Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
235 results
evil-winrm-py preview

evil-winrm-py

GitHubadityatelange/evil-winrm-py

Execute commands interactively on remote Windows machines using the WinRM protocol (just faster)

authenticationcommand-and-controllateral-movement+7
400
13 days ago
CVE-2026-49869 preview

CVE-2026-49869

GitHubeqstlab/cve-2026-49869

PoC and Docker lab for CVE-2026-49869, an unauthenticated RCE in Kestra OSS via an AuthenticationFilter path bypass that allows flow creation and…

authenticationexploitationlabs-practice+6
15 days ago
MicroTrick preview

MicroTrick

GitHubdigiprosec/microtrick

Self-contained Python PoC exploiting the MikroTrick SSH chain (CVE-2026-86060, CVE-2026-67279) to gain unauthenticated full admin access on MikroTik…

authenticationembedded-systems-securityexploitation+7
5210 days ago
EntraTrace preview

EntraTrace

GitHubbert-janp/entratrace

Defensive research tool that documents observable API endpoints and user agents of offensive tooling targeting Microsoft Entra ID, supporting…

authenticationcloud-securitydefensive-tools+5
915 days ago
CVE-2024-57610 preview

CVE-2024-57610

GitHubh4ckm3-png/cve-2024-57610

Proof-of-concept demonstrating lack of rate limiting on the Sylius v2.0.2 login endpoint, enabling unrestricted automated authentication attempts.

authenticationpapers-researchpenetration-testing+2
1 year ago
Potato preview

Potato

GitHubfoxglovesec/potato

Windows local privilege escalation exploit using NBNS spoofing, fake WPAD proxy, and HTTP-to-SMB NTLM relay to gain NT AUTHORITY\SYSTEM access.

authenticationexploitationlateral-movement+5
7435 years ago
CVE-2026-11387-WooCommerce-SMS-OTP preview

CVE-2026-11387-WooCommerce-SMS-OTP

GitHubabraxas/cve-2026-11387-woocommerce-sms-otp

SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress; SMS Alert <3.9.6; Unauthenticated Privilege Escalation…

authenticationexploitationpenetration-testing+4
415 days ago
CVE-2023-42793-TeamCity-Unauthenticated-RCE preview

CVE-2023-42793-TeamCity-Unauthenticated-RCE

GitHubburakacar6/cve-2023-42793-teamcity-unauthenticated-rce

A PoC and automated version detection/exploit tool for JetBrains TeamCity Authentication Bypass & RCE (CVE-2023-42793).

authenticationexploitationpenetration-testing+3
29 days ago
research-cve-2026-85649 preview

research-cve-2026-85649

GitHubchewkeanho/research-cve-2026-85649

[MIRROR] The CVE-2026-85649 Security Research Publication.

authenticationcurated-resourceseducation+3
29 days ago
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
171 month ago
POC-CVE-2026-0073 preview

POC-CVE-2026-0073

GitHubnaheeju/poc-cve-2026-0073

Security research PoC for CVE-2026-0073: ADB authentication bypass verification

android-securityauthenticationexploitation+2
51 month ago
CVE-2026-41940-AuthBypass-Detector preview

CVE-2026-41940-AuthBypass-Detector

GitHubunteikyou/cve-2026-41940-authbypass-detector

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

authenticationpenetration-testingreconnaissance+2
15 months ago
CVE-2026-0073-Android-adbd-authentication-bypass-POC preview

CVE-2026-0073-Android-adbd-authentication-bypass-POC

GitHubsectestannaquinn/cve-2026-0073-android-adbd-authentication-bypass-poc

Proof-of-concept exploit for CVE-2026-0073, an Android ADB authentication bypass allowing network attackers to connect to devices with ADB over TCP…

android-securityauthenticationexploitation+3
845 months ago
CVE-2026-7671 preview

CVE-2026-7671

GitHubcaginkyr/cve-2026-7671

Proof-of-concept for CVE-2026-7671, demonstrating OTP brute-force on Tornet Scooter Android app due to missing rate limiting on /TwoFactor endpoint.

android-securityauthenticationexploitation+2
25 months ago
CVE-2026-5724 preview

CVE-2026-5724

GitHubtibrn/cve-2026-5724

Proof-of-concept exploit for CVE-2026-5724, an authentication bypass in Temporal's frontend gRPC service allowing unauthenticated access to workflow…

api-securityauthenticationexploitation+2
5 months ago
CVE-2026-20127 preview

CVE-2026-20127

GitHubrandeepajayasekara/cve-2026-20127

Walkthrough of the CVSS 10.0 authentication bypass in Cisco Catalyst SD-WAN from first malformed peering request to root on the management plane.

authenticationeducationexploitation+3
7 months ago
Keycloak_CVE-2026-18963_PoC preview

Keycloak_CVE-2026-18963_PoC

GitHubprot0tw/keycloak_cve-2026-18963_poc

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

authenticationexploitationlabs-practice+3
151 month ago
CVE-2021-36460 preview

CVE-2021-36460

GitHubmartinfrancois/cve-2021-36460

Advisory detailing a pass-the-hash vulnerability in VeryFitPro app (<=3.3.7) where SHA-1 password hashes are used for authentication, enabling…

authenticationexploitationmobile-security+2
1 month ago
Previous12…14Next