Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
237 results
ShuckNT preview

ShuckNT

GitHubyanncam/shucknt

ShuckNT is the script of Shuck.sh online service for on-premise use. It is design to dowgrade, convert, dissect and shuck authentication token based…

authenticationcryptographyhash-analysis+3
78
1 year ago
ProxyLogon preview

ProxyLogon

GitHubrickgeex/proxylogon

ProxyLogon is the formally generic name for CVE-2021-26855, a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the…

authenticationeducationexploitation+3
335 years ago
ft9201-libfprint preview

ft9201-libfprint

GitHubomgrant/ft9201-libfprint

Linux libfprint driver for the Focal-systems FT9201 (2808:93a9) USB fingerprint reader — runs FocalTech's own Windows matching engine natively on…

authenticationbinary-analysisembedded-systems-security+4
252 months ago
hostap preview

hostap

GitHubjmalinen/hostap

Clone of w1.fi hostap.git - NOTE: This is not the main development location and pull requests for this repository are ignored. See the upstream…

authenticationwi-fi-auditingwireless-security
166 years ago
Keycloak_CVE-2026-18963_PoC preview

Keycloak_CVE-2026-18963_PoC

GitHubprot0tw/keycloak_cve-2026-18963_poc

This repo is poc of cve-2026-18963. Please use it on legal products (lab, local,...).

authenticationexploitationlabs-practice+3
151 month ago
lempo preview

lempo

GitHubmauroeldritch/lempo

LEMPO (Ldap Exposure on POrtainer) is an exploit for CVE-2018-19466 (LDAP Credentials Disclosure on Portainer). Featured @ DevFest Siberia 2018

authenticationcontainer-securityexploitation+2
116 years ago
CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass preview

CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass

GitHubabsholi7ly/cve-2026-24858-forticloud-sso-authentication-bypass

CVE-2026-24858 FortiCloud Single Sign On (SSO) a factory default enabled feature once you register any FortiGate/FortiManager/FortiAnalyzer …

authenticationexploitationpenetration-testing+3
98 months ago
CVE-2025-59718-PoC preview

CVE-2025-59718-PoC

GitHubexfil0/cve-2025-59718-poc

Fortinet announced two closely related authentication‑bypass vulnerabilities on 9 December 2025. Both flaws involve improper verification of…

authenticationeducationexploitation+5
69 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubjenderal92/cve-2026-41940

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

authenticationcommand-and-controlexploitation+6
44 months ago
CVE-2024-4040 preview

CVE-2024-4040

GitHubgotr00t0day/cve-2024-4040

Exploit for CrushFTP SSTI vulnerability (CVE-2024-4040) enabling unauthenticated file read, authentication bypass, and remote code execution on…

authenticationexploitationinformation-gathering+3
72 years ago
WPTimeCapsulePOC preview

WPTimeCapsulePOC

GitHubsecforce/wptimecapsulepoc

An authentication bypass was recently discovered (https://www.webarxsecurity.com/vulnerability-infinitewp-client-wp-time-capsule/) on WP Time Capsule…

authenticationexploitationpayload-development+3
56 years ago
mobileiron-exploit preview

mobileiron-exploit

GitHubsynacktiv/mobileiron-exploit

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

authenticationauthentication-authorizationexploitation+3
92 years ago
CVE-2026-65400 preview

CVE-2026-65400

GitHubhorkimhab/cve-2026-65400

Proof-of-concept exploit for CVE-2026-65400 enabling authenticated file read/write, reverse shells, and persistence on macOS via Apple ScreenSharing.

authenticationeducationexploitation+4
31 month ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubund3sc0n0c1d0/cve-2022-40684

Utilities for exploiting vulnerability CVE-2022-40684 (FortiOS / FortiProxy / FortiSwitchManager - Authentication bypass on administrative interface).

authenticationexploitationpenetration-testing+2
43 years ago
CVE-2024-29296 preview

CVE-2024-29296

GitHubthaysolis/cve-2024-29296

CVE-2024-29296 - User enumeration on Portainer CE - 2.19.4

authenticationinformation-gatheringpenetration-testing+3
41 year ago
CVE-2026-53595_exploit preview

CVE-2026-53595_exploit

GitHub0xdak/cve-2026-53595_exploit

Exploit script chaining CVE-2026-53595 (anonymous account takeover) and CVE-2026-53593 (.pht upload) for unauthenticated remote code execution on…

authenticationexploitationpayload-generation+4
2 months ago
PoC-for-CVE-2021-38540- preview

PoC-for-CVE-2021-38540-

GitHubcaptain-v-hook/poc-for-cve-2021-38540-

Missing Authentication on Critical component CVE-2021-38540

authenticationexploitationmisconfiguration+3
44 years ago
Kerberos_CVE-2022-33679 preview

Kerberos_CVE-2022-33679

GitHubnotareaperbutdr34p3r/kerberos_cve-2022-33679

Python exploit for CVE-2022-33679 targeting Kerberos authentication to perform privilege escalation on Windows domain controllers via RC4 session key…

authenticationexploitationnetwork-security+2
43 years ago
Previous1234…14Next