Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
20 results
UltraRealy_with_CVE-2019-1040 preview

UltraRealy_with_CVE-2019-1040

GitHublazaars/ultrarealy_with_cve-2019-1040

Updated version for the tool UltraRealy with support of the CVE-2019-1040 exploit

authenticationcommand-and-controlexploitation+7
19
7 years ago
CVE-2025-33073 preview

CVE-2025-33073

GitHubobscura-cert/cve-2025-33073

Proof-of-concept tool that chains DNS injection, NTLM relay, and RPC-based coercion to test authentication relay paths in Windows Active Directory…

authenticationcommand-and-controldns-analysis+7
11 year ago
CVE-2026-10523-Ivanti-sentry preview

CVE-2026-10523-Ivanti-sentry

GitHubgagaltotal/cve-2026-10523-ivanti-sentry

Proof-of-concept detection tool for Ivanti Sentry authentication bypass and remote code execution vulnerabilities (CVE-2026-10520, CVE-2026-10523).…

authenticationcommand-and-controlexploitation+3
33 months ago
CVE-2026-41940 preview

CVE-2026-41940

GitHubjenderal92/cve-2026-41940

Bulk scanner and mass exploitation tool for CVE-2026-41940 on cPanel/WHM, built for automated target validation and high-speed multi-threaded…

authenticationcommand-and-controlexploitation+6
44 months ago
noPac preview

noPac

GitHubxltj/nopac

Go implementation of NoPac, exploiting CVE-2021-42278 and CVE-2021-42287

authentication-authorizationcommand-and-controlexploitation+3
3 months ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubhitechcloud-vietnam/cve-2026-41940-poc

Exploits CVE-2026-41940, a cPanel & WHM authentication bypass, to gain root WHM access and run post-exploitation commands, file reads, and account…

authenticationcommand-and-controlexploitation+8
10 days ago
fortios-auth-bypass-exploit-CVE-2024-55591 preview

fortios-auth-bypass-exploit-CVE-2024-55591

GitHubsysirq/fortios-auth-bypass-exploit-cve-2024-55591

Python exploit for CVE-2024-55591, bypassing FortiOS authentication to execute remote commands on vulnerable FortiGate and FortiProxy devices.

authentication-authorizationcommand-and-controlexploitation+3
31 year ago
Firework preview
Archived

Firework

GitHubspiderlabs/firework

Firework is a proof of concept tool to interact with Microsoft Workplaces creating valid files required for the provisioning process.

authenticationcommand-and-controlosint-social-engineering+5
436 years ago
CVE-2026-41940 preview

CVE-2026-41940

GitHublutfifakee-project/cve-2026-41940

cPanel/WHM CVE-2026-41940 - Mass Scanner & Exploiter

authenticationcommand-and-controlexploitation+6
15 months ago
CVE-2026-24061 preview

CVE-2026-24061

GitHubsh4den/cve-2026-24061

Proof of Concept: CVE-2026-24061 is a critical authentication bypass vulnerability in GNU inetutils-telnetd allowing unauthenticated remote attackers…

authenticationcommand-and-controleducation+7
63 months ago
cve-2026-41940-PoC preview

cve-2026-41940-PoC

GitHubyasouxken/cve-2026-41940-poc

Python PoC exploiting CVE-2026-41940, a cPanel & WHM authentication bypass enabling unauthenticated root-level WHM access, with scanning and…

authenticationcommand-and-controlexploitation+7
1893 days ago
lsawhisper-bof preview

lsawhisper-bof

GitHubdazzyddos/lsawhisper-bof

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without…

authenticationcommand-and-controlexploitation+4
2967 months ago
poc-cribl-rce preview

poc-cribl-rce

GitHublivehybrid/poc-cribl-rce

CVE-2019-11076 - Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request

authenticationcommand-and-controlexploitation+3
87 years ago
CVE-2020-11651 preview

CVE-2020-11651

GitHubdrew-alleman/cve-2020-11651

A script that exploits SaltStack CVE-2020-11651 and CVE-2020-11652 to add new users to a vulnerable Salt master by injecting entries into /etc/passwd…

authenticationcommand-and-controlexploitation+3
11 year ago
CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC preview

CVE-2024-47533-Cobbler-XMLRPC-Authentication-Bypass-RCE-Exploit-POC

GitHubdollarboysushil/cve-2024-47533-cobbler-xmlrpc-authentication-bypass-rce-exploit-poc

CVE-2024-47533 is a critical authentication bypass vulnerability in Cobbler (versions 3.0.0 to before 3.2.3 and 3.3.7) allowing unauthenticated…

authentication-authorizationcommand-and-controlexploitation+6
81 year ago
CVE-2026-41940-PoC-Exploit preview

CVE-2026-41940-PoC-Exploit

GitHubtc4dy/cve-2026-41940-poc-exploit

🚀 CVE-2026-41940 cPanel/WHM Auth Bypass Exploit - Best Flow 💥 CRLF injection leads to auth bypass, session hijacking & account leak. ✅ Proxy,…

authentication-authorizationcommand-and-controlexploitation+8
92 months ago
CVE-2022-46169_unauth_remote_code_execution preview

CVE-2022-46169_unauth_remote_code_execution

GitHubsvchost9913/cve-2022-46169_unauth_remote_code_execution

Unauthenticated Remote Code Execution through authentication bypass and command injection in Cacti < 1.2.23 and < 1.3.0

authentication-authorizationcommand-and-controlexploitation+3
3 years ago
CVE-2023-46805_CVE-2024-21887 preview

CVE-2023-46805_CVE-2024-21887

GitHubduy-31/cve-2023-46805_cve-2024-21887

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access…

authentication-authorizationcommand-and-controlexploitation+3
232 years ago
Previous12Next