Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
38 results
CVE-2026-9090-poc preview

CVE-2026-9090-poc

GitHubkimdir01/cve-2026-9090-poc

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

authenticationexploitationpayload-generation+4
9 days ago
CVE-2026-23009-DICOM-Network-Image-Injection-Without-Authentication preview

CVE-2026-23009-DICOM-Network-Image-Injection-Without-Authentication

GitHubgeorge0papasotiriou/cve-2026-23009-dicom-network-image-injection-without-authentication

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

authenticationexploitationnetwork-security+3
19 days ago
WPTimeCapsulePOC preview

WPTimeCapsulePOC

GitHubsecforce/wptimecapsulepoc

Exploit for authentication bypass in WP Time Capsule plugin (<1.21.16). Steals admin cookie and uploads webshell.

authenticationexploitationpayload-development+3
56 years ago
CVE-2026-9198 preview

CVE-2026-9198

GitHub0xgh057r3c0n/cve-2026-9198

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

authenticationcommand-and-controlexploitation+4
11 month ago
Explotacion-CVE-2023-32315-Openfire preview

Explotacion-CVE-2023-32315-Openfire

GitHubpulentoski/explotacion-cve-2023-32315-openfire

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

authenticationexploitationpayload-generation+3
1 month ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
1 month ago
CVE-2018-10933-libSSH-Authentication-Bypass preview

CVE-2018-10933-libSSH-Authentication-Bypass

GitHublikekabin/cve-2018-10933-libssh-authentication-bypass

Exploit tool for CVE-2018-10933 libSSH authentication bypass, enabling remote shell access without credentials using Python scripts and optional fake…

authenticationexploitationnetwork-security+3
17 years ago
Pachine preview

Pachine

GitHubly4k/pachine

Python implementation for CVE-2021-42278 (Active Directory Privilege Escalation)

authenticationexploitationpayload-generation+3
2774 years ago
CVE-2024-29855 preview

CVE-2024-29855

GitHubsinsinology/cve-2024-29855

Proof-of-concept exploit for CVE-2024-29855, an authentication bypass in Veeam Recovery Orchestrator. Includes JWT token spraying and technical root…

authenticationexploitationpayload-generation+4
192 years ago
poc-cribl-rce preview

poc-cribl-rce

GitHublivehybrid/poc-cribl-rce

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

authenticationcommand-and-controlexploitation+3
87 years ago
Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit preview

Oracle-OAM-Padding-Oracle-CVE-2018-2879-Exploit

GitHubmostafasoliman/oracle-oam-padding-oracle-cve-2018-2879-exploit

Padding oracle exploit for Oracle Access Manager (CVE-2018-2879) enabling decryption of encrypted cookies and encryption of arbitrary plaintext for…

authenticationcryptographyexploitation+5
115 years ago
CVE-2025-7955 preview

CVE-2025-7955

GitHubnxploited/cve-2025-7955

RingCentral Communications 1.5 - 1.6.8 - Missing Server‑Side Verification to Authentication Bypass via ringcentral_admin_login_2fa_verify Function

authenticationcommand-and-controlexploitation+6
10 years ago
CVE-2025-68860 preview

CVE-2025-68860

GitHubdedsecteam-blackhat/cve-2025-68860

Exploit script for CVE-2025-68860 targeting WordPress Mobile Builder plugin. Generates forged JWT tokens using a hardcoded secret to authenticate as…

authenticationexploitationpayload-generation+3
5 months ago
CVE-2025-68860 preview

CVE-2025-68860

GitHubnxploited/cve-2025-68860

WordPress Mobile builder Plugin <= 1.4.2 is vulnerable to a high priority Broken Authentication

authenticationexploitationpayload-generation+3
27 months ago
CVE-2025-13390 preview

CVE-2025-13390

GitHubnxploited/cve-2025-13390

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

authenticationexploitationpayload-development+5
17 months ago
CVE-2025-39596 preview

CVE-2025-39596

GitHubnxploited/cve-2025-39596

Quentn WP <= 1.2.8 - Unauthenticated Privilege Escalation

authenticationexploitationpayload-generation+4
111 months ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubdairrow/cve-2025-31161

Proof-of-concept exploit for CrushFTP authentication bypass (CVE-2025-31161) enabling unauthenticated user impersonation, administrative actions, and…

authenticationexploitationpayload-development+5
17 months ago
CVE-2025-1639 preview

CVE-2025-1639

GitHubnxploited/cve-2025-1639

Animation Addons for Elementor Pro <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

authenticationexploitationpayload-generation+3
1 year ago
Previous123Next