Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
471 results
CVE-2026-102261 preview

CVE-2026-102261

GitHub7acini/cve-2026-102261

Non-destructive Go verifier that checks whether a Camaleon CMS instance applies the authorization fix for CVE-2026-102261 in the media crop endpoint.

authentication-authorizationdefensive-toolspenetration-testing+5
10 days ago
CVE-2026-16764 preview

CVE-2026-16764

GitHubhakaioffsec/cve-2026-16764

Python exploit for CVE-2026-16764, a privilege escalation in OWASP DefectDojo where an is_staff REST API bypass lets a low-privileged user gain…

api-securityauthentication-authorizationeducation+6
115 days ago
CVE-2026-18783-TREX-MES-Uygulamalarinda-Yetkisiz-Nesne-Erisimi preview

CVE-2026-18783-TREX-MES-Uygulamalarinda-Yetkisiz-Nesne-Erisimi

GitHubhasanuyarrr/cve-2026-18783-trex-mes-uygulamalarinda-yetkisiz-nesne-erisimi

Advisory for CVE-2026-18783: missing server-side authentication on TREX MES /api/GetDataJSON3 allows unauthenticated data queries and arbitrary SQL…

api-securityauthentication-authorizationdefensive-tools+5
9 days ago
CVE-2026-94609 preview

CVE-2026-94609

GitHubanthonyk2923/cve-2026-94609

Write-up and proof-of-concept for CVE-2026-94609, an authentik privilege-escalation flaw letting users with add_user_to_group join superuser groups…

api-securityauthentication-authorizationeducation+6
15 days ago
CVE-2026-65013-BOLA-IDOR preview

CVE-2026-65013-BOLA-IDOR

GitHubisaca0315/cve-2026-65013-bola-idor

Reproducible BOLA/IDOR PoC against Onlook's tRPC API (CVE-2026-65013), with a 12-step exploit chain, vulnerable and patched Docker targets, and…

api-security-testingauthentication-authorizationeducation+7
25 days ago
CVE-2026-88899 preview

CVE-2026-88899

GitHubuziii2208/cve-2026-88899

Knowns 0.30.0: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

ai-securityauthentication-authorizationexploitation+4
25 days ago
cve-2026-41940-PoC-Linux preview

cve-2026-41940-PoC-Linux

GitHubxrzmodz444/cve-2026-41940-poc-linux

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass in cPanel/WHM. Supports custom payloads and verbose logging, compatible with…

authentication-authorizationexploitationpenetration-testing+2
1 month ago
CVE-2026-73309 preview

CVE-2026-73309

GitHubbombobombone/cve-2026-73309

Proof-of-concept and technical write-up for CVE-2026-73309, an OAuth2 authentication bypass in XenForo before 2.3.13. Demonstrates empty…

authentication-authorizationexploitationpapers-research+2
11 month ago
CVE-2026-73317 preview

CVE-2026-73317

GitHubbombobombone/cve-2026-73317

Proof-of-concept exploit and technical write-up for CVE-2026-73317, an authorization bypass in XenForo allowing limited admins to approve content as…

authentication-authorizationexploitationmisconfiguration+3
11 month ago
CVE-2026-73318 preview

CVE-2026-73318

GitHubbombobombone/cve-2026-73318

Proof-of-concept exploit for XenForo CVE-2026-73318, an authorization bypass allowing ACP administrators to trigger site-wide policy re-agreement.…

authentication-authorizationexploitationmisconfiguration+3
1 month ago
CVE-2026-82329-JFrog-Artifactory- preview

CVE-2026-82329-JFrog-Artifactory-

GitHub0xterror/cve-2026-82329-jfrog-artifactory-

Exploit PoC for CVE-2026-82329, an authentication bypass in JFrog Artifactory. Demonstrates forging JWT tokens to gain admin access and create a…

authentication-authorizationexploitationpenetration-testing+2
21 month ago
CVE-2026-41940 preview

CVE-2026-41940

GitHub0xgh057r3c0n/cve-2026-41940

cPanel & WHM - Authentication Bypass via Session-File CRLF Injection

authentication-authorizationexploitationpenetration-testing+4
11 month ago
CVE-2026-82329 preview

CVE-2026-82329

GitHub0xcyp1337/cve-2026-82329

Mass exploit for CVE-2026-82329, an unauthenticated authentication bypass in JFrog Artifactory. Supports single-target and batch scanning with…

authentication-authorizationexploitationpenetration-testing+3
1 month ago
artifactory-CVE-2026-82329-poc.py preview

artifactory-CVE-2026-82329-poc.py

GitHubrealalexandergeorgiev/artifactory-cve-2026-82329-poc.py

CVE-2026-82329 — JFrog Artifactory unauthenticated authentication bypass ("phantom join key" -> forged service admin token)

authentication-authorizationexploitationpenetration-testing+2
11 month ago
CVE-2026-82329-JFrog-Artifactory-Auth-Bypass preview

CVE-2026-82329-JFrog-Artifactory-Auth-Bypass

GitHubynsmroztas/cve-2026-82329-jfrog-artifactory-auth-bypass

Exploit for CVE-2026-82329, an unauthenticated auth bypass in self-hosted JFrog Artifactory, allowing admin token takeover via blank join key.

authentication-authorizationexploitationpenetration-testing+2
61 month ago
BUK_TS_KILLER preview

BUK_TS_KILLER

GitHubblackhatexploitation/buk_ts_killer

Exploit for BUK-TS authentication bypass and remote code execution, with steps to intercept responses and manipulate userid to gain unauthorized…

authentication-authorizationexploitationpenetration-testing+2
3 months ago
phpBB-CVE-2026-48611 preview

phpBB-CVE-2026-48611

GitHubethicalgrey/phpbb-cve-2026-48611

Automated PoC for CVE-2026-48611 — phpBB OAuth login_link authentication bypass

authentication-authorizationexploitationinformation-gathering+5
1 month ago
CVE-2026-55040-Mass-Exploit preview

CVE-2026-55040-Mass-Exploit

GitHubmaxprog-svg/cve-2026-55040-mass-exploit

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

authentication-authorizationexploitationpayload-generation+3
1 month ago
Previous12…27Next