Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
68 results
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubyasouxken/cve-2026-41940-poc

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

authenticationcommand-and-controlexploitation+7
7 days ago
CVE-2026-89026 preview

CVE-2026-89026

GitHubcflowsec/cve-2026-89026

Python PoC that forges a hard-coded HS256 JWT to exploit CVE-2026-89026 in Issabel pbxapi, enabling unauthenticated remote OS command execution via…

authenticationcommand-and-controlexploitation+5
112 days ago
Certi-Bhai preview

Certi-Bhai

GitHubincredibleindishell/certi-bhai

AD CS exploitation related stuff goes here

authenticationexploitationpayload-generation+4
406 months ago
kafka-keycloak-oauth preview

kafka-keycloak-oauth

GitHuboriolrius/kafka-keycloak-oauth

Apache Kafka 4.1.0 (KRaft) with Keycloak OAuth2 authentication using Strimzi - bypasses CVE-2025-27817 URL allowlist restriction

authenticationcloud-infrastructure-securityconfiguration-auditing+3
511 months ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubkaleth4/cve-2026-21858

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

authenticationexploitationpayload-development+4
5 months ago
CVE-2026-31816-rshell preview

CVE-2026-31816-rshell

GitHubimjdl/cve-2026-31816-rshell

Exploits CVE-2026-31816 in Budibase to bypass authentication, upload a malicious datasource plugin, and execute a reverse shell for remote access.

authenticationexploitationpayload-development+2
6 months ago
casbin preview

casbin

GitHubapache/casbin

Authorization library enforcing ACL, RBAC, ABAC, and custom access-control models with RESTful matching and policy management APIs for applications…

api-securityauthenticationauthentication-authorization+2
20.4k18 days ago
CVE-2026-20079 preview

CVE-2026-20079

GitHubcyberauth/cve-2026-20079

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

authenticationexploitationpayload-development+3
61 month ago
CVE-2026-9090-poc preview

CVE-2026-9090-poc

GitHubkimdir01/cve-2026-9090-poc

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

authenticationexploitationpayload-generation+4
1 month ago
Azure-App-Tools preview

Azure-App-Tools

GitHubrvrsh3ll/azure-app-tools

Collection of tools to use with Azure Applications

authenticationcloud-securitycommand-and-control+4
1142 years ago
CVE-2026-23009-DICOM-Network-Image-Injection-Without-Authentication preview

CVE-2026-23009-DICOM-Network-Image-Injection-Without-Authentication

GitHubgeorge0papasotiriou/cve-2026-23009-dicom-network-image-injection-without-authentication

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

authenticationexploitationnetwork-security+3
1 month ago
CVE-2025-12135 preview

CVE-2025-12135

GitHubd0n601/cve-2025-12135

WPBookit <= 1.0.6 - Unauthenticated Stored Cross-Site Scripting

authenticationcode-analysismisconfiguration+3
11 months ago
WPTimeCapsulePOC preview

WPTimeCapsulePOC

GitHubsecforce/wptimecapsulepoc

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

authenticationexploitationpayload-development+3
56 years ago
prepos-login-checker preview

prepos-login-checker

GitHubjenderal92/prepos-login-checker

Prepostseo Login Checker

authenticationpassword-attackspenetration-testing+2
4 months ago
CVE-2026-9198 preview

CVE-2026-9198

GitHub0xgh057r3c0n/cve-2026-9198

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

authenticationcommand-and-controlexploitation+4
32 months ago
Explotacion-CVE-2023-32315-Openfire preview

Explotacion-CVE-2023-32315-Openfire

GitHubpulentoski/explotacion-cve-2023-32315-openfire

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

authenticationexploitationpayload-generation+3
2 months ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
2 months ago
CVE-2018-10933-libSSH-Authentication-Bypass preview

CVE-2018-10933-libSSH-Authentication-Bypass

GitHublikekabin/cve-2018-10933-libssh-authentication-bypass

Exploit tool for CVE-2018-10933 libSSH authentication bypass, enabling remote shell access without credentials using Python scripts and optional fake…

authenticationexploitationnetwork-security+3
17 years ago
Previous1234Next