Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
91 results
CVE-2026-43914-PoC preview

CVE-2026-43914-PoC

GitHubboreas37/cve-2026-43914-poc

PoC for CVE-2026-43914: Vaultwarden <1.35.4 email-2FA brute-force bypass password oracle. Stdlib-only Python.

exploitationpassword-attackspenetration-testing+2
2
1 day ago
CVE-2026-71205-PoC preview

CVE-2026-71205-PoC

GitHubnel-droid/cve-2026-71205-poc

PoC: changedetection.io unlimited login brute-force, no rate limiting (CVE-2026-71205, Medium 6.5)

authenticationexploitationpassword-attacks+4
9 days ago
INSTA_CYBER preview

INSTA_CYBER

GitHubsabir555s/insta_cyber

INSTA_CYBER is a Python-powered ethical hacking tool designed for educational and research purposes. Built by Muhammad Sabir Ali (INNO_CYBER), this…

authenticationpassword-attackspassword-cracking+3
141 year ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubvozec/cve-2023-7028

This repository presents a proof-of-concept of CVE-2023-7028

exploitationpassword-attackspenetration-testing+3
2452 years ago
CVE-2023-7028 preview

CVE-2023-7028

GitHubduy-31/cve-2023-7028

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior…

exploitationpassword-attackspenetration-testing+2
32 years ago
redash-reset preview

redash-reset

GitHubrandomrobbiebf/redash-reset

Exploit the Redash weak secret key vulnerability (GHSA-g8xr-f424-h2rv) to generate password reset links for any user, enabling account takeover…

exploitationpassword-attackspenetration-testing+2
54 years ago
CVE-2023-6654 preview

CVE-2023-6654

GitHubqfmy1024/cve-2023-6654

CVE-2023-6654 EXP

exploitationpassword-attacksprivilege-escalation+2
21 year ago
Zimbra-Valid-Login-Checker preview

Zimbra-Valid-Login-Checker

GitHubjenderal92/zimbra-valid-login-checker

Lightweight Python script to test username/password combinations against Zimbra webmail login pages for security assessments and password auditing.

authenticationpassword-attackspenetration-testing+2
12 months ago
CVE-2022-26138 preview

CVE-2022-26138

GitHubz92g/cve-2022-26138

Confluence Hardcoded Password POC

exploitationpassword-attackspenetration-testing+2
154 years ago
wpbf preview

wpbf

GitHubatarantini/wpbf

Remotely test password strength of WordPress bloging software

information-gatheringpassword-attackspenetration-testing+3
10710 years ago
FaceBrute preview

FaceBrute

GitHubemerinohdz/facebrute

Facebook brute forcer script

authenticationpassword-attackspenetration-testing+2
2714 years ago
CredMaster preview

CredMaster

GitHubknavesec/credmaster

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

api-security-testingauthenticationcloud-security+9
1.3k1 year ago
CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below preview

CVE-2023-37756-CWE-521-lead-to-malicious-plugin-upload-in-the-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37756-cwe-521-lead-to-malicious-plugin-upload-in-the-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

exploitationmisconfigurationpassword-attacks+3
12 years ago
CVE-2021-45041 preview

CVE-2021-45041

GitHubmanuelz120/cve-2021-45041

PoC for CVE-2021-45041

exploitationpassword-attackspenetration-testing+2
4 years ago
CVE-2024-42849 preview

CVE-2024-42849

GitHubnjmbb8/cve-2024-42849

An issue in Silverpeas v.6.4.2 and lower allows a remote attacker to cause a denial of service via the password change function.

exploitationpassword-attackspenetration-testing+2
2 years ago
CVE-2024-42850 preview

CVE-2024-42850

GitHubnjmbb8/cve-2024-42850

An issue in Silverpeas v6.4.2 and lower allows for the bypassing of password complexity requirements.

authenticationmisconfigurationpassword-attacks+2
12 years ago
CVE-2021-27651 preview

CVE-2021-27651

GitHuborangmuda/cve-2021-27651

bypass all stages of the password reset flow

authenticationcode-analysisexploitation+3
14 years ago
openCRX-CVE-2020-7378 preview

openCRX-CVE-2020-7378

GitHubruthvikvegunta/opencrx-cve-2020-7378

Exploits Password Reset Vulnerability in OpenCRX, CVE-2020-7378. Also maintains Stealth by deleting all the password reset mails created by the script

authenticationexploitationpassword-attacks+3
55 years ago
Previous123456Next