Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
183 results
CVE-2020-35590 preview

CVE-2020-35590

GitHubn4nj0/cve-2020-35590

Brute-force tool for WordPress Plugin Limit Login Attempts Reloaded >=2.13.0 - Login Limit Bypass (CVE-2020-35590)

authenticationexploitationpassword-attacks+3
8
11 months ago
CVE-2022-1162 preview

CVE-2022-1162

GitHubgreenwolf/cve-2022-1162

Exploit for CVE-2022-1162: hardcoded password bypass in GitLab CE/EE OmniAuth accounts, enabling unauthorized login with a known credential.

authenticationexploitationpassword-attacks+3
44 years ago
metasploitable2 preview

metasploitable2

GitHubunix13/metasploitable2

PHP-CGI-REMOTE_CVE-2012-1823, UnrealIRCd, MySQL, PostgreSQL and SSH bruteforce, VSFTPD2.3.4, samba CVE-2007-2447, JAVA RMI Server, distcc daemon,…

exploitationmisconfigurationpassword-attacks+3
48 years ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubduy-31/cve-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior…

exploitationpassword-attackspenetration-testing+2
32 years ago
CVE-2026-43914-PoC preview

CVE-2026-43914-PoC

GitHubboreas37/cve-2026-43914-poc

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

exploitationpassword-attackspenetration-testing+2
11 month ago
wp-def preview

wp-def

GitHubjenderal92/wp-def

Wordpress Default Password

misconfigurationpassword-attacksvulnerability-analysis+1
23 months ago
CVE-2026-12416-CVE-2026-12417 preview

CVE-2026-12416-CVE-2026-12417

GitHubnxploited/cve-2026-12416-cve-2026-12417

Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter | Unauthenticated Privilege Escalation via Weak…

authenticationexploitationpassword-attacks+3
33 months ago
CVE-2026-71205-PoC preview

CVE-2026-71205-PoC

GitHubnel-droid/cve-2026-71205-poc

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

authenticationexploitationpassword-attacks+4
1 month ago
POC-CVE-2022-30600 preview

POC-CVE-2022-30600

GitHubboonjune/poc-cve-2022-30600

A proof of concept for CVE-2022-30600

authenticationexploitationpassword-attacks+3
33 years ago
CVE-2023-0630 preview

CVE-2023-0630

GitHubrandomrobbiebf/cve-2023-0630

CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection

exploitationpassword-attackspenetration-testing+2
23 years ago
CVE-2026-11387 preview

CVE-2026-11387

GitHub1beelze/cve-2026-11387

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

authenticationexploitationpassword-attacks+4
12 months ago
CVE-2022-31007-Python-POC preview

CVE-2022-31007-Python-POC

GitHubgregscharf/cve-2022-31007-python-poc

elabFTW < 4.1.0 - account lockout bypass and login brute force

authenticationexploitationpassword-attacks+3
23 years ago
CVE-2022-0439 preview

CVE-2022-0439

GitHubrandomrobbiebf/cve-2022-0439

CVE-2022-0439 - Email Subscribers & Newsletters < 5.3.2 - Subscriber+ Blind SQL injection

exploitationpassword-attackspenetration-testing+2
13 years ago
CVE-2026-5076 preview

CVE-2026-5076

GitHubzycoder0day/cve-2026-5076

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…

authenticationexploitationpassword-attacks+3
3 months ago
CVE-2025-58434-PoC preview

CVE-2025-58434-PoC

GitHubvincent-vbg/cve-2025-58434-poc

This repository contains a Proof of Concept (PoC) Python script for CVE-2025-58434, which enables attackers to change passwords of other users…

authenticationexploitationpassword-attacks+3
4 months ago
shiguresh preview

shiguresh

GitHubredsplit/shiguresh

CVE-2004-1769 // Mass cPanel Reset password

exploitationpassword-attacksvulnerability-analysis+1
16 years ago
CVE-2025-10658 preview

CVE-2025-10658

GitHubjfriedli/cve-2025-10658

Python exploit script for CVE-2025-10658: brute-forces 6-digit OTP in WordPress SupportCandy guest login to achieve full account takeover via…

authenticationexploitationpassword-attacks+3
16 months ago
CVE-2025-4094 preview

CVE-2025-4094

GitHubstarawneh/cve-2025-4094

CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass

authenticationexploitationpassword-attacks+3
11 year ago
Previous1…891011Next