Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
32 results
CVE-2023-46805_CVE-2024-21887 preview

CVE-2023-46805_CVE-2024-21887

GitHubduy-31/cve-2023-46805_cve-2024-21887

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access…

authentication-authorizationcommand-and-controlexploitation+3
23
2 years ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
92 months ago
CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC preview

CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC

GitHubdollarboysushil/cve-2024-47533-cobbler-xmlrpc-authentication-bypass-rce-exploit-poc

CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated…

authentication-authorizationcommand-and-controlexploitation+6
81 year ago
poc-cribl-rce preview

poc-cribl-rce

GitHublivehybrid/poc-cribl-rce

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

authenticationcommand-and-controlexploitation+3
87 years ago
fortios-auth-bypass-exploit-CVE-2024-55591 preview

fortios-auth-bypass-exploit-CVE-2024-55591

GitHubsysirq/fortios-auth-bypass-exploit-cve-2024-55591

Python exploit for CVE-2024-55591, bypassing FortiOS authentication to execute remote commands on vulnerable FortiGate and FortiProxy devices.

authentication-authorizationcommand-and-controlexploitation+3
31 year ago
CVE-2025-47227_CVE-2025-47228 preview

CVE-2025-47227_CVE-2025-47228

GitHubsynacktiv/cve-2025-47227_cve-2025-47228

ScriptCase Pre-Authenticated Remote Command Execution exploitation script (CVE-2025-47227, CVE-2025-47228).

authentication-authorizationcommand-and-controlexploitation+3
111 year ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubk3ystr0k3r/cve-2026-24061

A PoC exploit for CVE-2026-24061 - GNU InetUtils telnetd Argument Injection Authentication Bypass

authenticationauthentication-authorizationcommand-and-control+8
33 months ago
noPac preview

noPac

GitHubxltj/nopac

Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287

authentication-authorizationcommand-and-controlexploitation+3
2 months ago
CVE-2022-46169 preview

CVE-2022-46169

GitHub0xn7y/cve-2022-46169

Exploit for CVE-2022-46169

authentication-authorizationcommand-and-controlexploitation+3
12 years ago
CVE-2022-46169_unauth_remote_code_execution preview

CVE-2022-46169_unauth_remote_code_execution

GitHubsvchost9913/cve-2022-46169_unauth_remote_code_execution

Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0

authentication-authorizationcommand-and-controlexploitation+3
3 years ago
CVE-2026-89026 preview

CVE-2026-89026

GitHubcflowsec/cve-2026-89026

Python PoC that forges a hard-coded HS256 JWT to exploit CVE-2026-89026 in Issabel pbxapi, enabling unauthenticated remote OS command execution via…

authenticationcommand-and-controlexploitation+5
7 days ago
CVE-2026-9198_exploit preview

CVE-2026-9198_exploit

GitHub0xdak/cve-2026-9198_exploit

Unauthenticated RCE exploit for Langflow OSS chaining auto_login JWT bypass with validate/code exec() to achieve remote command execution and reverse…

command-and-controlexploitationpenetration-testing+4
12 months ago
python-pentesting preview

python-pentesting

GitHubustayready/python-pentesting

Just a repo of random Python scripts to get pentesters started with the Python language on engagements.

cloud-securitycommand-and-controleducation+6
2196 years ago
ls-poc preview

ls-poc

GitHubtruekas/ls-poc

Proof-of-concept exploit for CVE-2026-30368, demonstrating authentication bypass in Lightspeed Classroom to control student devices via Ably channel.

command-and-controlexploitationpayload-development+3
145 months ago
CVE-2023-27350 preview

CVE-2023-27350

GitHubdezso-dfield/cve-2023-27350

PaperCut NG/MG Authentication Bypass and Remote Code Execution (RCE) Exploit Tool. A standalone Bash implementation of the PaperCut exploit chain,…

authentication-authorizationcommand-and-controlexploitation+4
9 months ago
CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE preview

CVE-2023-27524-Apache-Superset-Auth-Bypass-and-RCE

GitHubjakabakos/cve-2023-27524-apache-superset-auth-bypass-and-rce

Exploit for CVE-2023-27524 targeting Apache Superset auth bypass and RCE. Forges session cookies, enumerates databases/users, executes OS commands,…

authentication-authorizationcommand-and-controldatabase-security+5
283 years ago
cPanelSniper preview

cPanelSniper

GitHubynsmroztas/cpanelsniper

CVE-2026-41940 — cPanel & WHM Authentication Bypass via Session-File CRLF Injection

authentication-authorizationcommand-and-controlexploitation+6
4994 months ago
askWAM preview

askWAM

GitHubdirkjanm/askwam

Ask the Web Account Manager (WAM) for Entra ID tokens

authenticationcommand-and-controlidentity-management+5
13112 days ago
Previous12Next