Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
237 results
CVE-2022-22845-Exploit preview

CVE-2022-22845-Exploit

GitHubomribaso/cve-2022-22845-exploit

Exploit for CVE-2022-22845 - Unauthenticated Admin Takeover On QXIP SIPCAPTURE Homer-App up to 1.4.27

authenticationexploitationpenetration-testing+2
2
4 years ago
CVE-2026-20896-Gitea-Authentication-Bypass preview

CVE-2026-20896-Gitea-Authentication-Bypass

GitHubjudgedbykira/cve-2026-20896-gitea-authentication-bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

authenticationeducationexploitation+5
11 month ago
SecuraBV-CVE-2020-1472 preview

SecuraBV-CVE-2020-1472

GitHubfa1c0n35/securabv-cve-2020-1472

Python script using Impacket to test for the Zerologon vulnerability (CVE-2020-1472) by attempting Netlogon authentication bypass on Domain…

authenticationexploitationnetwork-security+2
25 years ago
Craftcms-PoC-CVE-2026-31266 preview

Craftcms-PoC-CVE-2026-31266

GitHub0xrixet/craftcms-poc-cve-2026-31266

Security research on Craft CMS authentication mechanism

authenticationauthentication-authorizationexploitation+3
4 months ago
PaperCut-Authentication_Bypass_and_RCE preview

PaperCut-Authentication_Bypass_and_RCE

GitHubjoaoaugustom/papercut-authentication_bypass_and_rce

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

authenticationeducationexploitation+5
4 months ago
CVE-2026-32646 preview

CVE-2026-32646

GitHubmichaeladamgroberman/cve-2026-32646

CVE-2026-32646: Missing Authentication on Admin Device Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securityauthenticationcloud-security+6
4 months ago
CVE-2026-44596 preview

CVE-2026-44596

GitHubex-cal1bur/cve-2026-44596

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

api-security-testingauthenticationpassword-attacks+3
4 months ago
CVE-2024-8682 preview

CVE-2024-8682

GitHub4minx/cve-2024-8682

PoC exploit for CVE-2024-8682, enabling unauthenticated user registration on JNews WordPress themes via crafted AJAX requests.

authenticationexploitationpenetration-testing+2
21 year ago
CVE-2026-36959 preview

CVE-2026-36959

GitHubkirubel-cve/cve-2026-36959

Proof-of-concept exploit for CVE-2026-36959, a missing rate limiting vulnerability in U-SPEED Router firmware allowing brute-force attacks on the…

authenticationexploitationpenetration-testing+2
5 months ago
CVE-2026-40022 preview

CVE-2026-40022

GitHuboscerd/cve-2026-40022

Reproducer for CVE-2026-40022: Apache Camel camel-platform-http-main authentication bypass on non-root context paths

authenticationexploitationmisconfiguration+3
3 months ago
research preview

research

GitHubalessandrobertoldi/research

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

authenticationcurated-resourcesdns-subdomain-enumeration+5
5 months ago
CVE-2026-28766 preview

CVE-2026-28766

GitHubmichaeladamgroberman/cve-2026-28766

CVE-2026-28766: Missing Authentication on User Account Endpoint — Gardyn Home Kit (ICSA-26-055-03)

api-securityauthenticationcloud-security+3
4 months ago
CVE-2025-48827 preview

CVE-2025-48827

GitHubsh4den/cve-2025-48827

This repository contains a proof-of-concept exploit for CVE-2025-48827, a critical authentication bypass vulnerability affecting vBulletin…

authenticationeducationexploitation+3
13 months ago
CVE-2025-31161 preview

CVE-2025-31161

GitHubcesarbtakeda/cve-2025-31161

Exploit for CVE-2025-31161 with Python and C implementations, allowing authorized penetration testers to manipulate user accounts on target hosts.

authenticationexploitationpenetration-testing+2
111 months ago
CVE-2026-41940-AuthBypass-Detector preview

CVE-2026-41940-AuthBypass-Detector

GitHubunteikyou/cve-2026-41940-authbypass-detector

Detection tool for cPanel/WHM CVE-2026-41940 (CRLF injection auth bypass). Verify vulnerability on servers you own or have permission to test. For…

authenticationpenetration-testingreconnaissance+2
15 months ago
CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX preview

CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX

GitHubbimboxh4/cve-2025-66039_cve-2025-61675_cve-2025-61678_reepbx

This vulnerability allows both authenticated and unauthenticated remote attackers to execute remote code on vulnerable FreePBX instances. These…

authenticationeducationexploitation+3
19 months ago
Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467 preview

Apache-OFBiz-Auth-Bypass-and-RCE-Exploit-CVE-2023-49070-CVE-2023-51467

GitHubgraysignal/apache-ofbiz-auth-bypass-and-rce-exploit-cve-2023-49070-cve-2023-51467

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

authenticationexploitationpenetration-testing+3
12 years ago
ssh_Enum_vaild preview

ssh_Enum_vaild

GitHub0xnehru/ssh_enum_vaild

A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2…

authenticationeducationexploitation+3
11 year ago
Previous1…345…14Next