Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
177 results
CVE-2026-8793 preview

CVE-2026-8793

GitHubh4zaz/cve-2026-8793

esponsible disclosure write-ups for CVE-2026-8793 - PaperCut NG 25.0.11

authenticationeducationexploitation+4
1 month ago
CVE-2026-5050-Blind-LDAP-Injection-via-Unescaped-Filter preview

CVE-2026-5050-Blind-LDAP-Injection-via-Unescaped-Filter

GitHubgeorge0papasotiriou/cve-2026-5050-blind-ldap-injection-via-unescaped-filter

Reproduces CVE-2026-5050 with a simulated Flask LDAP server and exploit script, demonstrating blind LDAP injection via unescaped filters to bypass…

authenticationeducationexploitation+2
2 months ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubhsw109/cve-2018-10933

Education purpose for CVE-2018-10933

authenticationeducationexploitation+3
42 years ago
CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID preview

CVE-2026-11116-SNMPv3-Authentication-Bypass-via-Default-EngineID

GitHubgeorge0papasotiriou/cve-2026-11116-snmpv3-authentication-bypass-via-default-engineid

Demonstrates CVE-2026-11116 SNMPv3 authentication bypass caused by guessable default EngineIDs, with a Python pysnmp simulation and guidance for…

authenticationeducationexploitation+3
2 months ago
cve-2026-43512-poc preview

cve-2026-43512-poc

GitHubcovepseng/cve-2026-43512-poc

Exploitability PoC for CVE-2026-43512 (Apache Tomcat Digest Authentication Bypass)

authenticationeducationexploitation+4
23 months ago
CVE-2026-51788 preview

CVE-2026-51788

GitHubaykhan32/cve-2026-51788

Detailed CVE-2026-51788 advisory for a DoS vulnerability in cleverange_auth v0.1.10, with technical analysis, CVSS scoring, and mitigation guidance…

authenticationeducationemail-security+3
2 months ago
2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report preview

2025-Oracle-SSO-LDAP-Attack-Post-Incident-Written-Report

GitHubjwa7470/2025-oracle-sso-ldap-attack-post-incident-written-report

Post-incident report analyzing the Oracle Cloud SSO/LDAP supply chain attack (CVE-2021-35587). Details the exploitation of legacy server…

authenticationcloud-securityeducation+3
1 month ago
CVE-2026-20253 preview

CVE-2026-20253

GitHubhet-kalariya/cve-2026-20253

Self-contained security training lab reproducing CVE-2026-20253 (Splunk Enterprise unauthenticated RCE). Provides a Docker-based environment to…

authenticationcommand-and-controlctf+9
2 months ago
CP-PLUS-EZ-P21-CVE-2026-65893-65894 preview

CP-PLUS-EZ-P21-CVE-2026-65893-65894

GitHubcybervinner/cp-plus-ez-p21-cve-2026-65893-65894

Documents CP PLUS EZ-P21 IP camera CVEs: arbitrary code execution via debug feature and improper authentication of HTTP endpoints, with responsible…

authenticationeducationembedded-systems-security+5
2 months ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubap0dexme0/cve-2023-27350

Perfom With Massive Authentication Bypass In PaperCut MF/NG

authenticationeducationexploitation+3
23 years ago
CVE-2026-34348 preview

CVE-2026-34348

GitHubhorkimhab/cve-2026-34348

CVE-2026-34348 - Draft or TODO

authenticationeducationexploitation+3
1 month ago
CVE-2026-29000-PoC preview

CVE-2026-29000-PoC

GitHubdua2z3rr/cve-2026-29000-poc

CVE-2026-29000 - pac4j-jwt (< 4.5.9 / < 5.7.9 / < 6.3.3) JwtAuthenticator authentication bypass PoC

authenticationctfeducation+5
11 month ago
CVE-2024-10542 preview

CVE-2024-10542

GitHububaydev/cve-2024-10542

WordPress Spam protection, AntiSpam, FireWall by CleanTalk Plugin <= 6.43.2 is vulnerable to Unauthenticated Arbitrary Plugin Installation

authenticationeducationexploitation+3
31 year ago
CVE-2024-4358 preview

CVE-2024-4358

GitHubgh-ost00/cve-2024-4358

Telerik Report Server deserialization and authentication bypass exploit chain for CVE-2024-4358/CVE-2024-1800

authenticationeducationexploitation+3
32 years ago
CVE-2026-54415-PoC preview

CVE-2026-54415-PoC

GitHubabdugafforov-bobur/cve-2026-54415-poc

PoC for CVE-2026-54415 — Azuriom CMS (<1.2.11) Broken Access Control → account takeover

authenticationctfeducation+4
23 months ago
CVE-2025-47646 preview

CVE-2025-47646

GitHubnxploited/cve-2025-47646

WordPress PSW Front-end Login &amp; Registration Plugin <= 1.12 is vulnerable to Broken Authentication

authenticationeducationexploitation+3
21 year ago
CVE-2026-20896-Gitea-Authentication-Bypass preview

CVE-2026-20896-Gitea-Authentication-Bypass

GitHubjudgedbykira/cve-2026-20896-gitea-authentication-bypass

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

authenticationeducationexploitation+5
11 month ago
CVE-2026-8206 preview

CVE-2026-8206

GitHubdungsocool/cve-2026-8206

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

authenticationeducationexploitation+6
12 months ago
Previous1…456…10Next