Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
93 results
CVE-2022-24342 preview

CVE-2022-24342

GitHubyuriisanin/cve-2022-24342

PoC for CVE-2022-24342: account takeover via CSRF in GitHub authentication

authenticationexploitationpenetration-testing+3
36
4 years ago
agent-vault-proxy preview

agent-vault-proxy

GitHubinflightsec/agent-vault-proxy

Just-in-time API keys for AI agents - and any other process you route through it: the caller only ever sees a placeholder.

ai-securityapi-securityauthentication+3
3118 days ago
HATCHA preview

HATCHA

GitHubmondaycom/hatcha

CAPTCHA proves you're human. HATCHA proves you're not.

ai-securityanti-botauthentication+3
1026 months ago
agentsid-scanner preview

agentsid-scanner

GitHubagentsid-dev/agentsid-scanner

Security scanner for MCP servers. Grades auth, permissions, injection risks, and tool safety. The Lighthouse of agent security.

ai-securityapi-security-testingauthentication+7
255 months ago
CVE-2026-0257 preview

CVE-2026-0257

GitHubsfewer-r7/cve-2026-0257

Proof-of-concept script to leverage the PAN-OS GlobalProtect authentication bypass CVE-2026-0257

authenticationexploitationpenetration-testing+3
284 months ago
agensic preview

agensic

GitHubalex188dot/agensic

Cryptographic terminal forensics and session replay for AI agents. Tracks, signs, and audits every command with provenance labels, replayable…

ai-securityauthenticationdigital-forensics+5
291 month ago
CVE-2026-19490 preview

CVE-2026-19490

GitHubtarpeg007/cve-2026-19490

NetScaler ADC/Gateway SAML unsigned-assertion bypass via HTTP-Redirect binding (CTX696939) - root cause analysis + PoC

authenticationbinary-analysisexploitation+4
1325 days ago
OWASP-WSTG-Rag preview

OWASP-WSTG-Rag

GitHubzilbonn/owasp-wstg-rag

OWASP Web Security Testing Guide RAG system with ChromaDB, MCP for Claude Code

ai-securityapi-security-testingauthentication+8
229 months ago
CVE-2022-25262 preview

CVE-2022-25262

GitHubyuriisanin/cve-2022-25262

PoC + vulnerability details for CVE-2022-25262 / JetBrains Hub single-click SAML response takeover

authenticationexploitationpenetration-testing+3
174 years ago
CVE-2026-20127 preview

CVE-2026-20127

GitHubsfewer-r7/cve-2026-20127

Exploit for Cisco Catalyst SD-WAN Controller authentication bypass (CVE-2026-20127) that forges DTLS CHALLENGE_ACK_ACK messages to gain unauthorized…

authenticationexploitationnetwork-security+3
246 months ago
watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523 preview

watchTowr-vs-Ivanti-Sentry-RCE-CVE-2026-10520-CVE-2026-10523

GitHubwatchtowrlabs/watchtowr-vs-ivanti-sentry-rce-cve-2026-10520-cve-2026-10523

Python-based detection artifact generator for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520,…

authenticationexploitationpenetration-testing+3
143 months ago
CVE-2022-40684-POC preview

CVE-2022-40684-POC

GitHubkljunowsky/cve-2022-40684-poc

Exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager

authenticationexploitationpenetration-testing+3
163 years ago
cPanelWHM-AuthBypass preview

cPanelWHM-AuthBypass

GitHubkagantua/cpanelwhm-authbypass

Go-based scanner and exploit tool for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports batch scanning, token leakage, and…

authenticationexploitationpenetration-testing+3
115 months ago
vibe-coding-security preview

vibe-coding-security

GitHubboxed-dev/vibe-coding-security

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

ai-securityapi-securityauthentication+9
151 month ago
WantasticCore preview

WantasticCore

GitHubwantasticapp/wantasticcore

AIO Cloud Managment Server

ai-securityauthenticationcloud-security+6
152 months ago
0-click-RCE-Exploit-for-CVE-2024-10924 preview

0-click-RCE-Exploit-for-CVE-2024-10924

GitHubjoshuaprovoste/0-click-rce-exploit-for-cve-2024-10924

Unauthenticated authentication bypass to RCE exploit for CVE-2024-10924. Abuses an authentication and 2FA bypass in the Really Simple Security…

authenticationexploitationpayload-development+4
148 months ago
CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass preview

CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass

GitHubabsholi7ly/cve-2026-24858-forticloud-sso-authentication-bypass

CVE-2026-24858 FortiCloud Single Sign On (SSO) a factory default enabled feature once you register any FortiGate/FortiManager/FortiAnalyzer …

authenticationexploitationpenetration-testing+3
98 months ago
CVE-2025-58434 preview

CVE-2025-58434

GitHubr3vpwnx/cve-2025-58434

Exploit chain for Flowise 3.0.5: unauthenticated account takeover via password-reset token disclosure (CVE-2025-58434) chained to CustomMCP…

authenticationexploitationpenetration-testing+3
18 days ago
Previous123456Next