Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
9 results
CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc preview

CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc

GitHubalihussainzada/cve-2026-29000-python-poc-pac4j-jwt-authenticationbypass-poc

Python proof-of-concept demonstrating an authentication bypass in pac4j JWT by crafting a JWE token with an unsigned inner JWT, allowing privilege…

authentication-authorizationeducationexploitation+3
2
6 months ago
smbtakeover preview

smbtakeover

GitHubzyn3rgy/smbtakeover

BOF and Python3 implementation of technique to unbind 445/tcp on Windows via SCM interactions

authentication-authorizationlateral-movementpenetration-testing+2
3621 year ago
mobileiron-exploit preview

mobileiron-exploit

GitHubsynacktiv/mobileiron-exploit

Python script to exploit the OWASSRF + TabShell chain on vulnerable Microsoft Exchange servers, leveraging Kerberos authentication for command…

authenticationauthentication-authorizationexploitation+3
92 years ago
CVE-2023-52268 preview

CVE-2023-52268

GitHubsqu1dw3rm/cve-2023-52268

Authentication Bypass for FreeScout End-User Portal

authentication-authorizationexploitationpenetration-testing+3
1 year ago
apache__jspwiki_CVE-2022-46907_2-11-3 preview

apache__jspwiki_CVE-2022-46907_2-11-3

GitHubshoucheng3/apache__jspwiki_cve-2022-46907_2-11-3

Exploit module for Apache JSPWiki CVE-2022-46907, targeting a Java-based wiki platform with JAAS security integration. Provides vulnerability…

authentication-authorizationconfiguration-auditingeducation+3
10 months ago
apache__jspwiki_CVE-2019-10077_2-11-0-M3 preview

apache__jspwiki_CVE-2019-10077_2-11-0-M3

GitHubshoucheng3/apache__jspwiki_cve-2019-10077_2-11-0-m3

Exploit module for Apache JSPWiki CVE-2019-10077, targeting a Java-based wiki platform with JAAS authentication and access control. Enables…

authentication-authorizationconfiguration-auditingexploitation+3
1 year ago
dahua-dvr-metasploit preview

dahua-dvr-metasploit

GitHubfsn4k3/dahua-dvr-metasploit

Improved Metasploit module for CVE-2013-6117 (Dahua DVR authentication bypass)

authentication-authorizationexploitationexploit-frameworks+4
3 months ago
CVE-2024-38473 preview

CVE-2024-38473

GitHubabdurahmon3236/cve-2024-38473

Proof-of-concept demonstrating an encoding flaw in Apache HTTP Server mod_proxy that can bypass authentication via crafted encoded URLs.

authentication-authorizationexploitationpenetration-testing+3
32 years ago
CVE-2022-43704 preview

CVE-2022-43704

GitHub9lyph/cve-2022-43704

Sinilink XY-WFTX Wifi Remote Thermostat Module Temperature Controller

authentication-authorizationembedded-systems-securityexploitation+7
51 year ago