Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
61 results
evil-winrm preview

evil-winrm

GitHubhackplayers/evil-winrm

The ultimate WinRM shell for hacking/pentesting

authenticationexploitationpayload-generation+3
5.5k
11 days ago
CVE-2026-20079 preview

CVE-2026-20079

GitHubcyberauth/cve-2026-20079

Implements the CVE-2026-20079 authentication-bypass-to-root-RCE chain against Cisco Secure FMC using fingerprint, check, proof, and interactive…

authenticationexploitationpayload-development+3
420 days ago
CVE-2026-9090-poc preview

CVE-2026-9090-poc

GitHubkimdir01/cve-2026-9090-poc

PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

authenticationexploitationpayload-generation+4
29 days ago
wp2shell-poc preview

wp2shell-poc

GitHubicex0/wp2shell-poc

wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain

authenticationcommand-and-controlexploitation+5
7761 month ago
CVE-2026-23009-DICOM-Network-Image-Injection-Without-Authentication preview

CVE-2026-23009-DICOM-Network-Image-Injection-Without-Authentication

GitHubgeorge0papasotiriou/cve-2026-23009-dicom-network-image-injection-without-authentication

Proof-of-concept for CVE-2026-23009 demonstrating unauthenticated DICOM image injection into vulnerable PACS servers using pynetdicom, with a…

authenticationexploitationnetwork-security+3
1 month ago
CVE-2026-9198 preview

CVE-2026-9198

GitHub0xgh057r3c0n/cve-2026-9198

IBM Langflow Unauthenticated RCE via Auto-Login Bypass

authenticationcommand-and-controlexploitation+4
11 month ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
1 month ago
sdk preview

sdk

GitLabcosignet/sdk

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

api-securityauthenticationauthentication-authorization+3
2 months ago
CVE-2026-5118 preview

CVE-2026-5118

GitHub1beelze/cve-2026-5118

Automated exploit and mass scanner for CVE-2026-5118, an unauthenticated privilege escalation in WordPress Divi Form Builder <=5.1.2, enabling admin…

authenticationexploitationpayload-generation+6
2 months ago
Explotacion-CVE-2023-32315-Openfire preview

Explotacion-CVE-2023-32315-Openfire

GitHubpulentoski/explotacion-cve-2023-32315-openfire

Python exploit for CVE-2023-32315 targeting Openfire servers. Bypasses admin panel authentication via Unicode path traversal to create an…

authenticationexploitationpayload-generation+3
2 months ago
CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass preview

CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass

GitHubbiitts/cve-2026-49230-apisix-jwe-decrypt-auth-bypass

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

api-securityauthenticationcryptography+5
2 months ago
JWTweak preview

JWTweak

GitHubrishuranjanofficial/jwtweak

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

authenticationcryptographypayload-generation+3
1032 months ago
cpanel2shell-scanner preview

cpanel2shell-scanner

GitHubassetnote/cpanel2shell-scanner

High fidelity scanner for CVE-2026-41940 (cPanel & WHM authentication bypass)

authenticationexploitationpayload-development+3
933 months ago
CVE-2025-26788 preview

CVE-2025-26788

GitHubjun2e0/cve-2025-26788

Proof-of-concept exploit for CVE-2025-26788 demonstrating WebAuthn credential ID manipulation via JavaScript hooking to bypass authentication in…

authenticationexploitationpayload-development+2
4 months ago
CVE-2026-37749 preview

CVE-2026-37749

GitHubmenevarad007/cve-2026-37749

Proof-of-concept for SQL injection in CodeAstro Simple Attendance Management System 1.0, demonstrating authentication bypass via crafted username…

authenticationexploitationvulnerability-analysis+2
14 months ago
CVE-2026-21858 preview

CVE-2026-21858

GitHubkaleth4/cve-2026-21858

Automated exploit chain for n8n achieving unauthenticated arbitrary file read, admin token forgery, and sandbox bypass to remote code execution via…

authenticationexploitationpayload-development+4
5 months ago
CVE-2025-11986 preview

CVE-2025-11986

GitHubjfriedli/cve-2025-11986

Proof-of-concept exploit for CVE-2025-11986 demonstrating unauthenticated access bypass in WordPress crypto_connect plugin via nonce extraction and…

authenticationexploitationpayload-generation+3
5 months ago
Certi-Bhai preview

Certi-Bhai

GitHubincredibleindishell/certi-bhai

AD CS exploitation related stuff goes here

authenticationexploitationpayload-generation+4
385 months ago
Previous1234Next