Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
643 results
CVE-2026-5430 preview

CVE-2026-5430

GitHubabraxas/cve-2026-5430

Disclosure pack and Python PoC for CVE-2026-5430, a JWT algorithm-confusion flaw in WSO2 API Manager 4.5.0 enabling unauthenticated admin account…

api-securityauthenticationcryptography+6
1
8 days ago
CVE-2025-51471-POC preview

CVE-2025-51471-POC

GitHubajtazer/cve-2025-51471-poc

This PoC is for educational and authorized security testing purposes only. Do NOT use against systems you don't own.

authenticationexploitationred-teaming+2
29 months ago
cve-2026-29145 preview

cve-2026-29145

GitHubgregk4sec/cve-2026-29145

Original security research and proof-of-concept for CVE-2026-29145, an Apache Tomcat OCSP authentication bypass vulnerability, including technical…

authenticationexploitationvulnerability-analysis+1
5 months ago
CVE-2023-27524 preview

CVE-2023-27524

GitHubkarthi-the-hacker/cve-2023-27524

Exploit tool for CVE-2023-27524, an authentication bypass vulnerability in Apache Superset. Enables unauthenticated access to Superset instances for…

authenticationexploitationpenetration-testing+2
12 years ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubcesarbtakeda/cve-2025-31161

Exploit for CVE-2025-31161 with Python and C implementations, allowing authorized penetration testers to manipulate user accounts on target hosts.

authenticationexploitationpenetration-testing+2
111 months ago
CVE-2026-34828 preview

CVE-2026-34828

GitHub0xmrma/cve-2026-34828

listmonk’s Session Persistence After Password Reset and Password Change

authenticationexploitationpenetration-testing+2
16 months ago
CVE-2021-3130 preview

CVE-2021-3130

GitHubjet-pentest/cve-2021-3130

Proof-of-concept for CVE-2021-3130: demonstrates credential exposure via HTML obfuscation bypass in Open-AudIT up to 4.0.2, revealing SSH, SNMP, and…

authenticationmisconfigurationpenetration-testing+2
5 years ago
libfido2 preview

libfido2

GitHubyubico/libfido2

Provides library functionality for FIDO2, including communication with a device over USB or NFC.

authenticationcryptographyhardware-security+2
7382 months ago
django-defender preview

django-defender

GitHubjazzband/django-defender

A simple super fast django reusable app that blocks people from brute forcing login attempts

authenticationdefensive-toolspassword-attacks+1
1.1k8 months ago
CVE-2022-40684 preview

CVE-2022-40684

GitHubcarlosevieira/cve-2022-40684

PoC for CVE-2022-40684 - Authentication bypass lead to Full device takeover (Read-only)

authenticationexploitationpenetration-testing+2
863 years ago
github-dev-token-steal-poc preview

github-dev-token-steal-poc

GitHubammaraskar/github-dev-token-steal-poc

Proof-of-concept exploit demonstrating a GitHub OAuth token-stealing vulnerability via crafted developer workflow triggers, enabling unauthorized…

authenticationexploitationsupply-chain-security+2
204 months ago
CVE-2024-8698-POC preview

CVE-2024-8698-POC

GitHubhuydoppaz/cve-2024-8698-poc

Proof-of-concept exploit for CVE-2024-8698 targeting Keycloak SAML authentication bypass. Demonstrates vulnerability exploitation in identity…

authenticationexploitationpenetration-testing+2
61 year ago
CVE-2026-73313 preview

CVE-2026-73313

GitHubbombobombone/cve-2026-73313

Proof-of-concept exploit for CVE-2026-73313, an MFA bypass in XenForo's passkey TFA provider allowing account takeover after password compromise.

authenticationexploitationpenetration-testing+2
25 days ago
CVE-2026-51954 preview

CVE-2026-51954

GitHubenvincion1991-cmyk/cve-2026-51954

Vulnerability Research

api-securityauthenticationexploitation+2
2 months ago
CVE-2026-75431_PowerJob_jwt_key_predictable preview

CVE-2026-75431_PowerJob_jwt_key_predictable

GitHubunpredictable21/cve-2026-75431_powerjob_jwt_key_predictable

Demonstrates a critical JWT signing key predictability vulnerability in PowerJob Server, allowing offline key derivation and token forgery for admin…

authenticationexploitationpenetration-testing+2
1 month ago
watchTowr-vs-Progress-ShareFile-CVE-2026-2699 preview

watchTowr-vs-Progress-ShareFile-CVE-2026-2699

GitHubwatchtowrlabs/watchtowr-vs-progress-sharefile-cve-2026-2699

Detection artifact for CVE-2026-2699 Progress ShareFile authentication bypass. Sends GET to /ConfigService/Admin.aspx to check vulnerability.

authenticationpenetration-testingvulnerability-analysis+1
36 months ago
TYPO3-v7.6.15-Unencrypted-Login-Request preview

TYPO3-v7.6.15-Unencrypted-Login-Request

GitHubfaizzaidi/typo3-v7.6.15-unencrypted-login-request

Proof-of-concept exploit for TYPO3 v7.6.15 unencrypted login request vulnerability (CVE-2017-6370), demonstrating plaintext credential exposure over…

authenticationexploitationpenetration-testing+2
29 years ago
2026-41940-poc preview

2026-41940-poc

GitHubnickpaulsec/2026-41940-poc

CVE-2026-41940: detect and exploit cpanel vuln

authenticationexploitationpenetration-testing+2
15 months ago
Previous1234…36Next