Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
35 results
OpenShell preview

OpenShell

GitHubnvidia/openshell

Sandboxed runtime for autonomous AI agents with declarative YAML policies enforcing filesystem, network, and process constraints, plus endpoint-bound…

ai-securityauthentication-authorizationcloud-security+7
8.6k
5 days ago
cve-2026-41940-PoC-Linux preview

cve-2026-41940-PoC-Linux

GitHubxrzmodz444/cve-2026-41940-poc-linux

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports custom payloads and verbose logging, compatible with…

authentication-authorizationexploitationpenetration-testing+2
11 days ago
CVE-2026-41940-Exploit-PoC preview

CVE-2026-41940-Exploit-PoC

GitHubishanoshada/cve-2026-41940-exploit-poc

Exploit PoC for CVE-2026-41940, a cPanel & WHM authentication bypass via CRLF injection. Includes mass scanning, post-exploitation actions, and an…

authentication-authorizationexploitationpayload-development+5
24 months ago
CVE-2026-28372-telnetd-Privilege-Escalation preview

CVE-2026-28372-telnetd-Privilege-Escalation

GitHubrohitberiwala/cve-2026-28372-telnetd-privilege-escalation

This Proof‑of‑Concept demonstrates a **Local Privilege Escalation** vulnerability in GNU inetutils `telnetd`. `telnetd` improperly passes…

authentication-authorizationexploitationpenetration-testing+2
16 months ago
CVE-2026-0920-WordPress-LA-Studio-Exploit preview

CVE-2026-0920-WordPress-LA-Studio-Exploit

GitHubgalaxy-sc/cve-2026-0920-wordpress-la-studio-exploit

Proof-of-concept exploit for CVE-2026-0920 in LA-Studio Element Kit, enabling unauthenticated privilege escalation to administrator via crafted AJAX…

authentication-authorizationexploitationpenetration-testing+3
28 months ago
freeipa preview

freeipa

GitHubfreeipa/freeipa

Centralizes identity, authentication, and access control for Linux/UNIX environments using LDAP, Kerberos, PKI, DNS, and Active Directory trust.

authenticationauthentication-authorizationcryptography+2
1.3k4 days ago
spire preview

spire

GitHubspiffe/spire

Workload identity platform that attests running services, issues SPIFFE IDs/SVIDs, and enables mTLS and JWT authentication for Kubernetes,…

authenticationauthentication-authorizationcloud-infrastructure-security+5
2.5k1 day ago
ksmbrace preview

ksmbrace

GitHubturtlearm/ksmbrace

ksmbd CVEs: CVE-2026-31717, CVE-2026-68083

authentication-authorizationdefensive-toolsexploitation+3
51 month ago
cve-2026-39987 preview

cve-2026-39987

GitHubmatesz44/cve-2026-39987

Exploits CVE-2026-39987 pre-auth RCE in Marimo <0.23.0 by connecting to the unauthenticated /terminal/ws WebSocket. Supports arbitrary command…

authentication-authorizationexploitationpenetration-testing+2
1 month ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
1191 day ago
pared preview

pared

GitLabrenich/pared

Lightweight, secure control plane & real-time web dashboard in Crystal for Linux firewalld and NetworkManager host security.

authentication-authorizationdefensive-toolsidentity-access-management+2
1 month ago
Kangaroo preview

Kangaroo

GitHubmonkeysec-sys/kangaroo

Authentication bypass exploit for CVE-2026-32746 targeting legacy Telnet servers, with defensive guidance and Go-based implementation for authorized…

authentication-authorizationeducationexploitation+3
21 month ago
fusionauth-samlv2 preview

fusionauth-samlv2

GitHubfusionauth/fusionauth-samlv2

SAML v2.0 bindings in Java using JAXB

api-securityauthentication-authorizationcryptography+2
105 months ago
kcmapper preview

kcmapper

GitHubsynacktiv/kcmapper

KcMapper is a security auditing tool for Keycloak. It exports your Keycloak configuration (realms, clients, users, roles, etc.) into a Neo4j graph…

authentication-authorizationconfiguration-auditingidentity-access-management+3
147 months ago
teleport preview

teleport

GitHubgravitational/teleport

The easiest, and most secure way to access and protect all of your infrastructure.

api-securityauthentication-authorizationcloud-security+7
20.9k26 days ago
watchTowr-vs-progress-moveit_CVE-2024-5806 preview

watchTowr-vs-progress-moveit_CVE-2024-5806

GitHubwatchtowrlabs/watchtowr-vs-progress-moveit_cve-2024-5806

Exploit for the CVE-2024-5806

authentication-authorizationexploitationinformation-gathering+3
452 years ago
CVE-2024-47533 preview

CVE-2024-47533

GitHubokkotsu1/cve-2024-47533

Exploit for CVE-2024-47533, a critical authentication bypass in Cobbler XML-RPC API, granting unauthenticated admin access for educational security…

authentication-authorizationeducationexploitation+3
11 year ago
NoEyes preview

NoEyes

GitHubymsniper/noeyes

Secure terminal chat. E2E encrypted, zero-metadata blind-forwarder server. PyNaCl XSalsa20-Poly1305 + Ed25519 + forward secrecy. Cross-platform…

authentication-authorizationcryptographyencryption-decryption-tools+3
1463 months ago
Previous12Next