Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
145 results
CVE-2026-29000 preview

CVE-2026-29000

GitHubjake-young-dev/cve-2026-29000

Proof-of-concept exploit for CVE-2026-29000, an authentication bypass in pac4j-jwt, demonstrating JWT crafting with arbitrary roles for unauthorized…

authenticationeducationexploitation+2
4 months ago
CVE-2026-35030-PoC preview

CVE-2026-35030-PoC

GitHublearner202649/cve-2026-35030-poc

The code for personally reproducing the corresponding vulnerability

authenticationcryptographyeducation+5
3 months ago
PaperCut-Authentication_Bypass_and_RCE preview

PaperCut-Authentication_Bypass_and_RCE

GitHubjoaoaugustom/papercut-authentication_bypass_and_rce

This exploit is based on CVE-2023-27350 and was built upon the original exploit by horizon3ai and the Metasploit module.

authenticationeducationexploitation+5
3 months ago
CVE-2026-42568 preview

CVE-2026-42568

GitHubex-cal1bur/cve-2026-42568

An LDAP injection vulnerability exists in org.yamcs.security.LdapAuthModule. The username parameter is inserted directly into LDAP search filters…

authenticationeducationexploitation+3
3 months ago
CVE-2023-6329 preview

CVE-2023-6329

GitHubitzvenom/cve-2023-6329

Python PoC exploit for CVE-2023-6329 authentication bypass in Control iD iDSecure. Reconstructs admin credentials via predictable password derivation…

authenticationeducationexploitation+4
15 months ago
POC_CVE-2015-9235 preview

POC_CVE-2015-9235

GitHubtierchampion/poc_cve-2015-9235

Demo of the algorithm confusion attack on various JWT libraries

authenticationctfeducation+3
5 months ago
CVE-2026-29000-pac4j-jwt-auth-bypass preview

CVE-2026-29000-pac4j-jwt-auth-bypass

GitHubptechamanja/cve-2026-29000-pac4j-jwt-auth-bypass

Proof-of-Concept (PoC) for an authentication bypass vulnerability affecting applications using pac4j-jwt with JWE (JSON Web Encryption).

authenticationctfexploitation+3
15 months ago
CVE-2026-44338-Lab preview

CVE-2026-44338-Lab

GitHubrootdirective-sec/cve-2026-44338-lab

Docker-based lab demonstrating CVE-2026-44338 authentication bypass in PraisonAI's legacy Flask API. Includes vulnerable and patched services with…

authenticationeducationlabs-practice+3
3 months ago
CVE-2025-11171 preview

CVE-2025-11171

GitHubsnailsploit/cve-2025-11171

CVE-2025-11171

authenticationeducationexploitation+3
3 months ago
Flowise-CVE-2025-58434-PasswordReset preview

Flowise-CVE-2025-58434-PasswordReset

GitHubr3nsi15/flowise-cve-2025-58434-passwordreset

Unauthenticated password reset exploit for Flowise AI ≤ 3.0.5. Abuses the /api/v1/account/forgot-password endpoint to change any user's password…

authenticationeducationexploitation+3
14 months ago
FlowiseAI-Critical-KillChain preview

FlowiseAI-Critical-KillChain

GitHubcveteam/flowiseai-critical-killchain

Critical unauthenticated kill chain leading to full RCE in FlowiseAI (CVE-2025-58434 + CVE-2025-59528)

authenticationeducationexploitation+5
14 months ago
Principal-HackTheBox preview

Principal-HackTheBox

GitHubledksv/principal-hackthebox

Detailed walkthrough of exploiting CVE-2026-29000 in pac4j-jwt to bypass authentication, extract credentials from API settings, and escalate…

authenticationcryptographyctf+5
4 months ago
Moniker-Link-Lab-Setup preview

Moniker-Link-Lab-Setup

GitHube-m-e-k-a/moniker-link-lab-setup

Penetration testing lab demonstrating CVE-2024-21413 moniker link exploitation for NTLM credential theft, including attack execution, hash cracking,…

authenticationeducationexploitation+6
5 months ago
Web-Penetration-Test preview

Web-Penetration-Test

GitHubsalimelh94/web-penetration-test

Exploiting WordPress vulnerabilities (CVE-2025-34077), authentication bypass via cookie injection, and privilege escalation to root. Part of my…

authenticationctfeducation+6
4 months ago
cve-2025-29927-nextjs preview

cve-2025-29927-nextjs

GitHubgitgudkrish/cve-2025-29927-nextjs

Educational demo of CVE-2025-29927, a critical Next.js middleware authentication bypass. Includes a vulnerable admin panel, proof-of-concept exploit…

authenticationeducationpenetration-testing+3
3 months ago
starlette-host-header-lab preview

starlette-host-header-lab

GitHubxtremebeing/starlette-host-header-lab

Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710

authenticationeducationlabs-practice+3
13 months ago
pocketbase-CVE-2026-44166 preview

pocketbase-CVE-2026-44166

GitHubalardiians/pocketbase-cve-2026-44166

Lab + writeup for CVE-2026-44166: PocketBase OAuth2 account pre-hijacking via unvalidated createData.email

authenticationctfeducation+5
2 months ago
ssh_Enum_vaild preview

ssh_Enum_vaild

GitHub0xnehru/ssh_enum_vaild

A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2…

authenticationeducationexploitation+3
11 year ago
Previous1…567…9Next