Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
45 results
CVE-2025-49901 preview

CVE-2025-49901

GitHubnxploited/cve-2025-49901

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

authentication-authorizationexploitationpassword-attacks+3
4 months ago
CVE-2026-45156-POC preview

CVE-2026-45156-POC

GitHubcybertechajju/cve-2026-45156-poc

This repository contains the Proof of Concept (PoC) exploit script for CVE-2026-45156

authentication-authorizationexploitationpenetration-testing+3
22 months ago
CVE-2026-55040 preview

CVE-2026-55040

GitHubsfewer-r7/cve-2026-55040

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

authentication-authorizationexploitationimpersonation-tools+4
5826 days ago
gimmepatz preview

gimmepatz

GitHub6mile/gimmepatz

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

api-securityauthentication-authorizationcloud-security+7
431 year ago
CVE-2026-29000 preview

CVE-2026-29000

GitHubkernelzeroday/cve-2026-29000

Forge JWE-wrapped unsigned JWTs to bypass pac4j-jwt signature verification (CVE-2026-29000) and authenticate as any user; includes Python CLI,…

authentication-authorizationexploitationpayload-generation+5
96 months ago
Powermad preview

Powermad

GitHubkevin-robertson/powermad

PowerShell MachineAccountQuota and DNS exploit tools

authenticationidentity-managementlateral-movement+4
1.5k3 years ago
ldeep preview

ldeep

GitHubfranc-pentest/ldeep

In-depth ldap enumeration utility

authentication-authorizationconfiguration-auditingdns-analysis+4
60416 days ago
SCCMSecrets preview

SCCMSecrets

GitHubsynacktiv/sccmsecrets

SCCMSecrets.py aims at exploiting SCCM policies distribution for credentials harvesting, initial access and lateral movement.

authentication-authorizationexploitationinformation-gathering+5
2756 days ago
DahuaConsole preview

DahuaConsole

GitHubmcw0/dahuaconsole

Dahua Console, access internal debug console and/or other researched functions in Dahua devices. Feel free to contribute in this project.

authentication-authorizationembedded-systems-securityexploitation+5
3181 year ago
aad-sso-enum-brute-spray preview

aad-sso-enum-brute-spray

GitHubtreebuilder/aad-sso-enum-brute-spray

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

authentication-authorizationcloud-securityinformation-gathering+3
1934 years ago
violin preview

violin

GitHubstrategic-automation/violin

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

authentication-authorizationexploitationosint+8
8317 days ago
CVE-2023-42793 preview

CVE-2023-42793

GitHubh454nsec/cve-2023-42793

JetBrains TeamCity Authentication Bypass CVE-2023-42793 Exploit

authentication-authorizationexploitationpenetration-testing+3
452 years ago
SecretsStalker preview

SecretsStalker

GitHubrootsecdev/secretsstalker

Read-only Entra ID app-credential assessment: enumerates Graph permissions, Azure RBAC, and reachable cloud data, then maps findings to…

authentication-authorizationcloud-infrastructure-securitycloud-security+7
181 month ago
CVE-2024-55591-POC preview

CVE-2024-55591-POC

GitHubexfil0/cve-2024-55591-poc

A comprehensive all-in-one Python-based Proof of Concept script to discover and exploit a critical authentication bypass vulnerability…

authentication-authorizationexploitationnetwork-security+6
121 year ago
CVE-2022-43704 preview

CVE-2022-43704

GitHub9lyph/cve-2022-43704

Sinilink XY-WFTX Wifi Remote Thermostat Module Temperature Controller

authentication-authorizationembedded-systems-securityexploitation+7
51 year ago
CVE-2024-27198-RCE preview

CVE-2024-27198-RCE

GitHubpasswa11/cve-2024-27198-rce

Exploit for JetBrains TeamCity authentication bypass (CVE-2024-27198/27199) enabling remote code execution. Includes dork queries for asset discovery…

authentication-authorizationexploitationpenetration-testing+3
32 years ago
CVE-2023-33730 preview

CVE-2023-33730

GitHubsahiloj/cve-2023-33730

eScan Management Console version 14.0.1400.2281 contains privilege escalation via `GetUserCurrentPwd` function lets attackers retrieve any user's…

authentication-authorizationeducationexploitation+8
16 months ago
Automated-scanner-CVE-2026-41940 preview

Automated-scanner-CVE-2026-41940

GitHubsardine-web/automated-scanner-cve-2026-41940

Automated scanner & post-exploitation toolkit for CVE-2026-41940 — cPanel & WHM root authentication bypass via session-file CRLF injection

authentication-authorizationcommand-and-controlexploitation+8
13 months ago
Previous123Next