Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1166 results
CVE-2024-27198-EXPLOIT preview

CVE-2024-27198-EXPLOIT

GitHubk3ystr0k3r/cve-2024-27198-exploit

A PoC exploit for CVE-2024-27198 - JetBrains TeamCity Authentication Bypass

authenticationeducationexploitation+4
8
2 years ago
CVE-2025-64446 preview

CVE-2025-64446

GitHubsensepost/cve-2025-64446

A scanner for the FortiNet vulnerability CVE-2025-64446

authenticationexploitationpenetration-testing+3
329 months ago
CVE-2025-55182-React-RCE preview

CVE-2025-55182-React-RCE

GitHubxcanwin/cve-2025-55182-react-rce

[漏洞复现] 全球首款基于RSC特性能绕过WAF检测的CVE-2025-55182 React Server RCE 漏洞 EXP。

exploitationpayload-developmentpenetration-testing+3
159 months ago
CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc preview

CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc

GitHubalihussainzada/cve-2026-29000-python-poc-pac4j-jwt-authenticationbypass-poc

Python proof-of-concept demonstrating an authentication bypass in pac4j JWT by crafting a JWE token with an unsigned inner JWT, allowing privilege…

authentication-authorizationeducationexploitation+3
25 months ago
CVE-2024-29849 preview

CVE-2024-29849

GitHubsinsinology/cve-2024-29849

Veeam Backup Enterprise Manager Authentication Bypass (CVE-2024-29849)

authentication-authorizationexploitationpenetration-testing+3
902 years ago
CVE-2026-25924 preview

CVE-2026-25924

GitHubdrkim-dev/cve-2026-25924

Proof-of-concept exploit for CVE-2026-25924, demonstrating administrative remote code execution in Kanboard through a missing access control check on…

code-analysisexploitationpayload-development+3
26 months ago
CVE-2025-29927 preview

CVE-2025-29927

GitHubemadshanab/cve-2025-29927

New nuclei CVE

exploitationpayload-generationpenetration-testing+3
21 year ago
CVE-2022-46169 preview
Archived

CVE-2022-46169

GitHubsaspect488/cve-2022-46169

PoC for CVE-2022-46169 - Unauthenticated RCE on Cacti <= 1.2.22

command-and-controlexploitationpenetration-testing+3
293 years ago
frameless-bitb preview

frameless-bitb

GitHubwaelmas/frameless-bitb

A new approach to Browser In The Browser (BITB) without the use of iframes, allowing the bypass of traditional framebusters implemented by login…

educationids-ips-evasionphishing+3
4552 years ago
CVE-2022-23131 preview

CVE-2022-23131

GitHubjweny/cve-2022-23131

Go-based proof-of-concept exploit for CVE-2022-23131, a Zabbix SAML authentication bypass. Enables unauthorized admin access by forging SAML…

exploitationpenetration-testingred-teaming+2
954 years ago
CVE-2023-20198 preview

CVE-2023-20198

GitHubsmokeintheshell/cve-2023-20198

CVE-2023-20198 Exploit PoC

authenticationcommand-and-controlexploitation+3
665 months ago
keycloak-CVE-2026-18963 preview

keycloak-CVE-2026-18963

GitHubgman0x00/keycloak-cve-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

authenticationexploitationlabs-practice+3
11 days ago
CVE-2025-12720 preview

CVE-2025-12720

GitHubd0n601/cve-2025-12720

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

api-security-testingauthenticationexploitation+3
10 months ago
0xMiddleware preview

0xMiddleware

GitHubev3rpalestine/0xmiddleware

CVE-2025-29927: Next.js Middleware Exploit

authenticationexploitationpenetration-testing+3
1 year ago
CVE-2023-20198 preview

CVE-2023-20198

GitHubsanan2004/cve-2023-20198

Proof-of-concept exploit for CVE-2023-20198 targeting Cisco IOS XE Web UI. Enables unauthenticated remote command execution, configuration retrieval,…

command-and-controlexploitationpenetration-testing+3
2 years ago
zabbix-cve-2022-23131 preview

zabbix-cve-2022-23131

GitHubfa1c0n35/zabbix-cve-2022-23131

Exploit for Zabbix SAML SSO bypass (CVE-2022-23131) enabling unauthorized admin access by forging session cookies.

authentication-authorizationexploitationpenetration-testing+2
14 years ago
CVE-2026-35616-check preview

CVE-2026-35616-check

GitHubbishopfox/cve-2026-35616-check

Non-destructive scanner for CVE-2026-35616, a pre-authentication API bypass in FortiClient EMS. Detects vulnerability by comparing HTTP responses…

api-security-testingauthenticationexploitation+3
25 months ago
jboss-autopwn-1 preview

jboss-autopwn-1

GitHub1872892142/jboss-autopwn-1

JBoss Autopwn as featured at BlackHat Europe 2010 - this version incorporates CVE-2010-0738 the JBoss authentication bypass VERB manipulation…

authenticationcommand-and-controlexploitation+5
11 years ago
Previous123…65Next