Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
915 results
CVE-2026-24061-Telnetd preview

CVE-2026-24061-Telnetd

GitHubish3ng0m4/cve-2026-24061-telnetd

CVE-2026-24061 GNU Inetutils Telnetd Authentication Bypass

authenticationeducationexploitation+3
11h 29m ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
119h 56m ago
cve-2024-55591-poc preview

cve-2024-55591-poc

GitHubull0a/cve-2024-55591-poc

Educational implementation in Go for CVE-2024-55591 (Fortinet FortiOS Authentication Bypass). Designed for security research, vulnerability…

authenticationexploitationpenetration-testing+2
119 hours ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubeqstlab/cve-2026-18963

Unauthenticated account takeover via reset-credentials flow bypass

authenticationexploitationpenetration-testing+2
0 days ago
POC-CVE-2026-0073 preview

POC-CVE-2026-0073

GitHubnaheeju/poc-cve-2026-0073

Security research PoC for CVE-2026-0073: ADB authentication bypass verification

android-securityauthenticationexploitation+2
1 day ago
CVE-2026-78905-Facebook-Account-Takeover preview

CVE-2026-78905-Facebook-Account-Takeover

GitHubvxssroott/cve-2026-78905-facebook-account-takeover

Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

authenticationexploitationvulnerability-analysis+1
2 days ago
messari-crack preview

messari-crack

GitHubtimuronlinq/messari-crack

Cracking utility to bypass premium access controls on Messari's research platform, enabling unauthorized access to premium reports and real-time…

authenticationcryptographyexploitation+3
21912 days ago
CVE-2026-29000-Lab preview

CVE-2026-29000-Lab

GitHubrootdirective-sec/cve-2026-29000-lab

Library-level proof-of-concept lab demonstrating CVE-2026-29000 in pac4j-jwt, comparing vulnerable and patched versions with Docker to show forged…

authenticationexploitationvulnerability-analysis+1
5 months ago
CVE-2026-24061-payload preview

CVE-2026-24061-payload

GitHubilokaas/cve-2026-24061-payload

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

authenticationexploitationpenetration-testing+3
4 days ago
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass preview

the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

GitHubhunt-benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

api-securityauthenticationexploitation+3
5 days ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
5 days ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubalt3kx/cve-2026-18963

Detection and verification tool for CVE-2026-18963, a Keycloak reset-credentials state bypass. Performs version fingerprinting, realm/client/user…

authenticationexploitationinformation-gathering+4
5 days ago
Exploit-For-CVE-2026-18963 preview

Exploit-For-CVE-2026-18963

GitHubblackhatexploitation/exploit-for-cve-2026-18963

Exploit for CVE-2026-18963, a critical unauthenticated account takeover in Keycloak's reset-credentials flow, chaining two bugs to bypass email…

authenticationexploitationpenetration-testing+3
8 days ago
CVE-2026-22794-POC preview

CVE-2026-22794-POC

GitHubmalikhamza7/cve-2026-22794-poc

🔴 CVE-2026-22794 - Appsmith Password Reset Account Takeover via Origin Header Injection | PoC Exploit + Nuclei Template

authenticationexploitationpenetration-testing+3
77 months ago
CVE-2026-41940-AuthBypass-Detector preview

CVE-2026-41940-AuthBypass-Detector

GitHubunteikyou/cve-2026-41940-authbypass-detector

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

authenticationpenetration-testingreconnaissance+2
24 months ago
2026-41940-poc preview

2026-41940-poc

GitHubnickpaulsec/2026-41940-poc

CVE-2026-41940: detect and exploit cpanel vuln

authenticationexploitationpenetration-testing+2
14 months ago
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
3 months ago
keycloak-CVE-2026-18963 preview

keycloak-CVE-2026-18963

GitHubgman0x00/keycloak-cve-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

authenticationexploitationlabs-practice+3
7 days ago
Previous12…51Next