Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
241 results
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHublanicer/cve-2026-41940-poc

Exploits cPanel/WHM CVE-2026-41940 authentication bypass via CRLF session injection for unauthenticated root-level WHM access, then lists accounts,…

authentication-authorizationpenetration-testingpersistence-mechanisms+5
29
2 days ago
CVE-2026-44848-PoC preview

CVE-2026-44848-PoC

GitHubboreas37/cve-2026-44848-poc

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

api-security-testingauthentication-authorizationcontainer-security+3
2 days ago
jit preview

jit

GitHubjitpass/jit

Find the plaintext secrets on your Mac and move them behind Touch ID, injected just in time without breaking the tools that read them. Free and…

authentication-authorizationconfiguration-auditingdevsecops+3
146 days ago
CVE-2026-73673 preview

CVE-2026-73673

GitHubozcanpng/cve-2026-73673

Non-destructive PoC and technical write-up for CVE-2026-73673, an unauthenticated firmware-update flaw in Netis NC63 router, with reproduction and…

authentication-authorizationembedded-systems-securityexploitation+3
27 days ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubpemarine/cve-2026-41940-poc

Exploit for CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM that grants root-level WHM access via CRLF session injection, with…

authentication-authorizationexploitationpenetration-testing+3
2707 days ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
28 days ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
735 days ago
CVE-2026-27344 preview

CVE-2026-27344

GitHubac8999/cve-2026-27344

Missing Authorization in inseriswiss inseri core inseri-core allows Exploiting Incorrectly Configured Access Control Security Levels.This issue…

api-securityauthentication-authorizationmisconfiguration+3
9 days ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
5210 days ago
caos-os preview

caos-os

GitHubdigicred-oss/caos-os

Customer Assurance Operating System. Answer the security questionnaires your customers send you, once.

authentication-authorizationdefensive-toolsinformation-gathering+2
11 days ago
oauth-scan preview

oauth-scan

GitHubportswigger/oauth-scan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

authentication-authorizationconfiguration-auditinginformation-gathering+3
1921 year ago
AzureAD-Attack-Defense preview

AzureAD-Attack-Defense

GitHubcloud-architekt/azuread-attack-defense

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can…

authentication-authorizationcloud-securityconfiguration-auditing+5
2.5k1 month ago
HardeningKitty preview

HardeningKitty

GitHubscipag/hardeningkitty

HardeningKitty - Checks and hardens your Windows configuration

authentication-authorizationconfiguration-auditingdefensive-tools+2
1.8k1 month ago
OAUTHScan preview

OAUTHScan

GitHubakabe1/oauthscan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

api-securityapi-security-testingauthentication-authorization+6
1781 year ago
API-Security-Checklist preview

API-Security-Checklist

GitHubshieldfy/api-security-checklist

Checklist of the most important security countermeasures when designing, testing, and releasing your API

api-securityauthentication-authorizationcurated-resources+4
23.3k1 month ago
BurpSuite-For-Pentester preview

BurpSuite-For-Pentester

GitHubignitetechnologies/burpsuite-for-pentester

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

authentication-authorizationcurated-resourceseducation+7
2.6k5 months ago
SecurityExplained preview

SecurityExplained

GitHubharsh-bothra/securityexplained

SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create…

authentication-authorizationcurated-resourceseducation+7
5464 years ago
Azure-APIM-Dev-Portal-Signup-Bypass preview

Azure-APIM-Dev-Portal-Signup-Bypass

GitHubdz-y/azure-apim-dev-portal-signup-bypass

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

api-securityapi-security-testingauthentication-authorization+6
15 days ago
Previous12…14Next