Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
407 results
APIHarvester preview

APIHarvester

GitHubpiratesshield/apiharvester

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

api-securityapi-security-testingcrawler+9
32
2 months ago
CVE-2026-105030-poc preview

CVE-2026-105030-poc

GitHubasvorg/cve-2026-105030-poc

A python3 PoC for CVE-2026-105030 Kener 4.0.0 before 4.1.6 Hidden Monitor Data Disclosure via Dashboard API

api-securityexploitationinformation-gathering+4
1 day ago
CVE-2026-104110 preview

CVE-2026-104110

GitHubpervinzahidli/cve-2026-104110

Unauthenticated disclosure of internal folder path, client email, and upload policy for FileRise Pro client portals via /api/pro/portals/get.php

api-securityauthenticationexploitation+5
2 days ago
CVE-2026-103440 preview

CVE-2026-103440

GitHubbombobombone/cve-2026-103440

Report summary and local proof-of-concept script demonstrating CVE-2026-103440, a PageTriage API disclosure of suppressed reviewer usernames on…

api-securityexploitationinformation-gathering+2
3 days ago
CVE-2026-102973 preview

CVE-2026-102973

GitHubbombobombone/cve-2026-102973

Sanitized report and local proof-of-concept script demonstrating the MediaWiki action=emailuser API EmailUserAuthorizeSend hook bypass…

api-securityauthentication-authorizationexploitation+3
3 days ago
CVE-2026-100903 preview

CVE-2026-100903

GitHub4ybrick/cve-2026-100903

PoC and enumeration script for CVE-2026-100903, a missing-authentication flaw in the GEO.RITM REST API that leaks object and driver data anonymously.

api-securityauthenticationexploitation+6
6 days ago
CVE-2026-16764 preview

CVE-2026-16764

GitHubhakaioffsec/cve-2026-16764

Python exploit for CVE-2026-16764, a privilege escalation in OWASP DefectDojo where an is_staff REST API bypass lets a low-privileged user gain…

api-securityauthentication-authorizationeducation+6
19 days ago
CVE-2026-15583 preview

CVE-2026-15583

GitHubabraxas/cve-2026-15583

Proof-of-concept client and Docker lab reproducing CVE-2026-15583, an unauthenticated confused-deputy SSRF in Grafana MCP Server that leaks…

api-securitydata-exfiltrationexploitation+6
13 days ago
CVE-2026-18783-TREX-MES-Uygulamalarinda-Yetkisiz-Nesne-Erisimi preview

CVE-2026-18783-TREX-MES-Uygulamalarinda-Yetkisiz-Nesne-Erisimi

GitHubhasanuyarrr/cve-2026-18783-trex-mes-uygulamalarinda-yetkisiz-nesne-erisimi

Advisory for CVE-2026-18783: missing server-side authentication on TREX MES /api/GetDataJSON3 allows unauthenticated data queries and arbitrary SQL…

api-securityauthentication-authorizationdefensive-tools+5
3 days ago
ai-agent-gateway preview

ai-agent-gateway

GitHubtuskira/ai-agent-gateway

Open-source gateway that secures, governs, and observes AI agents' MCP tool calls and LLM traffic, with API-key authentication and an admin console…

ai-securityapi-securityauthentication-authorization+6
22 days ago
Securiscan preview

Securiscan

GitHubvighnesh91/securiscan

Standard-library Python security triage engine that scans web apps, APIs, LLMs, and mobile packages via passive header inspection, active canary…

ai-securityapi-securityapi-security-testing+8
4 days ago
CVE-2026-5430 preview

CVE-2026-5430

GitHubabraxas/cve-2026-5430

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

api-securityauthenticationcryptography+6
18 days ago
CVE-2026-94609 preview

CVE-2026-94609

GitHubanthonyk2923/cve-2026-94609

Write-up and proof-of-concept for CVE-2026-94609, an authentik privilege-escalation flaw letting users with add_user_to_group join superuser groups…

api-securityauthentication-authorizationeducation+6
9 days ago
wp-secure-mcp preview

wp-secure-mcp

GitHubles-k/wp-secure-mcp

A WordPress plugin exposing an MCP server over the REST API, with the security model as the point -- closes the CVE-2026-15015 OAuth-bypass shape by…

ai-securityapi-securityauthentication-authorization+5
10 days ago
POC-CVE-2026-93680 preview

POC-CVE-2026-93680

GitHubrmhowe425/poc-cve-2026-93680

Proof-of-concept exploit for CVE-2026-93680 demonstrating MCP SSE authentication bypass and data exfiltration via tool invocation.

api-securityauthenticationdata-exfiltration+4
12 days ago
zte-smartlife-app-pwned preview

zte-smartlife-app-pwned

GitHubminanagehsalalma/zte-smartlife-app-pwned

ZTE SmartLife security findings leading to account takeover: 100K+ Google Play downloads and CVE-2026-86552 through CVE-2026-86555.

android-securityapi-securitycryptography+7
12 days ago
CVE-2026-12944 preview

CVE-2026-12944

GitHubshadowforge-cyber/cve-2026-12944

Python PoC exploiting CVE-2026-12944, an SSRF in Langflow 1.10.0 via urllib in custom components, with authenticated read and fetch capabilities.

api-securityexploitationpenetration-testing+3
17 days ago
CVE-2026-76460 preview

CVE-2026-76460

GitHubs3v3n-jg/cve-2026-76460

Educational Flask lab simulating CVE-2026-76460 authentication bypass, with vulnerable, secure, and strict modes plus a PoC exploit script and…

api-securityauthenticationdefensive-tools+5
216 days ago
Previous12…23Next