Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
53 results
swift-nio-ssh preview

swift-nio-ssh

GitHubapple/swift-nio-ssh

SwiftNIO SSH is a programmatic implementation of SSH using SwiftNIO

authenticationencryption-decryption-toolsnetwork-security+2
520
1 day ago
CVE-2026-19660 preview

CVE-2026-19660

GitHubmurrez/cve-2026-19660

Python PoC scanner and exploit for CVE-2026-14378, a pre-auth administrator session takeover in the DevKit Pro WordPress plugin via forged…

authenticationexploitationinformation-gathering+5
6 days ago
CVE-2026-14378 preview

CVE-2026-14378

GitHubmurrez/cve-2026-14378

Python PoC scanner and exploit helper for CVE-2026-14378, an unauthenticated admin session takeover in the DevKit Pro WordPress plugin via forged…

authenticationdefensive-toolsexploitation+7
6 days ago
CVE-2026-103977 preview

CVE-2026-103977

GitHubpervinzahidli/cve-2026-103977

Session-scoped TOTP rate limiting permits repeated verification attempts

authenticationauthentication-authorizationdefensive-tools+2
6 days ago
CVE-2026-76504-Proof-of-concept preview

CVE-2026-76504-Proof-of-concept

GitHubshadowforge-cyber/cve-2026-76504-proof-of-concept

EUVD-2026-89950 Improper Handling of URL Encoding (Hex Encoding) (CWE-177)

api-securityauthenticationexploitation+5
27 days ago
By-Poloss..-..CVE-2026-19125 preview

By-Poloss..-..CVE-2026-19125

GitHubpolosss/by-poloss..-..cve-2026-19125

Verified proof-of-concept exploiting the EthPress <= 2.3.5 unauthenticated authentication bypass, granting a WordPress administrator session via a…

authenticationexploitationpassword-attacks+5
15 days ago
CVE-2026-20079-checker preview

CVE-2026-20079-checker

GitHubdiegoarias008/cve-2026-20079-checker

Read-only Python checker that validates CVE-2026-20079 Cisco FMC authentication-bypass behavior by comparing unauthenticated and csm_processes…

authenticationdefensive-toolsinformation-gathering+5
24 days ago
sshamble preview

sshamble

GitHubrunzeroinc/sshamble

Research tool that scans SSH services for authentication bypasses, timing leaks, weak keys, and post-session exposures, with JSON output and analysis.

authenticationdefensive-toolsinformation-gathering+6
1.2k27 days ago
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
171 month ago
CVE-2026-78905-Facebook-Account-Takeover preview

CVE-2026-78905-Facebook-Account-Takeover

GitHubvxssroott/cve-2026-78905-facebook-account-takeover

Social Media Infrastructure Vulnerability Research. CVE-2026-78905: OAuth token reuse and session hijacking in Facebook's Graph API.

authenticationexploitationvulnerability-analysis+1
31 month ago
CVE-2026-71206-PoC preview

CVE-2026-71206-PoC

GitHubnel-droid/cve-2026-71206-poc

PoC: Shiori JWT CheckToken never re-validates account state (CVE-2026-71206, High 8.2)

authenticationauthentication-authorizationexploitation+3
1 month ago
CVE-2026-20896-Gitea-Authentication-Bypass preview

CVE-2026-20896-Gitea-Authentication-Bypass

GitHubjudgedbykira/cve-2026-20896-gitea-authentication-bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

authenticationeducationexploitation+5
11 month ago
agensic preview

agensic

GitHubalex188dot/agensic

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

ai-securityauthenticationdigital-forensics+5
292 months ago
pocKeycloakCVE-2023-0264 preview

pocKeycloakCVE-2023-0264

GitHubeliangonzi00/pockeycloakcve-2023-0264

Proof-of-concept exploit for CVE-2023-0264 (Keycloak OIDC session hijacking) with a frontend for session_id substitution and an agent that detects…

authenticationdefensive-toolsexploitation+7
2 months ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
2 months ago
CVE-2026-48611-phpBB preview

CVE-2026-48611-phpBB

GitHublxdwnpiper/cve-2026-48611-phpbb

Python proof-of-concept exploit that bypasses authentication in phpBB 3.3.16 and below by forging session cookies to gain admin access.

authenticationexploitationpassword-attacks+4
3 months ago
Research-CVE-2026-21858 preview

Research-CVE-2026-21858

GitHubbannt08/research-cve-2026-21858

Technical analysis and proof-of-concept for CVE-2026-21858, an authentication bypass and RCE in n8n, demonstrating LFI, session forgery, and full…

authenticationexploitationremote-access-trojan+2
5 months ago
LogHound preview

LogHound

GitHubrnb-team/loghound

Post-Exploitation EVTX Analyzer for BloodHound Mapping

authenticationdigital-forensicsforensics+6
125 months ago
Previous123Next