Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
81 results
vibe-coding-security preview

vibe-coding-security

GitHubboxed-dev/vibe-coding-security

Pre-launch security checklist for AI-generated apps (Lovable, v0, Bolt, Cursor). 69 checks covering Supabase RLS, exposed keys, and prompt injection.…

ai-securityapi-securityauthentication+9
15
1 month ago
CVE-2024-32113-POC preview

CVE-2024-32113-POC

GitHubracerz-fighting/cve-2024-32113-poc

Apache OfBiz vulns

authenticationexploitationpayload-generation+3
72 years ago
CVE-2022-29593 preview

CVE-2022-29593

GitHub9lyph/cve-2022-29593

Proof-of-concept exploit for authentication bypass via capture-replay in Dingtian DT-R002 relay, allowing unauthorized control of relays through HTTP…

authenticationexploitationfuzzing+8
81 year ago
some-tweak-to-hide-jwt-payload-values preview

some-tweak-to-hide-jwt-payload-values

GitHubpassword123456/some-tweak-to-hide-jwt-payload-values

Lightweight Python library for obfuscating JWT payload values using XOR encryption with timestamp-based keys, preventing plaintext decoding of…

api-securityauthenticationeducation+1
102 years ago
the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass preview

the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

GitHubhunt-benito/the-token-was-a-row-number-cve-2026-67602-phpipam-rest-api-authentication-bypass

Exploit and PoC for CVE-2026-67602, an authentication bypass in phpIPAM REST API via object-cache key collision, including a logic-level PoC and…

api-securityauthenticationexploitation+3
1 month ago
CVE-2026-44351-poc preview

CVE-2026-44351-poc

GitHubisaca0315/cve-2026-44351-poc

Proof-of-concept for CVE-2026-44351, an authentication bypass in fast-jwt <6.2.4 where an empty HMAC key lets attackers forge arbitrary JWTs accepted…

api-securityauthenticationcryptography+6
13 days ago
inference-gateway-PoC preview

inference-gateway-PoC

GitHubsqueeze440/inference-gateway-poc

PoC — cross-origin requests reuse the configured provider API key in inference-gateway (GHSA-5293-fcm6-fh8v, CVE-2026-87009, CVSS 5.4).

api-securityauthenticationexploitation+3
18 days ago
CVE-2026-20079-checker preview

CVE-2026-20079-checker

GitHubdiegoarias008/cve-2026-20079-checker

Read-only Python checker that validates CVE-2026-20079 Cisco FMC authentication-bypass behavior by comparing unauthenticated and csm_processes…

authenticationdefensive-toolsinformation-gathering+5
14 days ago
CVE-2026-51954 preview

CVE-2026-51954

GitHubenvincion1991-cmyk/cve-2026-51954

Vulnerability Research

api-securityauthenticationexploitation+2
1 month ago
CVE-2026-58231 preview

CVE-2026-58231

GitHubwildandeveloper/cve-2026-58231

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

api-securityauthenticationinformation-gathering+4
7 days ago
CVE-2025-6514 preview

CVE-2025-6514

GitHubcyberency/cve-2025-6514

mcp-remote exposed to OS command injection

api-securityauthenticationcommand-and-control+3
710 months ago
Galdralag-firmware preview

Galdralag-firmware

GitHubsupermagnum/galdralag-firmware

A cryptographic framework for Baochip-1x .

authenticationcryptographyembedded-systems-security+4
31 month ago
cve-2026-33032-scanner preview

cve-2026-33032-scanner

GitHubtwinson333/cve-2026-33032-scanner

Non-destructive vulnerability scanner for Nginx-UI MCP Endpoint Authentication Bypass (CVE-2026-33032)

api-securityauthenticationexploitation+3
35 months ago
CVE-2026-76460 preview

CVE-2026-76460

GitHubs3v3n-jg/cve-2026-76460

Educational Flask lab simulating CVE-2026-76460 authentication bypass, with vulnerable, secure, and strict modes plus a PoC exploit script and…

api-securityauthenticationdefensive-tools+5
110 days ago
cve-2021-21994_POC preview

cve-2021-21994_POC

GitHubmreza-en/cve-2021-21994_poc

Validates and exploits VMware ESXi SFCB authentication bypass (CVE-2021-21994) via a probe/fuzz harness, enabling unauthenticated CIM-XML enumeration.

authenticationexploitationfuzzing+3
1 month ago
CVE-2026-73519-WolfStack-PoC preview

CVE-2026-73519-WolfStack-PoC

GitHubsqueeze440/cve-2026-73519-wolfstack-poc

PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

api-securityauthenticationcontainer-security+3
1 month ago
CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass preview

CVE-2026-49230-APISIX-jwe-decrypt-Auth-Bypass

GitHubbiitts/cve-2026-49230-apisix-jwe-decrypt-auth-bypass

PoC for CVE-2026-49230: Apache APISIX jwe-decrypt authentication bypass (missing AES-GCM tag validation, CWE-354, CVSS 9.1)

api-securityauthenticationcryptography+5
2 months ago
sdk preview

sdk

GitLabcosignet/sdk

Thin TypeScript + zero-dep Python client and recipes to gate high-risk actions behind a payload-bound passkey approval.

api-securityauthenticationauthentication-authorization+3
2 months ago
Previous12345Next