Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
67 results
By-Poloss..-..CVE-2026-19125 preview

By-Poloss..-..CVE-2026-19125

GitHubpolosss/by-poloss..-..cve-2026-19125

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

authenticationexploitationpassword-attacks+5
5 days ago
CVE-2024-31218-WEBHOOD-LAB preview

CVE-2024-31218-WEBHOOD-LAB

GitHubchandrimanath04-hue/cve-2024-31218-webhood-lab

Docker-based lab reproducing CVE-2024-31218, an unauthenticated PocketBase admin creation flaw in Webhood, with PoC, detection, and remediation…

authenticationeducationexploitation+4
9 days ago
CVE-2026-18963 preview

CVE-2026-18963

GitHubivanesk315/cve-2026-18963

Docker-based lab and Python exploit for CVE-2026-18963, a Keycloak reset-credentials flow bypass enabling account takeover via email verification…

authenticationeducationexploitation+6
19 days ago
CVE-2026-53519 preview

CVE-2026-53519

GitHubivanesk315/cve-2026-53519

Docker lab reproducing CVE-2026-53519, a pre-auth path traversal in Nezha Dashboard that leaks jwt_secret_key and enables JWT forgery and admin…

authenticationeducationexploitation+5
19 days ago
CVE-2026-75431_PowerJob_jwt_key_predictable preview

CVE-2026-75431_PowerJob_jwt_key_predictable

GitHubunpredictable21/cve-2026-75431_powerjob_jwt_key_predictable

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

authenticationexploitationpenetration-testing+2
1 month ago
CVE-2026-PSA-2026-00043-1 preview

CVE-2026-PSA-2026-00043-1

GitHubhorkimhab/cve-2026-psa-2026-00043-1

Proof-of-concept exploit for an unauthenticated root authentication bypass in Proxmox VE 7.0-8.0.3, intended for authorized security testing and…

authenticationeducationexploitation+3
27 days ago
cve-2026-82329-jfrog-artifactory preview

cve-2026-82329-jfrog-artifactory

GitHubdinosn/cve-2026-82329-jfrog-artifactory

Reproducible Docker lab and Python PoC for CVE-2026-82329, an unauthenticated auth-bypass in JFrog Artifactory leading to admin takeover, with…

authenticationcloud-securityexploitation+5
1227 days ago
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass preview

the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

GitHubhunt-benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

api-securityauthenticationexploitation+3
1 month ago
keycloak-CVE-2026-18963 preview

keycloak-CVE-2026-18963

GitHubgman0x00/keycloak-cve-2026-18963

PoC, Dockerfile playground and root cause from patch diff analysis.

authenticationexploitationlabs-practice+3
11 month ago
CVE-2026-29145-Tester preview

CVE-2026-29145-Tester

GitHubchenjp/cve-2026-29145-tester

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

authenticationeducationexploitation+3
5 months ago
CVE-2026-29145-Tester preview

CVE-2026-29145-Tester

GitHubsancliffe/cve-2026-29145-tester

This repository contains a proof-of-concept (PoC) environment designed to test for CVE-2026-29145.

authenticationeducationexploitation+3
5 months ago
kafka-keycloak-oauth preview

kafka-keycloak-oauth

GitHuboriolrius/kafka-keycloak-oauth

Apache Kafka 4.1.0 (KRaft) with Keycloak OAuth2 authentication using Strimzi - bypasses CVE-2025-27817 URL allowlist restriction

authenticationcloud-infrastructure-securityconfiguration-auditing+3
511 months ago
inetutils-telnetd-auth-bypass preview

inetutils-telnetd-auth-bypass

GitHubleonjza/inetutils-telnetd-auth-bypass

A small docker lab to play with cve-2026-24061, the inetutils-telnetd authentication bypass.

authenticationexploitationlabs-practice+2
128 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHublucaspdiniz/cve-2026-24061

Vulnerability in GNU InetUtils telnetd Enables Remote Root Access

authenticationexploitationpenetration-testing+2
8 months ago
CVE-2026-24061-POC preview

CVE-2026-24061-POC

GitHubjayglxr/cve-2026-24061-poc

Proof-of-concept exploit for CVE-2026-24061, a critical remote authentication bypass in GNU inetutils-telnetd via crafted NEW_ENVIRON USER variable,…

authenticationexploitationnetwork-security+3
688 months ago
CVE-2026-24061_Lab preview

CVE-2026-24061_Lab

GitHubgabs-hub/cve-2026-24061_lab

Educational Docker lab demonstrating CVE-2026-24061, an authentication bypass in GNU telnetd allowing root access via argument injection in the USER…

authenticationeducationexploitation+2
8 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubclayofgilgamesh/cve-2026-29000

CTF lab and exploit toolkit for CVE-2026-29000, a pac4j-jwt JWE authentication bypass. Includes vulnerable Flask target, token forging library,…

authenticationctfeducation+5
6 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHub0xw1ld/cve-2026-29000

Rust-based exploit generator for CVE-2026-29000, an authentication bypass in pac4j-jwt via alg:none JWT nested in JWE, automating JWKS retrieval and…

authenticationctfexploitation+3
6 months ago
Previous1234Next