Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
129 results
CVE-2022-40684 preview

CVE-2022-40684

GitHubccordeiro/cve-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

authenticationexploitationinformation-gathering+3
9 months ago
bug-bounty-reports-desai-vinayak preview

bug-bounty-reports-desai-vinayak

GitHubdesaivinayak449/bug-bounty-reports-desai-vinayak

Bug bounty and vulnerability research reports by Desai Vinayak — includes CVE-2023-50290 (Apache Solr) and Zscaler subdomain takeover findings.

cloud-securitycurated-resourcesdns-analysis+6
9 months ago
CVE-2025-4606 preview

CVE-2025-4606

GitHubyucaerin/cve-2025-4606

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

exploitationpassword-attacksprivilege-escalation+3
1 year ago
CVE-2024-50478 preview

CVE-2024-50478

GitHubrandomrobbiebf/cve-2024-50478

1-Click Login: Passwordless Authentication 1.4.5 - Authentication Bypass via Account Takeover

authentication-authorizationexploitationpenetration-testing+3
1 year ago
nepstech-xpon-router-CVE-2024-40119 preview

nepstech-xpon-router-CVE-2024-40119

GitHubbaroi-ai/nepstech-xpon-router-cve-2024-40119

Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without…

exploitationiot-securitypenetration-testing+3
2 years ago
CVE-2021-40101 preview

CVE-2021-40101

GitHubs1lkys/cve-2021-40101

Survey XSS combined with CSRF leads to Admin Account Takeover in Concrete5 8.5.4

exploitationpenetration-testingphishing-tools+3
4 years ago
POC-CVE-2026-63030-CVE-2026-60137- preview

POC-CVE-2026-63030-CVE-2026-60137-

GitHubtrandonga3/poc-cve-2026-63030-cve-2026-60137-

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

api-securityeducationexploitation+6
1 day ago
CVE-2026-73847-emlog-PoC preview

CVE-2026-73847-emlog-PoC

GitHubsqueeze440/cve-2026-73847-emlog-poc

PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

exploitationpenetration-testingvulnerability-analysis+2
4 days ago
CVE-2026-72898 preview

CVE-2026-72898

GitHub4minx/cve-2026-72898

Proof-of-concept exploit for CVE-2026-72898, an unauthenticated SQL injection in Metabase's password-reset endpoint. Forges an admin session for full…

exploitationpenetration-testingvulnerability-analysis+3
15 days ago
cve-2026-71362-magento-lab preview

cve-2026-71362-magento-lab

GitHubdinosn/cve-2026-71362-magento-lab

Docker lab reproducing CVE-2026-71362 Magento/Adobe Commerce account takeover via customer-session identity switch, with PoC and official-patch A/B/A…

authentication-authorizationeducationexploitation+4
15 days ago
CVE-2026-7458 preview

CVE-2026-7458

GitHubsangsenimanwartefak/cve-2026-7458

Python proof-of-concept exploit for CVE-2026-7458, an unauthenticated authentication bypass in PickPlugins User Verification WordPress plugin via…

authenticationexploitationpenetration-testing+2
2 months ago
Bug_Bounty_writeups preview

Bug_Bounty_writeups

GitHubalexbieber/bug_bounty_writeups

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

curated-resourceseducationvulnerability-analysis+1
8524 years ago
Reconator preview

Reconator

GitHubgokulapap/reconator

Automated Recon for Pentesting & Bug Bounty

dns-subdomain-enumerationfuzzinginformation-gathering+6
4413 months ago
Eagle preview

Eagle

GitHubbitthebyte/eagle

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

exploitationinformation-gatheringmisconfiguration+4
1285 years ago
CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval- preview

CVE-2026-22005-OAuth-2.0-Device-Code-Phishing-Short-Interval-

GitHubgeorge0papasotiriou/cve-2026-22005-oauth-2.0-device-code-phishing-short-interval-
authentication-authorizationeducationexploitation+4
16 days ago
CVE-2026-11551-PoC preview

CVE-2026-11551-PoC

GitHububaydev/cve-2026-11551-poc
authenticationcode-analysisexploitation+5
2 months ago
CVE-2024-53617 preview

CVE-2024-53617

GitHubii5mai1/cve-2024-53617
exploitationpenetration-testingvulnerability-analysis+2
1 year ago
hackerone-reports preview

hackerone-reports

GitHubreddelexc/hackerone-reports

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

ctfcurated-resourceseducation+7
6.5k3 days ago
Previous1234…8Next