Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
52 results
CVE-2026-55040-Mass-Exploit preview

CVE-2026-55040-Mass-Exploit

GitHubmaxprog-svg/cve-2026-55040-mass-exploit

Exploit for CVE-2026-55040 in Microsoft SharePoint, forging JWT tokens via algorithm none, weak HS256 secrets, and RS256 substitution to impersonate…

authentication-authorizationexploitationpayload-generation+3
9 days ago
CVE-2018-10933 preview

CVE-2018-10933

GitHubsoledad208/cve-2018-10933

CVE-2018-10933 very simple POC

authentication-authorizationexploitationpayload-generation+3
1267 years ago
JWTweak preview

JWTweak

GitHubrishuranjanofficial/jwtweak

Detects the algorithm of input JWT Token and provide options to generate the new JWT token based on the user selected algorithm.

authenticationcryptographypayload-generation+3
1032 months ago
jwt-spoof-tool preview

jwt-spoof-tool

GitHubamr9k8/jwt-spoof-tool

Automate JWT Exploit (CVE-2018-0114)

authentication-authorizationeducationexploitation+3
3 years ago
CVE-2015-9235_JWT_key_confusion preview

CVE-2015-9235_JWT_key_confusion

GitHubnxvh1337/cve-2015-9235_jwt_key_confusion

automate CVE-2015-9235 exploitation

educationexploitationpayload-generation+3
32 years ago
CVE-2019-19609-POC-Python preview

CVE-2019-19609-POC-Python

GitHubn000xy/cve-2019-19609-poc-python

Strapi Framework, 3.0.0-beta.17.4

exploitationpassword-attackspayload-generation+3
4 years ago
jwt-key-id-injector preview

jwt-key-id-injector

GitHubdariusztytko/jwt-key-id-injector

Simple python script to check against hypothetical JWT vulnerability.

payload-generationpenetration-testingvulnerability-analysis+1
515 years ago
CVE-2026-1529 preview

CVE-2026-1529

GitHub0x240x23elu/cve-2026-1529

Keycloak: Unauthorized organization registration via improper invitation token validation

authentication-authorizationexploitationpayload-generation+3
46 months ago
CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc preview

CVE-2026-29000-Python-PoC-pac4j-JWT-AuthenticationBypass-Poc

GitHubalihussainzada/cve-2026-29000-python-poc-pac4j-jwt-authenticationbypass-poc

Python proof-of-concept demonstrating an authentication bypass in pac4j JWT by crafting a JWE token with an unsigned inner JWT, allowing privilege…

authentication-authorizationeducationexploitation+3
25 months ago
CVE-2026-29000 preview

CVE-2026-29000

GitHub0xw1ld/cve-2026-29000

Rust-based exploit generator for CVE-2026-29000, an authentication bypass in pac4j-jwt via alg:none JWT nested in JWE, automating JWKS retrieval and…

authenticationctfexploitation+3
5 months ago
jwt-hack preview

jwt-hack

GitHubhahwul/jwt-hack

JSON Web Token Hack Toolkit

encryption-decryption-toolspassword-crackingpayload-generation+3
1.1k3 days ago
jwt-key-confusion-poc preview

jwt-key-confusion-poc

GitHubaalex954/jwt-key-confusion-poc

JWT Key Confusion PoC (CVE-2015-9235) Written for the Hack the Box challenge - Under Construction

ctfexploitationpayload-generation+3
24 years ago
CVE-2018-0114 preview

CVE-2018-0114

GitHuberemiel/cve-2018-0114

python2.7 script for JWT generation

authenticationencryption-decryption-toolsexploitation+3
25 years ago
cve-2026-49352-poc preview

cve-2026-49352-poc

GitHubcovepseng/cve-2026-49352-poc

Exploitability PoC for CVE-2026-49352 (9router Hardcoded JWT Secret Authentication Bypass)

authentication-authorizationeducationexploitation+4
12 months ago
CVE-2025-10294 preview

CVE-2025-10294

GitHubjfriedli/cve-2025-10294

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

authentication-authorizationexploitationpayload-generation+3
5 months ago
CVE-2025-9209 preview

CVE-2025-9209

GitHubnxploited/cve-2025-9209

RestroPress – Online Food Ordering System 3.0.0 - 3.1.9.2 - Unauthenticated Information Exposure to Authentication Bypass via Forged JWT

authentication-authorizationexploitationinformation-gathering+5
10 months ago
CVE-2025-8570 preview

CVE-2025-8570

GitHubnxploited/cve-2025-8570

BeyondCart Connector <= 2.1.0 - Missing Configuration of JWT Secret to Unauthenticated Privilege Escalation

authentication-authorizationeducationexploitation+6
11 months ago
CVE-2026-29000-PoC-Exploit preview

CVE-2026-29000-PoC-Exploit

GitHubtc4dy/cve-2026-29000-poc-exploit

CVE-2026-29000 – pac4j-jwt Authentication Bypass (🔥 CVSS 10.0). One-click admin forge via public key JWE wrapping. Leaks configs, users, secrets.…

authentication-authorizationeducationexploitation+6
33 months ago
Previous123Next