Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
9 results
CVE-2026-44351-poc preview

CVE-2026-44351-poc

GitHubisaca0315/cve-2026-44351-poc

Proof-of-concept for CVE-2026-44351, an authentication bypass in fast-jwt <6.2.4 where an empty HMAC key lets attackers forge arbitrary JWTs accepted…

api-securityauthenticationcryptography+6
22 days ago
CVE-2026-13447 preview

CVE-2026-13447

GitHubabraxas/cve-2026-13447

Proof-of-concept exploit for CVE-2026-13447, a critical authentication bypass in the WordPress MStore API plugin via forged Firebase JWT tokens, with…

authenticationcryptographyexploitation+5
6 days ago
gpgsm-cve-2026-57062-cms-gcm-short-tag preview

gpgsm-cve-2026-57062-cms-gcm-short-tag

GitHubgoldendivider/gpgsm-cve-2026-57062-cms-gcm-short-tag

Proof-of-concept demonstrating a CMS AES-GCM short-tag authentication bypass in GnuPG's gpgsm (CVE-2026-57062). Forges a message that decrypts on…

cryptographyexploitationpenetration-testing+1
1 month ago
CVE-2026-61500 preview

CVE-2026-61500

GitHubaramosf/cve-2026-61500

Python PoC and Docker lab for CVE-2026-61500: recovers Rejetto HFS V8 PRNG state to forge an admin session cookie and achieve RCE via server_code.

cryptographyeducationexploitation+7
10 days ago
the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt preview

the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

GitHubhunt-benito/the-same-key-opens-every-box-cve-2026-71960-hard-coded-jwt-secret-in-cudy-wr3000-mesh-mqtt

PoC toolkit that unpacks router firmware, decrypts device secrets, forges JWT tokens, and exploits CVE-2026-71960/71961 to take over Cudy WR3000 mesh…

authenticationcryptographyexploitation+4
1 month ago
ClaimJumper preview

ClaimJumper

GitHubfevra-dev/claimjumper

Professional JWT security testing toolkit. Analyze, crack, forge, and exploit JSON Web Tokens with 15+ vulnerability checks, 100k secret wordlist,…

authenticationcryptographyexploitation+6
18 months ago
secuimag3a preview
Archived

secuimag3a

GitHubmatthiasbe/secuimag3a

Exploit of the CVE-2016-1494 allowing to forge signatures of RSA keys with low exponents

cryptographyeducationexploitation+2
19 years ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubc0gnit00/cve-2026-29000

Python POC, Exploit for CVE-2026-29000

authentication-authorizationcryptographyeducation+5
14 months ago
CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit preview

CVE-2025-14611-CentreStack-and-Triofox-full-Poc-Exploit

GitHubpl4tyz/cve-2025-14611-centrestack-and-triofox-full-poc-exploit

CVE-2025-14611 CentreStack and Triofox full Poc/Exploit

authenticationcryptographyexploitation+6
9 months ago