Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
46 results
CVE-2026-21003-JWT-none-Algorithm-Bypass-via-kid-Header-Omission preview

CVE-2026-21003-JWT-none-Algorithm-Bypass-via-kid-Header-Omission

GitHubgeorge0papasotiriou/cve-2026-21003-jwt-none-algorithm-bypass-via-kid-header-omission

Proof-of-concept exploit for CVE-2026-21003 demonstrating JWT authentication bypass by omitting the kid header and using the 'none' algorithm to…

adversarial-attackapi-securityauthentication-authorization+4
1 month ago
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass preview

the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

GitHubhunt-benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

api-securityauthenticationexploitation+3
9 days ago
CVE-2026-59243_exploit preview

CVE-2026-59243_exploit

GitHub0xdak/cve-2026-59243_exploit

Exploit for Apache Airflow FAB OAuth authentication bypass (CVE-2026-59243) that achieves admin access and remote code execution by triggering a…

api-securityauthentication-authorizationexploitation+3
1 month ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
1 month ago
oathkeeper preview

oathkeeper

GitHubory/oathkeeper

A cloud native Identity & Access Proxy / API (IAP) and Access Control Decision API that authenticates, authorizes, and mutates incoming HTTP(s)…

api-securityauthenticationauthentication-authorization+5
3.6k1 month ago
private-landing preview

private-landing

GitHubvhscom/private-landing

🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso,…

api-securityauthenticationauthentication-authorization+8
793 months ago
zaproxy preview

zaproxy

GitHubzaproxy/zaproxy

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

android-securityapi-securityapi-security-testing+15
15.7k3 days ago
carbon-identity-framework preview

carbon-identity-framework

GitHubwso2/carbon-identity-framework

Core framework for identity and access management, providing authentication, authorization, and identity governance capabilities for enterprise…

api-securityauthentication-authorizationcloud-security+2
1372 days ago
limitrr-php preview

limitrr-php

GitHubeddiejibson/limitrr-php

Better PHP rate limiting using Redis.

api-securityauthentication-authorizationscripting-automation+2
206 years ago
CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover- preview

CVE-2026-3456-OAuth2-PKCE-Race-Condition-Account-Takeover-

GitHubgeorge0papasotiriou/cve-2026-3456-oauth2-pkce-race-condition-account-takeover-

Python PoC for CVE-2026-3456 demonstrating OAuth2 PKCE race-condition account takeover, with a vulnerable auth server and concurrent code-verifier…

api-securityauthentication-authorizationexploitation+3
1 month ago
moltis preview

moltis

GitHubmoltis-org/moltis

A secure persistent personal agent server in Rust. One binary, sandboxed execution, multi-provider LLMs, voice, memory, Telegram, WhatsApp, Discord,…

ai-securityapi-securityauthentication-authorization+7
2.8k3 days ago
bluemonday preview

bluemonday

GitHubmicrocosm-cc/bluemonday

bluemonday: a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS

api-securitycode-analysisdefensive-tools+3
3.7k1 year ago
openapi-parser preview

openapi-parser

GitHubaress31/openapi-parser

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

api-securityapi-security-testingpenetration-testing+2
2082 years ago
graphql-threat-matrix preview

graphql-threat-matrix

GitHubnicholasaleks/graphql-threat-matrix

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

api-securitycurated-resourcespenetration-testing+2
3701 year ago
My-Presentation-Slides preview

My-Presentation-Slides

GitHubdhiyaneshgeek/my-presentation-slides

Collection's of Tech Talk that are presented by me :)

api-securitycloud-securitycurated-resources+6
10127 days ago
Windows-Python-RAT preview

Windows-Python-RAT

GitHubthe404hacking/windows-python-rat

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

api-securitycommand-and-controlpayload-development+3
1176 years ago
Azure-APIM-Cross-Tenant-Signup-Bypass preview

Azure-APIM-Cross-Tenant-Signup-Bypass

GitHubbountyyfi/azure-apim-cross-tenant-signup-bypass

Security advisory: Azure APIM Developer Portal allows cross-tenant account registration by bypassing UI signup restrictions. Reported to MSRC twice -…

api-securitycloud-securityinformation-gathering+4
161 month ago
CVE-2026-67598 preview

CVE-2026-67598

GitHubilhomjonr/cve-2026-67598

CVE-2026-67598 — Emlog Pro: disabled TLS certificate validation in AI assistant (MITM → API-key theft). CWE-295, CVSS 9.1. Reported by @IlhomjonR.

ai-securityapi-securitycode-analysis+3
29 days ago
Previous123Next