-pentest/cve-2020-27747

Possible Account Takeover | Brute Force Ability

authenticationexploitationpassword-attacks+2
5 years ago
CVE-2021-22911 preview

CVE-2021-22911

GitHubjayngng/cve-2021-22911

Modifed ver of the original exploit to save some times on password reseting for unprivileged user

authentication-authorizationexploitationpassword-attacks+2
4 years ago
Previous1…29303132Next