Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
30 results
auth preview

auth

GitHubsupabase/auth

A JWT based API for managing users and issuing JWT tokens

authenticationauthentication-authorizationidentity-access-management+1
2.5k
8 days ago
zappzarapp-php-security preview

zappzarapp-php-security

GitLabmarcstraube/zappzarapp-php-security

PHP 8.4+ security library (mirror)

api-securityauthentication-authorizationcode-analysis+6
12 days ago
Kerberos-CVE-2026-27912 preview

Kerberos-CVE-2026-27912

GitHuboxstussz-eng/kerberos-cve-2026-27912

PoC for CVE-2026-27912 - Windows Kerberos Elevation of Privilege (ResetNightmare). Unauthorized password reset via Kerberos flaw. For security…

authentication-authorizationexploitationpassword-attacks+2
214 days ago
CVE-2026-24031 preview

CVE-2026-24031

GitHubaramosf/cve-2026-24031

Self-contained Python PoC for Dovecot SQL authentication bypass: logs in as any user without the real password and enumerates usernames on vulnerable…

authentication-authorizationdatabase-securityemail-security+4
216 days ago
CVE-2026-15964-PoC preview

CVE-2026-15964-PoC

GitHubinstructor-admin/cve-2026-15964-poc

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

authentication-authorizationexploitationinformation-gathering+5
127 days ago
chpwd preview
Archived

chpwd

GitHubb0lbas/chpwd

Secure CLI password manager (Argon2id + AES-256-GCM)

authentication-authorizationcryptographyencryption-decryption-tools+2
51 month ago
The Vault by Focused Hunts preview

The Vault by Focused Hunts

GitLabfocused.hunts/the.vault

Privacy-first password manager with local storage and bring-your-own-cloud sync across Google Drive, Microsoft OneDrive, and Dropbox. Your…

authentication-authorizationcloud-securityencryption-decryption-tools+3
2 months ago
Password-Strength-Evaluator preview

Password-Strength-Evaluator

GitHubjenderal92/password-strength-evaluator

Password Strength Evaluator is a tool to evaluate the strength of passwords and provide recommendations to improve their security.

authentication-authorizationdefensive-toolseducation+1
3 months ago
CVE-2025-47227 preview

CVE-2025-47227

GitHubouts1d3r-net/cve-2025-47227

Exploit for CVE-2025-47227 - ScriptCase Password Reset (Pre-Auth)

authentication-authorizationexploitationpassword-attacks+3
63 months ago
public-passwd preview

public-passwd

GitHubst4rburn/public-passwd

Use CVE-2026-46333 and CVE-2026-31431 to change any user's password.

authenticationauthentication-authorizationbinary-exploitation+5
23 months ago
Silverpeas-AuthBypass-CVE-2024-36042 preview

Silverpeas-AuthBypass-CVE-2024-36042

GitHubha5ant/silverpeas-authbypass-cve-2024-36042

Python PoC for CVE-2024-36042 authentication bypass in Silverpeas < 6.3.5. Features version detection, multi-threaded user enumeration, message…

authentication-authorizationexploitationinformation-gathering+5
3 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubmurrez/cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940, an authentication bypass chain in WHM/cPanel. Multi-threaded scanner that changes root password on…

authentication-authorizationexploitationpenetration-testing+3
53 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubdennisec/cve-2026-41940

Exploit script for CVE-2026-41940, an authentication bypass in cPanel/WHM using CRLF injection to gain admin access and change root password, with…

authentication-authorizationexploitationpenetration-testing+3
3 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubrosemary1337/cve-2026-41940

Proof-of-concept exploit for CVE-2026-41940, an unauthenticated authentication bypass in cPanel/WHM using CRLF injection to leak security tokens and…

authentication-authorizationexploitationpenetration-testing+3
4 months ago
CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise preview

CVE-2025-58434-Unauthenticated-Password-Reset-Flowwise

GitHubsteampunk424/cve-2025-58434-unauthenticated-password-reset-flowwise

The forgot-password endpoint in Flowise returns sensitive information including a valid password reset tempToken without authentication or…

authentication-authorizationexploitationpenetration-testing+3
14 months ago
CVE-2023-33730 preview

CVE-2023-33730

GitHubsahiloj/cve-2023-33730

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

authentication-authorizationeducationexploitation+8
16 months ago
smartermail-CVE-2026-23760-poc preview

smartermail-CVE-2026-23760-poc

GitHubmaxmnml/smartermail-cve-2026-23760-poc

CVE-2026-23760 - An authentication bypass via password reset API in SmarterMail.

authentication-authorizationexploitationpenetration-testing+3
67 months ago
CVE-2025-67070-Intelbras-CFTV-MFA-Bypass preview

CVE-2025-67070-Intelbras-CFTV-MFA-Bypass

GitHubteteco/cve-2025-67070-intelbras-cftv-mfa-bypass

A critical vulnerability in the Intelbras NVD 9032 R Ftd IP CFTV device allows an attacker to bypass the multi-factor authentication during password…

authentication-authorizationexploitationpenetration-testing+3
7 months ago
Previous12Next