Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
70 results
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
1
1 day ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubyasirr10/cve-2026-29000

Exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt allowing attackers to forge admin tokens using only the public key.

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2026-36959 preview

CVE-2026-36959

GitHubkirubel-cve/cve-2026-36959

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

authenticationexploitationpenetration-testing+2
4 months ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubkaleth4/cve-2026-21858

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

authenticationexploitationpayload-development+4
4 months ago
CVE-2026-21994 preview

CVE-2026-21994

GitHubg0w6y/cve-2026-21994

Proof-of-concept exploit for CVE-2026-21994, demonstrating unauthenticated admin session forgery via a hardcoded Flask SECRET_KEY and SSH host…

authenticationcloud-securityexploitation+3
5 months ago
CVE-2025-60375 preview

CVE-2025-60375

GitHubajansha/cve-2025-60375

Proof-of-concept for an authentication bypass in PerfexCRM prior to 3.3.1, demonstrating how empty credentials can grant unauthorized admin access.

authenticationexploitationpenetration-testing+2
10 months ago
CVE-2026-6182-SQLI-auth preview

CVE-2026-6182-SQLI-auth

GitHubxmyronn/cve-2026-6182-sqli-auth

Proof-of-concept for SQL injection authentication bypass in Simple Content Management System PHP, allowing unauthenticated attackers to gain admin…

authenticationexploitationpenetration-testing+2
4 months ago
CVE-2026-10243-AUTH preview

CVE-2026-10243-AUTH

GitHubxmyronn/cve-2026-10243-auth

Proof of concept demonstrating unauthenticated access to critical admin functions in Smart Parking System 1.0, allowing account creation, data…

authenticationexploitationpenetration-testing+2
3 months ago
CVE-2026-23550-PoC preview

CVE-2026-23550-PoC

GitHubthetorjancaptain/cve-2026-23550-poc

CVE-2026-23550 - Modular DS WordPress Plugin **Unauthenticated Admin Access**

authenticationexploitationpenetration-testing+3
17 months ago
CVE-2026-23550 preview

CVE-2026-23550

GitHubsangsenimanwartefak/cve-2026-23550

Bash exploit for CVE-2026-23550 that triggers unauthenticated WordPress admin login via crafted REST API request to Modular Connector's…

authenticationexploitationpenetration-testing+3
2 months ago
CVE-2020-24029 preview

CVE-2020-24029

GitHubredteambrasil/cve-2020-24029

Detailed disclosure of an unauthenticated password change vulnerability in ForLogic Qualiex v1 and v3, enabling remote privilege escalation and…

authenticationexploitationinformation-gathering+4
1 month ago
CVE-2025-60375 preview

CVE-2025-60375

GitHubahamedyaseen03/cve-2025-60375

CVE-2025-60375 — Authentication bypass / incorrect access control in PerfexCRM < 3.3.1 (admin login)

authenticationmisconfigurationpenetration-testing+3
10 months ago
CVE-2020-25273 preview

CVE-2020-25273

GitHubjonathanrey87/cve-2020-25273

Online Bus Booking System 1.0, there is Authentication bypass on the Admin Login screen in admin.php via username or password SQL injection.

authenticationeducationexploitation+3
5 years ago
CVE-2020-5148 preview

CVE-2020-5148

GitHubl0lsec/cve-2020-5148

CVE-2020-5148 - Forced Authentication in the SonicWall UTM SSO Agent. The agent probes unvalidated workstations as Domain Admin, so one outbound web…

authenticationexploitationinformation-gathering+6
1 month ago
Explotacion-CVE-2023-32315-Openfire preview

Explotacion-CVE-2023-32315-Openfire

GitHubpulentoski/explotacion-cve-2023-32315-openfire

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

authenticationexploitationpayload-generation+3
1 month ago
cve-2022-23131 preview

cve-2022-23131

GitHubwr0x00/cve-2022-23131

Exploit for CVE-2022-23131 targeting Zabbix SAML SSO authentication bypass. Generates a signed session cookie to gain unauthorized admin access.

authenticationexploitationpenetration-testing+2
13 years ago
wpbf preview

wpbf

GitHubdejanlevaja/wpbf

WPBF - a multithreaded WP brute forcer

authenticationinformation-gatheringpassword-attacks+2
512 years ago
CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below preview

CVE-2023-37755---Hardcoded-Admin-Credential-in-i-doit-Pro-25-and-below

GitHubleekenghwa/cve-2023-37755---hardcoded-admin-credential-in-i-doit-pro-25-and-below

Proof-of-concept for CVE-2023-37755: hardcoded admin credentials (admin/admin) in i-doit Pro 25 and below, enabling unauthorized admin login via the…

authenticationexploitationmisconfiguration+3
2 years ago
Previous1234Next