Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
42 results
CVE-2026-27344 preview

CVE-2026-27344

GitHubac8999/cve-2026-27344

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

api-securityauthentication-authorizationmisconfiguration+3
8 days ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
5210 days ago
POC-CVE-2026-56164-exploit preview

POC-CVE-2026-56164-exploit

GitHubsam00/poc-cve-2026-56164-exploit

CVE-2026-56164 is a critical missing-authentication vulnerability affecting on-premises Microsoft SharePoint Server. It allows unauthenticated,…

authentication-authorizationexploitationinformation-gathering+5
214 days ago
CVE-2026-8239 preview

CVE-2026-8239

GitHubaj2108/cve-2026-8239

Security write-up for an IDOR in Concrete CMS exposing conversation ratings through missing authorization on the get_rating endpoint, with root…

authentication-authorizationeducationinformation-gathering+3
20 days ago
aad-sso-enum-brute-spray preview

aad-sso-enum-brute-spray

GitHubtreebuilder/aad-sso-enum-brute-spray

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

authentication-authorizationcloud-securityinformation-gathering+3
1934 years ago
hekate preview

hekate

GitHubsourceincite/hekate
authentication-authorizationexploitationinformation-gathering+5
484 years ago
Discuz-X5.0-Authentication-Bypass-Exploit-Framework preview

Discuz-X5.0-Authentication-Bypass-Exploit-Framework

GitHubcerberusmrxi/discuz-x5.0-authentication-bypass-exploit-framework

Discuz! X5.0 Authentication Bypass Exploit Framework (CVE-2026-49952) - Critical vulnerability allowing unauthenticated database backup access via…

authentication-authorizationdatabase-securityexploit-frameworks+4
127 days ago
CVE-2026-35616 preview

CVE-2026-35616

GitHub0xblackash/cve-2026-35616

CVE-2026-35616

authentication-authorizationeducationexploitation+3
14 months ago
POC-CVE-2026-60206 preview

POC-CVE-2026-60206

GitHubimbas007/poc-cve-2026-60206

cve cve-2026-60206 weblogic saml exploit poc vulnerability oracle scanner security

authentication-authorizationexploitationpenetration-testing+4
3328 days ago
CVE-2025-60188-Atarim-Plugin-Exploit preview

CVE-2025-60188-Atarim-Plugin-Exploit

GitHubm4sh-wacker/cve-2025-60188-atarim-plugin-exploit

CVE-2025-60188 Atarim Plugin Exploit

authentication-authorizationexploitationinformation-gathering+3
227 months ago
wordpress-really-simple-security-authn-bypass-exploit preview

wordpress-really-simple-security-authn-bypass-exploit

GitHubm3ssap0/wordpress-really-simple-security-authn-bypass-exploit

Exploits Really Simple Security < 9.1.2 authentication bypass (CVE-2024-10924).

authentication-authorizationexploitationpenetration-testing+3
191 year ago
CVE-2026-47101-PoC preview

CVE-2026-47101-PoC

GitHublearner202649/cve-2026-47101-poc

The code for personally reproducing the corresponding vulnerability

api-security-testingauthentication-authorizationeducation+7
2 months ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubh454nsec/cve-2023-42793

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

authentication-authorizationexploitationpenetration-testing+3
452 years ago
DNN_CVE-2015-2794 preview

DNN_CVE-2015-2794

GitHubstyx00/dnn_cve-2015-2794

NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID:…

authentication-authorizationexploitationpenetration-testing+2
10 years ago
cve-2026-47777 preview

cve-2026-47777

GitHubbekwiner/cve-2026-47777
authentication-authorizationcode-analysispenetration-testing+3
11 month ago
CVE-2022-36537 preview

CVE-2022-36537

GitHubmalwareman007/cve-2022-36537

POC of CVE-2022-36537

authentication-authorizationexploitationinformation-gathering+3
361 year ago
CVE-2026-27771 preview

CVE-2026-27771

GitHubportbuster1337/cve-2026-27771

CVE-2026-27771 - Gitea/Forgejo Container Registry Auth Bypass Exploit PoC - Pull private container images without authentication

authentication-authorizationcontainer-securityeducation+5
192 months ago
CVE-2025-41646---Critical-Authentication-Bypass- preview

CVE-2025-41646---Critical-Authentication-Bypass-

GitHubgreenforcenetworks/cve-2025-41646---critical-authentication-bypass-

CVE-2025-41646 - Critical Authentication bypass

authentication-authorizationexploitationids-ips-evasion+5
11 year ago
Previous123Next